Security firms track FTX exploiter through Bitcoin mixer

Experts are tracking one of the largest exploits in crypto history as the attacker attempts to launder their funds

article-image

REDPIXEL.PL/Shutterstock modified by Blockworks

share

A significant portion of the funds from a nearly $500 million exploit are currently being laundered via a mixer service on the Bitcoin blockchain. However, informed sources tell Blockworks that the exploiter’s efforts may be stymied by the sheer sum they’re attempting to obfuscate. 

Amid the collapse of crypto exchange FTX in November 2022, an unknown attacker made off with $477 million in customer funds. 

According to a report from analysis firm Elliptic, in the weeks that followed the attacker almost immediately lost some $31 million from Tether freezing their USDT, and likewise lost significant sums to slippage as they swapped between stablecoins and other assets to ether. 

The attacker then bridged some 74,000 of their remaining 245,000 ether (ETH) ($306 million at the time) through the now-defunct Ren cross-chain bridge to Bitcoin, where they then deposited into the ChipMixer mixing service, per Elliptic research. Elliptic estimates that upwards of $4 million was eventually successfully sent to centralized exchanges to offramp to fiat. 

Since then, the remaining 185,000 ETH sat largely untouched, until the hacker once again began swapping ETH for BTC last week

In an interview with Blockworks, Evgenii Melnichuk, chief investigation officer at BLIN Analytics, reported that the exploiter swapped nearly 72,500 ETH to bitcoin (BTC) via ThorChain. Subsequently, ThorChain paused its operations, partly due to concerns over potential law enforcement scrutiny.

Loading Tweet..

But why is the exploiter swapping from Ethereum to Bitcoin to begin with? 

“One of the main reasons is liquidity,” said Melnichuk. “On Bitcoin there’s more mixers, and they’re different. On Ethereum, after Tornado was sanctioned, a lot of people stopped using it and liquidity decreased, and as a result the anonymity set also decreased.”

Indeed, both BLIN and Elliptic confirm that the exploiter has attempted to wash 4,000 BTC via Sinbad, a clone of the Blender.io service, which was sanctioned by the treasury in 2022

However, according to Melnichuk, the vast amounts deposited into Sinbad have “overheated” the service, ruining the anonymity set. BLIN believes it has successfully tracked the funds through the mixer as a result.

“Some of the coins the hacker deposited to Sinbad were withdrawn by the same hacker — the mixer was overheated,” Melnichuk told Blockworks. 

The 4,000 BTC have been transferred to intermediary addresses. From there, the hacker will likely dispatch the funds to exchanges, leveraging stolen or purchased accounts. A second option is that the hacker will attempt to send funds to other blockchains to further obfuscate their tracks, perhaps sending funds to Avalanche — a pattern used by North Korean-funded Lazarus Group hackers.

Elliptic, meanwhile, believes it has tracked the older BTC mixed through Chipmixer. 

“Of the stolen assets that can be traced through ChipMixer, significant amounts are combined with funds from Russia-linked criminal groups, including ransomware gangs and darknet markets, before being sent to exchanges. This points to the involvement of a broker or other intermediary with a nexus in Russia,” the firm wrote.


Get the news in your inbox. Explore Blockworks newsletters:

Tags

Decoding crypto and the markets. Daily, with Byron Gilliam.

Upcoming Events

Javits Center North | 445 11th Ave

Tues - Thurs, March 24 - 26, 2026

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Research Report Templates (5).png

Research

ERC 8004 introduces a new trust layer for AI agents by standardizing onchain identity, reputation, and validation. As agents begin handling capital and coordinating autonomously, trust becomes the key constraint to broader adoption. The rollout mirrors the early x402 narrative, where adoption lagged the initial launch until major integrations and a viral use case pulled attention into the ecosystem. If ERC 8004 follows a similar path, downstream infrastructure tied to the standard could see outsized benefit as the narrative gains traction. The primary beneficiaries are likely to be agent frameworks and launchpads at the distribution layer, agent to agent coordination platforms that enable delegation and payments, and validation providers that offer stronger security and execution guarantees.

article-image

BTC finished the week up 1.6%, while L2s, RWAs and the treasury trade continued to grind lower

article-image

DTCC moves DTC-custodied Treasuries onchain via Canton, while Lighter’s LIT launches trading at a fees multiple in Hyperliquid territory

article-image

In the 90s, rapt audiences worldwide watched a coffee pot — will that fascination ever turn to crypto?

article-image

Some systems improve by failing — and crypto has no choice

article-image

Yield Basis introduces an IL-free AMM design that already dominates BTC DEX liquidity

article-image

Maybe tokenholders don’t need the rights that corporate shareholders have come to expect

Newsletter

The Breakdown

Decoding crypto and the markets. Daily, with Byron Gilliam.

Blockworks Research

Unlock crypto's most powerful research platform.

Our research packs a punch and gives you actionable takeaways for each topic.

SubscribeGet in touch

Blockworks Inc.

133 W 19th St., New York, NY 10011

Blockworks Network

NewsPodcastsNewslettersEventsRoundtablesAnalytics