An Ethereum wallet linked to the Aztec Private Rollup Bridge exploit has moved another 300 ETH to Tornado Cash.
The latest transfer was worth around $572,000 at the time of the transaction. It brings the total amount sent from the wallet to the mixer to 500 ETH, valued at about $953,000.
The movements are linked to a June exploit that affected an older Aztec bridge contract. The attack resulted in losses of roughly $2.165 million.
Another 300 ETH moved through Tornado Cash
Blockchain security firm PeckShield reported on Aug. 8 that an address associated with the Aztec Private Rollup Bridge attacker had sent 300 ETH to Tornado Cash.
The transfer was made in three separate transactions of 100 ETH each.
At the time of PeckShield’s report, the 300 ETH was worth approximately $572,000. With the new transfers, the wallet has now sent a total of 500 ETH to Tornado Cash.
There is no public information identifying who controls the address.
There is also no indication that any of these funds have been recovered.
Tornado Cash is a crypto mixing service. It combines deposits from different users and allows funds to later be withdrawn to other addresses. This can make it harder to follow the movement of cryptocurrency on the blockchain.
That is one reason why mixers are often used when stolen crypto is being moved.
The original Aztec attack caused millions in losses
The transfers are connected to an exploit involving the Aztec Private Rollup Bridge in June.
Reports at the time estimated the losses at about $2.165 million. The assets involved reportedly included 1,158 ETH, 150,000 DAI and 0.47 renBTC.
Aztec later clarified that the affected bridge was an old product. It was not part of the current Aztec network and was not connected to the project’s AZTEC token.
The incident also highlighted the risks of older crypto infrastructure that is no longer actively maintained.
The attacker was able to exploit a weakness in the bridge contract and withdraw assets that were not properly backed.
According to security researchers, the issue involved a difference between transactions covered by a zero-knowledge proof and the transactions actually processed during settlement.
This allowed the attacker to create balances that did not correspond to real deposits.
Why the old contract could not be stopped
One of the problems with the affected system was that Aztec Labs no longer had control over the contract.
The project had previously given up its administrative keys. This meant the contract could not simply be paused or upgraded after the vulnerability was discovered.
That design made the old system resistant to changes, but it also meant that the team had limited options once the exploit happened.
The incident involved infrastructure that had already been discontinued.
It was also separate from the current Aztec network.
Other stolen crypto has also moved through Tornado Cash
The Aztec transfers are not an isolated case.
Attackers behind other crypto exploits have also used Tornado Cash to move large amounts of Ethereum.
In July, a wallet associated with the Drift Protocol exploit moved 23,095 ETH through Tornado Cash. The funds were worth around $44.4 million at the time.
A wallet linked to the Radiant Capital attack also transferred 2,834 ETH to the mixer.
Another exploiter connected to Cork Protocol reportedly moved around 4,520 ETH through Tornado Cash.
These cases show a common pattern. Attackers often convert different stolen assets into ETH and then move the funds through several addresses or mixing services.
That does not necessarily make the funds impossible to track. Blockchain transactions remain publicly visible, and security companies continue to monitor addresses linked to major attacks.
But tracing the final destination can become much harder after funds pass through a mixer.
Tornado Cash remains a controversial service
Tornado Cash has been under close attention from US authorities for several years.
In March 2025, the US Treasury removed Tornado Cash and related smart-contract addresses from its sanctions list. The move followed a federal appeals court decision that found the Treasury had gone beyond its authority by sanctioning immutable smart contracts.
The decision did not remove concerns around the use of crypto mixers.
US authorities have continued to focus on the role of such services in money laundering, sanctions evasion and cybercrime. Officials have also raised concerns about their use by hacking groups linked to North Korea.
The latest Aztec-related transfer therefore comes against a much larger debate over privacy tools and the use of crypto mixers.
More funds could still move
The 500 ETH already sent to Tornado Cash represents only part of the assets associated with the Aztec exploit.
The original attack was estimated to involve around $2.165 million in losses.
It is not yet clear what happened to the remaining funds.
Further transactions from the exploiter’s wallet could provide more information. The address could send additional ETH to Tornado Cash, move the assets to other wallets, or use other services.
For now, the latest 300 ETH transfer shows that the wallet linked to the Aztec exploit remains active months after the original attack.
