On-chain data has revealed that a wallet linked to the Balancer exploit—which drained nearly $116 million from the protocol’s V2 liquidity pools in 2025—has resurfaced after five months of dormancy. The wallet transferred 1,100 ether (ETH), valued at approximately $2.55 million, through the cross-chain liquidity protocol Thorchain, converting the funds into bitcoin (BTC) within about an hour. The activity was first flagged by Lookonchain, a blockchain analytics firm, and has reignited concerns about the persistence of exploiters and the challenges of monitoring decentralized finance (DeFi) platforms.
Breaking the Silence: Laundering Through Thorchain
According to Lookonchain's tracking, the exploiter executed the transfers in multiple transactions, rapidly moving 1,100 ETH before routing them through Thorchain to swap for BTC. Thorchain is a decentralized cross-chain protocol that enables asset transfers between blockchains without requiring Know-Your-Customer (KYC) verification or centralized intermediaries. This lack of identity controls has made Thorchain a preferred tool for illicit actors looking to convert stolen funds into harder-to-trace assets.
The ETH-to-BTC route is particularly attractive to hackers: it removes funds from the Ethereum ecosystem, where centralized exchanges and DeFi protocols can more easily blacklist addresses or freeze assets, and places them into Bitcoin's UTXO-based architecture. Bitcoin's transaction model distributes traceability across a vast number of addresses, significantly complicating blockchain forensic efforts. The five-month gap between the original breach and this fund movement aligns with a well-documented tactic used by major crypto attackers: they allow wallets to go dormant long enough for active monitoring to wane before beginning to move funds, attempting to outlast both law enforcement attention and automated alerts from services like Lookonchain, Peckshield, and ZachXBT.
Thorchain's architecture does include a mechanism for validators to vote for temporary halts on specific chains when malicious activity is detected—a feature that was activated in previous incidents. However, such votes require independent validator coordination, are rarely used, and are reversible. This makes Thorchain a persistently attractive option for exploit proceeds that need to be moved quickly and with limited friction.
The Original Balancer Breach and Its Aftermath
The Balancer exploit that took place in 2025 was one of the most consequential DeFi hacks of the year, siphoning approximately $116 million from the protocol's V2 liquidity pools. The attack exploited a batch swap rounding bug that allowed the hacker to systematically drain funds from multiple pools. The financial and reputational damage was severe: Balancer Labs subsequently announced it would shut down as a company, transferring control of the protocol's future to its decentralized autonomous organization (DAO). The protocol has since operated under a leaner, community-led structure.
The incident also contributed to a broader industry reckoning over smart contract security—a debate that gained fresh urgency in April 2026 following the $292 million KelpDAO exploit and its downstream impact on Aave's lending markets. The reappearance of the Balancer exploiter's wallet is part of a growing trend in 2026 where previously dormant hack proceeds are beginning to move, likely driven in part by improving market liquidity that provides better exit conditions for large illicit positions.
Pattern Recognition and Implications
The use of Thorchain for the ETH-to-BTC conversion closely mirrors laundering techniques flagged by on-chain analysts in prior high-profile hacks. For example, in a case where a Kraken user lost $18.2 million in a social engineering attack, the attacker also routed funds through Thorchain. This consistency suggests that hackers are relying on well-tested infrastructure to launder their gains, exploiting the same decentralized tools that legitimate users rely on for cross-chain interoperability.
The reactivation of the Balancer exploiter's wallet underscores the persistent threat posed by DeFi flash loan attacks and smart contract exploits. Even months or years after an incident, attackers may still attempt to move funds when they perceive the risk of detection to be lower. For regulators, exchanges, and DeFi platforms, this event highlights the urgent need for enhanced monitoring of cross-chain transactions and the development of industry-wide anti-money laundering (AML) standards. Strengthening smart contract audits, bug bounty programs, and real-time on-chain surveillance systems are critical steps to reduce the likelihood of such attacks and to improve the recovery of stolen assets.

