A sophisticated attacker who compromised a multi-signature wallet and stole $27.3 million has now laundered $19.4 million through privacy protocol Tornado Cash A sophisticated attacker who compromised a multi-signature wallet and stole $27.3 million has now laundered $19.4 million through privacy protocol Tornado Cash

Hacker Drains $27M From Multi-Sig Wallet, Launders $19M via Tornado Cash

2026/01/06 23:01
4 min read

A sophisticated attacker who compromised a multi-signature wallet and stole $27.3 million has now laundered $19.4 million through privacy protocol Tornado Cash while maintaining a leveraged trading position worth nearly $10 million.

The incident, first detected by blockchain security firm PeckShield, marks the latest in a series of major exploits targeting crypto holders in early 2026.

PeckShield reported that the drainer withdrew 1,000 ETH, worth $3.24 million, from the lending platform Aave before depositing it into Tornado Cash, joining 6,300 ETH already laundered through the mixing service.

The attacker, who controls the compromised multi-signature wallet, simultaneously holds a $9.75 million leveraged long position consisting of $20.5 million in ETH against $10.7 million in DAI.

Wave of Exploits Hits Crypto Platforms

The multi-sig wallet drain occurred alongside multiple other security incidents detected within the past 24 hours.

PeckShield identified address 0xB8b4…3714 actively laundering 2,479.1 ETH, worth $7.9 million, through Tornado Cash, with funds originating from multiple TRON wallets before being bridged to Ethereum.

The investigators linked the attack to a “pig-butchering” investment scam that typically lures victims through fake romantic relationships before stealing their crypto holdings.

Separately, the exploiter behind September’s UXLink hack swapped 248 wrapped Bitcoin for 23 million DAI within an hour, moving stolen assets from an attack that minted billions of unauthorized tokens.

Blockchain security firm CertiK simultaneously flagged another $1.4 million exploit on an unverified contract related to TMXTribe on Arbitrum.

The attackers repeatedly minted and staked TMX LP with USDT, swapped for USDG, then unstaked and sold more USDG to drain USDT alongside wrapped SOL and WETH through a looping mechanism executed multiple times.

These exploits follow closely after hardware wallet manufacturer Ledger disclosed that customer data, including names, postal addresses, emails, and phone numbers, was accessed through a breach at payment processor Global-e on January 5.

While Ledger confirmed no payment card details, passwords, or private keys were exposed, security researchers warned that the leak significantly increases phishing and social engineering risks.

Particularly, given Ledger’s history of data breaches, dating back to a devastating 2020 incident that exposed 1.1 million email addresses and detailed personal information for approximately 292,000 customers, whose data was later dumped publicly.

Physical Security Risks Escalate for Crypto Holders

The Ledger breach has intensified concerns about physical attacks targeting cryptocurrency holders, particularly as violent incidents against users reach unprecedented levels.

Blockchain researcher Ignas, who confirmed receiving notification of his leaked data, warned that “wrench physical attacks are getting more common and I believe if economy & world gets more unstable, these attacks will become serious issue for crypto users.

Security researcher NanoBaiter also cautioned that “threat actors are probably using this data for social engineering attacks and phishing emails,” while another analyst warned that cross-referencing the 2020 and 2025 Ledger datasets with AI tools allows attackers to identify high-value targets with a very good precision.

Investor Haseeb Qureshi’s analysis of physical violence data showed attacks against crypto users have increased over time and grown more violent.

However, he noted that “some of this is just population effects because there are more people who hold crypto now.

Rezo, a Ledger user himself, emphasized the centralization risk inherent in crypto infrastructure, stating that “as long as crypto products depend on centralized infrastructure (payment processors, shipping, email), we’re exposed.

He added that while “Ledger didn’t get hacked, their payment processor did,” the leaked name and contact information create “perfect phishing material.”

December 2025 saw crypto hack losses drop 60% month-over-month to $76 million according to PeckShield, down from November’s $194.2 million.

Despite the decline, major incidents continue occurring, including a $50 million address poisoning scam, a $27.3 million private key leak, and Trust Wallet’s Christmas Day exploit that drained $7 million through a compromised browser extension.

As it stands now, security experts have advised victims whose information was exposed to be very cautious of phishing emails and spam, possibly change their location for safety, and use temporary details and addresses for deliveries, etc.

Market Opportunity
Ambire Wallet Logo
Ambire Wallet Price(WALLET)
$0.00785
$0.00785$0.00785
0.00%
USD
Ambire Wallet (WALLET) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

American Bitcoin’s $5B Nasdaq Debut Puts Trump-Backed Miner in Crypto Spotlight

American Bitcoin’s $5B Nasdaq Debut Puts Trump-Backed Miner in Crypto Spotlight

The post American Bitcoin’s $5B Nasdaq Debut Puts Trump-Backed Miner in Crypto Spotlight appeared on BitcoinEthereumNews.com. Key Takeaways: American Bitcoin (ABTC) surged nearly 85% on its Nasdaq debut, briefly reaching a $5B valuation. The Trump family, alongside Hut 8 Mining, controls 98% of the newly merged crypto-mining entity. Eric Trump called Bitcoin “modern-day gold,” predicting it could reach $1 million per coin. American Bitcoin, a fast-rising crypto mining firm with strong political and institutional backing, has officially entered Wall Street. After merging with Gryphon Digital Mining, the company made its Nasdaq debut under the ticker ABTC, instantly drawing global attention to both its stock performance and its bold vision for Bitcoin’s future. Read More: Trump-Backed Crypto Firm Eyes Asia for Bold Bitcoin Expansion Nasdaq Debut: An Explosive First Day ABTC’s first day of trading proved as dramatic as expected. Shares surged almost 85% at the open, touching a peak of $14 before settling at lower levels by the close. That initial spike valued the company around $5 billion, positioning it as one of 2025’s most-watched listings. At the last session, ABTC has been trading at $7.28 per share, which is a small positive 2.97% per day. Although the price has decelerated since opening highs, analysts note that the company has been off to a strong start and early investor activity is a hard-to-find feat in a newly-launched crypto mining business. According to market watchers, the listing comes at a time of new momentum in the digital asset markets. With Bitcoin trading above $110,000 this quarter, American Bitcoin’s entry comes at a time when both institutional investors and retail traders are showing heightened interest in exposure to Bitcoin-linked equities. Ownership Structure: Trump Family and Hut 8 at the Helm Its management and ownership set up has increased the visibility of the company. The Trump family and the Canadian mining giant Hut 8 Mining jointly own 98 percent…
Share
BitcoinEthereumNews2025/09/18 01:33
Botanix launches stBTC to deliver Bitcoin-native yield

Botanix launches stBTC to deliver Bitcoin-native yield

The post Botanix launches stBTC to deliver Bitcoin-native yield appeared on BitcoinEthereumNews.com. Botanix Labs has launched stBTC, a liquid staking token designed to turn Bitcoin into a yield-bearing asset by redistributing network gas fees directly to users. The protocol will begin yield accrual later this week, with its Genesis Vault scheduled to open on Sept. 25, capped at 50 BTC. The initiative marks one of the first attempts to generate Bitcoin-native yield without relying on inflationary token models or centralized custodians. stBTC works by allowing users to deposit Bitcoin into Botanix’s permissionless smart contract, receiving stBTC tokens that represent their share of the staking vault. As transactions occur, 50% of Botanix network gas fees, paid in BTC, flow back to stBTC holders. Over time, the value of stBTC increases relative to BTC, enabling users to redeem their original deposit plus yield. Botanix estimates early returns could reach 20–50% annually before stabilizing around 6–8%, a level similar to Ethereum staking but fully denominated in Bitcoin. Botanix says that security audits have been completed by Spearbit and Sigma Prime, and the protocol is built on the EIP-4626 vault standard, which also underpins Ethereum-based staking products. The company’s Spiderchain architecture, operated by 16 independent entities including Galaxy, Alchemy, and Fireblocks, secures the network. If adoption grows, Botanix argues the system could make Bitcoin a productive, composable asset for decentralized finance, while reinforcing network consensus. This is a developing story. This article was generated with the assistance of AI and reviewed by editor Jeffrey Albus before publication. Get the news in your inbox. Explore Blockworks newsletters: Source: https://blockworks.co/news/botanix-launches-stbtc
Share
BitcoinEthereumNews2025/09/18 02:37
Surprising New Alliance: MARA Restructures for AI Era

Surprising New Alliance: MARA Restructures for AI Era

MARA Holdings has revealed a groundbreaking partnership with Starwood Capital, aiming to revamp their existing cryptocurrency mining facilities into cutting-edge
Share
Coinstats2026/02/27 08:25