CoinTrust

Avici Hit by $1.02 Million Exploit as Funds Move to Tornado Cash

avici money

Avici has suffered a cryptocurrency exploit estimated at about $1.02 million, with the attacker moving funds through multiple blockchain transactions and converting the assets into USDC and Ethereum before transferring the proceeds to Tornado Cash.

The incident involved approximately 10,000 SOL being transferred to a secondary wallet controlled by the attacker. The funds were subsequently exchanged for roughly $1.02 million in USDC. The attacker then moved the proceeds across blockchain networks before converting the stablecoin holdings into approximately 418 ETH.

The attack resulted in about $1.02 million worth of assets being diverted from Avici, with the stolen SOL converted through USDC and ultimately into approximately 418 ETH.

The sequence indicates that the attacker used several stages to separate the original assets from their eventual destination. Moving the funds into a secondary wallet before conducting the swap created an additional layer between the initial transfer and subsequent transactions.

After the SOL was exchanged for USDC, the attacker bridged the funds to another network and converted the proceeds into Ethereum. The use of multiple assets and blockchain environments can make the movement of stolen cryptocurrency more difficult to track as investigators attempt to establish the complete transaction path.

Funds moved through multiple conversion stages

The reported transaction trail began with the transfer of 10,000 SOL from Avici-related holdings to a secondary wallet. At the prevailing value reflected in the incident report, the SOL represented approximately $1.02 million.

Rather than retaining the stolen cryptocurrency in its original form, the attacker converted the SOL into USDC. Stablecoins such as USDC can provide a relatively stable dollar-denominated value while also allowing funds to be transferred across blockchain networks.


The attacker subsequently bridged the USDC proceeds and exchanged them for approximately 418 ETH. This conversion represented another significant change in the composition of the assets involved in the incident.

Such multi-stage movements can complicate investigations because each conversion generates additional transactions across potentially different blockchain environments. Investigators typically rely on publicly visible transaction records to follow these movements and identify connections between wallets.

The reported activity shows that the attacker did not immediately move the stolen funds into a single destination. Instead, the assets were divided across several stages involving wallet transfers, token swaps, cross-chain movement, and another conversion.


Ethereum transfer followed the asset conversion

After obtaining approximately 418 ETH, the attacker deposited the funds into Tornado Cash. The reported destination was an address beginning with 0x2cE21E4921d3Eb116526c3651Dac0257657338D5.

The movement of the converted ETH into Tornado Cash represents the final stage identified in the reported transaction sequence and could make subsequent tracing of the funds more challenging.

Tornado Cash is a cryptocurrency mixing protocol designed to obscure connections between deposited and withdrawn digital assets. Its use in the reported transaction therefore adds another layer to the movement of the funds after the initial exploit.

The incident highlights the continuing risks faced by cryptocurrency projects and users holding assets across decentralized networks. Attackers can move stolen funds through different tokens and blockchain ecosystems relatively quickly, creating challenges for security teams and investigators attempting to respond to an exploit.


The reported $1.02 million loss also demonstrates how a single compromise can lead to a complex chain of transactions. In this case, the progression from SOL to USDC, followed by a cross-chain transfer and conversion into ETH, created several distinct stages in the movement of the assets.

As per the reported transaction trail, the funds eventually reached the identified Tornado Cash address after the attacker completed the asset conversions. Further movement of the cryptocurrency would determine whether investigators can continue following the proceeds or identify additional wallets connected to the incident.

The Avici exploit adds to the broader security concerns surrounding digital asset platforms, where rapid transfers and cross-chain swaps can complicate efforts to freeze, recover, or trace funds following a breach. The incident also underscores the importance of transaction monitoring and rapid detection when large cryptocurrency balances move unexpectedly.

Exit mobile version