In mid-November of last year, a cyber criminal successfully pulled off a $25 million exploit on the quantitative trading firm Kronos Research. It has now been discovered that this perpetrator has started to move the funds, nearly six months after the initial attack. The hacker transferred 1,314 Ether (ETH), equivalent to $4 million, to a new wallet address. This ETH was then further transferred to another address. The hacker then made 10 transactions of 100 ETH each and sent it to Tornado Cash, a cryptocurrency tumbling tool.

Tornado Cash is an open-source cryptocurrency mixer that operates on platforms compatible with the Ethereum Virtual Machine. These mixing services aim to obscure the trail of crypto transactions, making it extremely difficult to trace the original source of the funds. While the tool was created for privacy purposes, it has unfortunately become a favored choice for hackers looking to launder stolen funds through decentralized exchange platforms. The widespread use of Tornado Cash for illicit transactions prompted the United States government to take action and impose sanctions on its use in August 2022. As a result, the founders of Tornado Cash were charged with money laundering and sanctions violations a year later.

Opinions within the cryptocurrency community vary when it comes to the adoption of privacy tools like Tornado Cash. There is a consensus that developers and creators should not face government persecution solely for creating such applications. On that note, the crypto analytic firm PeckShield has raised the alarm about the movement of funds from the Kronos Research exploit. They have warned that the transfer to Tornado Cash suggests that the hacker is attempting to launder the stolen funds.

The attack on Kronos Capital took place in November 2023, and it involved the exploitation of the firm’s API keys. Initially, the firm denied any loss of funds, but later, an on-chain investigator named ZachXBT revealed that approximately 12,800 ETH, worth $25 million, was stolen and moved into six different crypto wallet addresses. In response to the incident, Kronos Capital temporarily suspended its trading services to conduct an investigation into the loss.

