Onchain data reveals that the wallet exploited in last year’s Balancer V2 breach, which drained approximately $116 million from the protocol’s liquidity pools, has become active again after a five-month hiatus. The address has moved 1,100 ether (ETH), currently worth about $2.55 million, through Thorchain, a decentralized cross-chain liquidity protocol, and is converting the funds into bitcoin (BTC). The movement was first flagged by blockchain monitoring service Lookonchain, once again highlighting the ongoing challenges in tracking and recovering stolen crypto assets.
Wallet Reactivation: Silence and Timing
The exploiter transferred the 1,100 ETH over the course of roughly one hour, gradually converting the proceeds into BTC via Thorchain. Thorchain’s architecture allows assets to move between blockchains without centralized intermediaries or know-your-customer (KYC) requirements, making it a recurring route for stolen funds seeking conversion into less traceable assets. The ETH-to-BTC path is particularly favored because it shifts funds out of the Ethereum ecosystem, where asset freezes and blacklists are more easily coordinated, into bitcoin’s UTXO-based system, which distributes traceability across a much larger set of addresses, thereby complicating tracking efforts.
The reactivation after five months of dormancy aligns with a pattern seen in major crypto exploits. Attackers often let wallets go quiet long enough for active monitoring to subside before beginning to move funds, a tactic designed to outlast both law enforcement attention and onchain alert systems maintained by firms like Lookonchain, Peckshield, and ZachXBT. The five-month gap places this movement well beyond the initial response window for the original breach, suggesting the attacker deliberately waited for attention to wane.
The Balancer Breach and Its Aftermath
The original hack occurred in 2025 when Balancer’s V2 pools were exploited due to a batch swap rounding bug. The attacker systematically drained approximately $116 million from multiple pools, making it one of the most consequential decentralized finance (DeFi) hacks of that year. In the aftermath, Balancer Labs announced the shutdown of its company structure, transferring control of the protocol to its decentralized autonomous organization (DAO). The incident spurred broader industry reflection on smart contract security, a debate that gained renewed urgency in April 2026 following the $292 million KelpDAO exploit and its downstream impact on Aave’s lending markets.
Laundering Patterns and Wider Trends
The Thorchain-based ETH-to-BTC conversion route mirrors laundering approaches observed by onchain analysts in connection with prior high-profile hacks, including a case where a Kraken user lost $18.2 million in a social engineering attack, with funds later routed through Thorchain by the exploiter. The reactivation of the Balancer exploiter’s wallet is part of a growing list of dormant exploit proceeds showing signs of movement in 2026—a trend that can be attributed in part to improving market liquidity, providing better exit conditions for large illicit positions. Thorchain’s governance does allow validators to vote for temporary halts on specific chains when malicious activity is detected, a mechanism deployed before during major incidents. However, such votes are rare, require independent validator coordination, and are reversible, making Thorchain a persistently attractive option for exploit proceeds needing to move quickly.
The Balancer exploiter’s latest move underscores that the repercussions of DeFi vulnerabilities can linger for years, while cross-chain laundering techniques continue to evolve. Protocols, exchanges, and regulators will need to collaborate more closely to counter increasingly sophisticated onchain criminal activity.

