
A hacker involved in the 2022 exploit of Voltage Finance has recently moved 100 Ether (ETH)—worth about $182,783—to the privacy-focused platform Tornado Cash. This marks the first significant activity from the hacker’s wallet in over five months, with the last transaction recorded in November 2024. The transfer, which came in a single batch, was sent from an address connected to the Voltage Finance attack, a wallet that had remained inactive since the incident.
In March 2022, the hacker exploited a flaw in the ERC677 token standard’s callback function, executing a reentrancy attack that drained Voltage Finance’s lending pool. The stolen assets included a mix of USDC, BUSD, wrapped Bitcoin, and ETH. Following the attack, Voltage Finance flagged the address on Etherscan and worked with centralized exchanges to block any transactions from it. They even offered a $50,000 bounty in hopes of recovering the stolen funds.
Our alerting system has detected @TornadoCash
deposits of 100 ETH from 0xCF4823dA7271fdedBe103500d8E197Bdca224B6d.The fund traces to ~$4M Voltage Finance
exploit on Fuse back in March 2022.Stay Vigilant! pic.twitter.com/eyqH1HbN3F
— CertiK Alert (@CertiKAlert) May 6, 2025
The recent transfer of ETH to Tornado Cash is worrying, as it suggests the hacker is still trying to launder the stolen funds. Tornado Cash is a decentralized privacy tool that allows users to hide the origins and destinations of their transactions, making it a popular choice for cybercriminals seeking to cover their tracks. Despite being sanctioned by the U.S. Treasury Department in 2022 due to its links with money laundering, Tornado Cash remains operational and continues to be used for these activities.
This incident highlights the persistent challenges in tackling cryptocurrency-related crime and the urgent need for stronger security protocols and regulatory measures to prevent such actions.
Get the weekly commit
New blockchain deep dives every week.

