In July 2026, the payment service provider Triple-A's own vault was hacked, with estimated losses publicly approximated at 11.8 million USD. The stolen assets were subsequently bridged to Ethereum and exchanged for various tokens, splitting and transferring on-chain. Almost three months later, the attack path experienced a critical turning point: according to monitoring by the blockchain security company Salus, on October 10, 2026, the attackers, after completing multiple rounds of fund aggregation, deposited a total of 4,970 ETH into the privacy mixing protocol Tornado Cash on Ethereum, splitting it into 56 transactions injected into the pool, with 49 transactions of 100 ETH and 7 transactions of 10 ETH, the rhythm of these actions was highly deliberate. This 4,970 ETH, valued at approximately 12.4 million USD, has been confirmed by several Chinese media citing Salus's data, and its scale not only slightly exceeds the initial estimated public loss of about 11.8 million USD, but also leaves a difference of several hundred thousand dollars in the digital dimension, the specific reason for which has not yet been publicly explained. After the funds completely entered the mixer, what was originally still in the tracking stage of the attack case was pushed into a new processing cycle, making subsequent on-chain tracking and law enforcement games more complex and prolonged.
Layered Transfer of Hacker Funds Within Three Months
From the theft of Triple-A's vault in July 2026 to the large-scale influx of funds into Tornado Cash in October, the attackers completed a typical "layered" path over three months. After the incident occurred, the stolen assets were first bridged to Ethereum and then underwent multiple rounds of asset exchange and continued transfer on-chain, creating distance between the original attack transactions and subsequent fund trajectories by constantly changing the forms of assets and resting addresses. This stage essentially laid the groundwork for more concealed operations that followed.
Entering September, on-chain behavior began to exhibit a clearer rhythm of "splitting - aggregating - mixing." According to on-chain monitoring on September 6, the attackers split part of the funds into two independent cash flows, attempting to weaken the direct connection between a single wallet and the Triple-A theft event through the dimensional diversification of addresses; some material noted that one of these cash flows had a withdrawal record from the mixer on October 9, but this detail still requires further verification. The real key node appeared around October 10—previously split two cash flows were re-aggregated into a single wallet, and after completing this "aggregation" action, the attackers uniformly injected a total of 4,970 ETH in batches into Tornado Cash, transforming the aggregation wallet from "dispersed traces" to "deep concealment," marking the funds' shift from the linearly traceable stage into the high-noise mixing stage.
4970 ETH Entering Tornado as a Turning Point for Money Laundering
The step on October 10 showed an extremely "neat" performance on-chain: the aggregation wallet made 56 deposits to Tornado Cash, with 49 transactions of 100 ETH each, and the remaining 7 transactions of 10 ETH each, totaling exactly 4,970 ETH. Based on public price estimates, this batch equates to about 12.4 million USD, slightly higher than the previously estimated loss of approximately 11.8 million USD announced in July, with the tens of thousands of dollars difference currently lacking a clear explanation. From the moment the linear cash flow was momentarily sliced into 56 independent entries, the narrative of the stolen assets from Triple-A on Ethereum completely shifted from "single-line tracking" to "high noise mixing."
The attackers' choice of this highly standardized splitting method itself is a signal of risk control: a large direct injection into a privacy protocol is more prone to be flagged as anomalous, while multiple transactions with close amounts and unified rhythms are more aligned with common mixing templates, attempting to "blend into the environment" within the overall anonymous collection. The denomination design of 100 ETH and 10 ETH also reserves more granular selection space for subsequent withdrawals, enabling different addresses to withdraw in batches at different times, further weakening the correspondence between individual withdrawals and the original theft event. For on-chain analysts, after this concentrated mixing node, the re-labeling and ownership judgment of funds will no longer rely on clear paths but will instead seek probabilistic anomalies within a vast anonymous collection, significantly raising the technical threshold and time costs for recovering assets caused by this deposit action of 4,970 ETH.
Questions on Theft of 11.8 Million and Money Laundering of 12.4 Million
According to Salus and various media reports, the 4,970 ETH sent to Tornado Cash on October 10 by the attackers was estimated at around 12.4 million USD at that time, while the stolen amount publicly disclosed in July was approximately 11.8 million USD. Some materials even mentioned a process of raising the estimate from around 9.3 million USD to 11.8 million USD, but this numerical correction still requires further confirmation. In terms of static USD measurements, the scale of funds mixed into Tornado exceeds the original loss estimate by about 600,000 USD, yet there is no public statement clarifying whether this discrepancy stems from changes in valuation criteria or if additional undisclosed assets entered the same money laundering path.
Given the limited evidence currently available, what can be done is to enumerate possible explanations rather than selecting one as a conclusion: on the one hand, from July to October, the price of ETH itself experienced fluctuations; converting the same batch of chips at different market prices at different times can easily yield a difference of hundreds of thousands of dollars at the dollar level; on the other hand, it cannot be ruled out that the attackers aggregated additional assets from other sources in subsequent operations, or that early statistics did not fully cover all damaged positions, these are merely unverified speculations. Readers need to deliberately distinguish between facts confirmed by on-chain and official information and reasonings derived from numerical differences, and should not misread the correlation between "4,970 ETH ≈ 12.4 million USD" and "July losses of about 11.8 million USD" as some inevitable causal relationship; until more on-chain and official information emerges, this 600,000 USD difference can only be regarded as an ongoing open question that should not be prematurely concluded.
Tornado: Privacy Tool or Hacker Haven
In the technical narrative, Tornado Cash is designed as a privacy mixing protocol on Ethereum: by disrupting the order of deposits and withdrawals, standardizing denominations, etc., it weakens the traceability between single addresses, allowing ordinary users to gain privacy space on-chain that resembles "cash transactions." However, from the compliance and risk control perspective, this intentionally created "observation blind spot" naturally generates tension with anti-money laundering and traceability requirements; once a large amount of involved funds rushes in, the privacy tool is quickly labeled as a "source of compliance risk."
In the Triple-A case, after the hackers completed cross-chain, exchange, and path splitting in the early stage, they ultimately chose to consolidate the funds into Tornado, clearly selecting the most controversial tool among many. According to AiCoin data, around October 10, 2026, the attackers re-merged the previously split funds through a single aggregation wallet, making 56 transactions to deposit a total of 4,970 ETH, approximately 12.4 million USD, this key money laundering node has been cross-verified by on-chain monitoring and public reporting. Given that numerous high-profile attacks have seen stolen funds enter the same mixing protocol, Tornado is gradually shifting in public discourse from "privacy tool" to "hackers' common haven," and its past history of being named in sanctions by some regulatory and law enforcement agencies raises the stakes; every large influx of capital becomes not just a detail of a single attack case, but a new tug-of-war in the long-term game surrounding privacy, compliance, and on-chain security.
What Other Variables Emerge After Increased Tracking Difficulty
As 4,970 ETH is split and injected into Tornado Cash, the on-chain path of Triple-A's stolen funds has been thoroughly "dispersed" on the surface, with traditional address tracking and fund aggregation logic encountering real bottlenecks. As of October 10, 2026, according to publicly available materials, there have been no substantial breakthroughs in identifying the attackers or recovering assets, and related details of law enforcement and compliance cooperation have not been disclosed, with concrete progress awaiting further verification. In this situation, observable variables mainly stem from two ends: one end is whether Tornado-related addresses will show withdrawals in the future, whether funds will re-enter the public market, which will become new on-chain clues; the other end is the communication rhythm between Triple-A and external security teams and law enforcement agencies, along with the subsequent monitoring results disclosed by security agencies like Salus, which can supplement the market with verifiable information. The funds have entered the privacy protocol, but whether there will be new actions regarding the attackers' identity, recovery paths, and cross-jurisdictional regulatory coordination will determine whether this case of the payment service provider theft will be classified as a "long-term unsolved case" or gradually pulled back into the traceable range through a lengthy game.
Join our community to discuss together and become stronger!
Exclusive Hyperliquid benefits for AiCoin: https://app.hyperliquid.xyz/join/AICOIN88
Exclusive Aster benefits for AiCoin: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。




