The hacker behind the $27.3 million multisig wallet breach has begun liquidating funds

Markets 2026-01-07 10:06

The perpetrator behind the December 18 $27.3 million cryptocurrency theft has withdrawn 1,000 ETH worth $3.24 million from the DeFi platform Aave and laundered it through Tornado Cash.

According to PeckShield, the attacker has now funneled up to 6,300 ETH, valued at $19.4 million, through Tornado Cash since the initial breach.

PeckShield wrote on X, “The drainer, who controls the compromised multisig, holds a $9.75M leveraged long position ($20.5M in ETH against $10.7M in DAI).”

Pig-butchering scam emerges in money trail

Another incident involving laundering and the use of Tornado Cash has caught the eye of on-chain monitors.

On-chain analyst Specter notified the public on X, stating, “A wallet bridged $7M to Ethereum from multiple wallets on the TRON blockchain. Tracing the funds suggests they originate from a crypto investment pig-butchering scam.”

PeckShield also corroborated the story with on-chain data, uncovering a laundering operation that is related to pig butchering.

PeckShield analysis indicated that one address alone had processed 2,479.1 ETH worth $7.9 million through Tornado Cash, with funds traced back to multiple Tron wallets before being bridged to Ethereum.

The attacker’s methodical approach involves depositing funds in 100 ETH batches into Tornado Cash, which severs the blockchain links between deposits and withdrawals, making recovery efforts more difficult.

Another incident highlighted by PeckShield the same day was the one where a “UXLink exploiter labeled address has swapped 248 $WBTC for 23M $DAI within the last hour.”

The on-chain security firm added that “This follows the Sept. 22 hack, where the attacker minted billions of unauthorized tokens and drained tens of millions in crypto assets.”

Crypto industry grapples with losses

The December theft forms part of an increasing pattern of crypto breaches that saw over $117.8 million lost to exploits, according to industry data. In November 2025, around $127 million was lost, with about $45 million frozen or recovered from that loot, according to data from cybersecurity firm Certik.

December saw several significant incidents, including a $50 million address poisoning attack and the exploit of Trust Wallet’s browser extension that saw losses run up to over $8.5 million.

A recent Chainalysis report pointed out that the top ten cryptocurrency hacks of 2025 resulted in a combined loss that exceeded $2.2 billion of the $3.4 billion that was stolen in the crypto industry. The report came out before the Trust Wallet exploit later in December.

The December breach ranks among the year’s most significant private key compromises, a category of attack that security experts consider devastating due to the complete control it grants perpetrators.

Phishing and wallet compromises ranked first and second by category in terms of the amount lost to breaches in December. Despite ongoing monitoring by blockchain security firms, no recovery efforts have been announced.

The attacker’s leveraged position on Aave presents more challenges to an already complicated issue, as liquidation of the collateral could trigger market movements. However, it will also provide opportunities for tracking if the perpetrator attempts to extract value.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.

Share to:

This content is for informational purposes only and does not constitute investment advice.

Curated Series

SuperEx Popular Science Articles Column

SuperEx Popular Science Articles Column

This collection features informative articles about SuperEx, aiming to simplify complex cryptocurrency concepts for a wider audience. It covers the basics of trading, blockchain technology, and the features of the SuperEx platform. Through easy-to-understand content, it helps users navigate the world of digital assets with confidence and clarity.

Unstaked related news and market dynamics research

Unstaked related news and market dynamics research

Unstaked (UNSD) is a blockchain platform integrating AI agents for automated community engagement and social media interactions. Its native token supports governance, staking, and ecosystem features. This special feature explores Unstaked’s market updates, token dynamics, and platform development.

XRP News and Research

XRP News and Research

This series focuses on XRP, covering the latest news, market dynamics, and in-depth research. Featured analysis includes price trends, regulatory developments, and ecosystem growth, providing a clear overview of XRP's position and potential in the cryptocurrency market.

How do beginners trade options?How does option trading work?

How do beginners trade options?How does option trading work?

This special feature introduces the fundamentals of options trading for beginners, explaining how options work, their main types, and the mechanics behind trading them. It also explores key strategies, potential risks, and practical tips, helping readers build a clear foundation to approach the options market with confidence.

What are the risks of investing in cryptocurrency?

What are the risks of investing in cryptocurrency?

This special feature covers the risks of investing in cryptocurrency, explaining common challenges such as market volatility, security vulnerabilities, regulatory uncertainties, and potential scams. It also provides analysis of risk management strategies and mitigation techniques, helping readers gain a clear understanding of how to navigate the crypto market safely.