According to on-chain analyst aryan's disclosure on the X platform, in the attack incident on the Drift protocol treasury, the attacker's address obtained funds through NEAR Intents 8 days ago but remained inactive until receiving a large amount of assets from the Drift treasury.
The attacker transferred the funds to multiple money laundering addresses. Notably, these money laundering addresses received funds through Backpack yesterday, and Backpack should have conducted KYC verification on these accounts. Subsequently, the money laundering addresses transferred the funds to an Ethereum address via Wormhole, which had previously received funds through Tornado Cash.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























