Go to app

How did 3200 ETH get successfully laundered

Published 7/5/2026, 4:53:07 PM

The 3,200 ETH laundering incident (approximately $5.5 million) occurred between July 2 and July 3, 2026, involving a sophisticated multi-stage operation that leveraged Tornado Cash and Circle's Cross-Chain Transfer Protocol (CCTP) to move funds to KuCoin via the Arbitrum network [Source: https://www.kucoin.com/news/flash/zachxbt-discloses-5-5m-eth-theft-via-tornado-cash-and-cctp-bridge].

Answer

The laundering operation was characterized by a "textbook" decentralized money laundering route, moving from initial theft to a centralized exchange exit point.

1. Method and Fund Flow

The operation followed a five-stage process to obfuscate the origin of the funds:

2. Technical Details of CCTP Exploitation

The use of CCTP was a critical technical choice for the launderers. Unlike traditional bridges that lock and unlock assets, CCTP uses a burn-and-mint mechanism:

  • Native Transfer: USDC is burned on the source chain (Ethereum) and a fresh, native version is minted on the destination chain (Arbitrum).
  • Permissionless Nature: The protocol is permissionless, allowing the attacker to integrate it into their laundering script without requiring approval from Circle, provided the funds were not blacklisted at the moment of the burn.
  • Speed and Liquidity: CCTP allowed the attacker to move $5.5 million in a single, highly liquid asset (USDC) without the slippage or "wrapped asset" risks associated with third-party bridges.

3. Incident Summary Table

MetricDetail
Total Amount3,200 ETH (~$5.5 million USD)
Date of OperationJuly 2–3, 2026
Primary ToolsTornado Cash, Circle CCTP
Destination ChainArbitrum
Exit PointKuCoin (7 deposit addresses)
AttributionZachXBT, Huoxing Finance

The incident highlights a growing trend where attackers favor native cross-chain protocols like CCTP over traditional bridges to move large volumes of stolen assets across ecosystems quickly.

Evidence Snippets

Claim: 3,200 ETH was laundered via CCTP to KuCoin on Arbitrum.

Claim: The funds originated from private key compromises and were mixed via Tornado Cash.

Claim: The funds were distributed across seven Arbitrum addresses.

Claim: KuCoin has a history of AML deficiencies that facilitate such laundering.