Balancer Exploiter Resurfaces After 5 Months, Moves 1,100 ETH Through Thorchain

Balancer Exploiter Resurfaces After 5 Months, Moves 1,100 ETH Through Thorchain

N
News Editor 01
2026-07-08 18:56:18
The Balancer V2 exploiter who stole $116 million reactivated after five months, moving 1,100 ETH ($2.55M) into BTC via Thorchain. The move follows a pattern seen in major hacks and highlights ongoing challenges in DeFi security and anti-money laundering.
BalancerEthereumBitcoinThorchainDeFi Security

On-chain data has revealed that a wallet linked to the Balancer exploit—which drained nearly $116 million from the protocol’s V2 liquidity pools in 2025—has resurfaced after five months of dormancy. The wallet transferred 1,100 ether (ETH), valued at approximately $2.55 million, through the cross-chain liquidity protocol Thorchain, converting the funds into bitcoin (BTC) within about an hour. The activity was first flagged by Lookonchain, a blockchain analytics firm, and has reignited concerns about the persistence of exploiters and the challenges of monitoring decentralized finance (DeFi) platforms.

Breaking the Silence: Laundering Through Thorchain

According to Lookonchain's tracking, the exploiter executed the transfers in multiple transactions, rapidly moving 1,100 ETH before routing them through Thorchain to swap for BTC. Thorchain is a decentralized cross-chain protocol that enables asset transfers between blockchains without requiring Know-Your-Customer (KYC) verification or centralized intermediaries. This lack of identity controls has made Thorchain a preferred tool for illicit actors looking to convert stolen funds into harder-to-trace assets.

The ETH-to-BTC route is particularly attractive to hackers: it removes funds from the Ethereum ecosystem, where centralized exchanges and DeFi protocols can more easily blacklist addresses or freeze assets, and places them into Bitcoin's UTXO-based architecture. Bitcoin's transaction model distributes traceability across a vast number of addresses, significantly complicating blockchain forensic efforts. The five-month gap between the original breach and this fund movement aligns with a well-documented tactic used by major crypto attackers: they allow wallets to go dormant long enough for active monitoring to wane before beginning to move funds, attempting to outlast both law enforcement attention and automated alerts from services like Lookonchain, Peckshield, and ZachXBT.

Thorchain's architecture does include a mechanism for validators to vote for temporary halts on specific chains when malicious activity is detected—a feature that was activated in previous incidents. However, such votes require independent validator coordination, are rarely used, and are reversible. This makes Thorchain a persistently attractive option for exploit proceeds that need to be moved quickly and with limited friction.

The Original Balancer Breach and Its Aftermath

The Balancer exploit that took place in 2025 was one of the most consequential DeFi hacks of the year, siphoning approximately $116 million from the protocol's V2 liquidity pools. The attack exploited a batch swap rounding bug that allowed the hacker to systematically drain funds from multiple pools. The financial and reputational damage was severe: Balancer Labs subsequently announced it would shut down as a company, transferring control of the protocol's future to its decentralized autonomous organization (DAO). The protocol has since operated under a leaner, community-led structure.

The incident also contributed to a broader industry reckoning over smart contract security—a debate that gained fresh urgency in April 2026 following the $292 million KelpDAO exploit and its downstream impact on Aave's lending markets. The reappearance of the Balancer exploiter's wallet is part of a growing trend in 2026 where previously dormant hack proceeds are beginning to move, likely driven in part by improving market liquidity that provides better exit conditions for large illicit positions.

Pattern Recognition and Implications

The use of Thorchain for the ETH-to-BTC conversion closely mirrors laundering techniques flagged by on-chain analysts in prior high-profile hacks. For example, in a case where a Kraken user lost $18.2 million in a social engineering attack, the attacker also routed funds through Thorchain. This consistency suggests that hackers are relying on well-tested infrastructure to launder their gains, exploiting the same decentralized tools that legitimate users rely on for cross-chain interoperability.

The reactivation of the Balancer exploiter's wallet underscores the persistent threat posed by DeFi flash loan attacks and smart contract exploits. Even months or years after an incident, attackers may still attempt to move funds when they perceive the risk of detection to be lower. For regulators, exchanges, and DeFi platforms, this event highlights the urgent need for enhanced monitoring of cross-chain transactions and the development of industry-wide anti-money laundering (AML) standards. Strengthening smart contract audits, bug bounty programs, and real-time on-chain surveillance systems are critical steps to reduce the likelihood of such attacks and to improve the recovery of stolen assets.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.