A wallet linked to the $116 million Balancer V2 exploit has suddenly reactivated after five months of dormancy, with on-chain data from Lookonchain showing the movement of 1,100 ether (worth approximately $2.55 million) through Thorchain, a decentralized cross-chain liquidity protocol. The funds are being converted from ETH to BTC, a route that has become a favored laundering path for major crypto heists due to Thorchain's lack of KYC controls and Bitcoin's UTXO architecture, which makes tracing significantly harder.
Wallet Reactivation and Tactical Timing
The exploiter moved the 1,100 ETH in roughly one hour, using Thorchain's native swap mechanism to funnel assets across blockchains without intermediaries. The five-month gap between the original breach and this wallet activity is consistent with a well-documented pattern: attackers purposely keep stolen funds dormant long enough to outlast the initial response window of law enforcement and blockchain monitoring services such as Lookonchain, Peckshield, and ZachXBT. By reappearing when attention has faded, the hacker reduces the risk of immediate intervention.
Thorchain's validators do have the ability to vote for temporary halts on specific chains when malicious behavior is detected—a mechanism deployed in past incidents. However, such votes require independent coordination among validators and are reversible, making Thorchain a persistently attractive option for hackers looking to move funds swiftly under the radar.
The Original Balancer Breach: A Defining Moment for DeFi
The Balancer exploit, which drained approximately $116 million from the protocol's V2 liquidity pools in 2025, was one of the most consequential decentralized finance (DeFi) hacks of the era. The attacker exploited a batch swap rounding bug in Balancer's smart contracts, systematically draining funds across multiple pools. The financial and reputational damage forced Balancer Labs to shut down as a company, handing over protocol governance to its decentralized autonomous organization (DAO).
The incident triggered a wider industry reckoning about smart contract security—a debate that gained fresh urgency in April 2026 after the $292 million KelpDAO exploit and its cascading impact on Aave's lending markets.
Laundering Pattern and Broader Market Trends
The ETH-to-BTC conversion through Thorchain mirrors laundering methods flagged in prior high-profile hacks, including a case where a Kraken user lost $18.2 million in a social engineering attack with funds later routed through Thorchain. The reactivation of the Balancer wallet is part of a growing list of dormant exploit proceeds showing signs of movement in 2026, a trend attributed partly to improving market liquidity, which provides better exit conditions for large illicit positions.
As of publication, the wallet still holds a significant amount of other assets, and analysts expect further movements. The case serves as a stark reminder that DeFi vulnerabilities continue to fuel sophisticated laundering operations, even as the industry pushes for stronger security standards.

