The attacker moved again. Another 300 ETH has entered Tornado Cash from the Aztec Network Private Rollup Bridge exploit address. Cumulative: 500 ETH. PeckShield flagged the address; funds keep moving. The bridge was compromised for approximately $2.165 million. We do not guess the crash; we trace the fault. The fault here is not just a vulnerable contract. It is a response gap. Weeks later, the attacker still controls the flow. No pause announcement. No fix disclosure. No recovery plan. The chain remembers what the ego forgets.
Aztec Network operates at a specific layer: L2 privacy infrastructure. Its Private Rollup Bridge is the entry point for assets moving between Ethereum L1 and Aztec's encrypted environment. This is the funnel. Every deposit crosses this contract. Every withdrawal depends on its integrity. When the bridge breaks, privacy becomes a liability. This is the gateway through which user capital enters the privacy layer. It is also the exit through which it was stolen.
Tornado Cash is the other half of this story. The mixer has been under OFAC sanctions since August 2022. Any address interacting with it inherits regulatory exposure. The attacker knows this. That is the point. By routing stolen ETH through Tornado, they convert traceable movements into statistical noise.
The timeline is fragmentary. Reports identify repeated transfers: one batch, then another 300 ETH. At a reference price near $1,906 per ETH, that tranche is worth roughly $572,000. The cumulative 500 ETH approaches $953,000. This is not rounding error money. This is deliberate, staged liquidation.
A timing question remains. Reports cite a June date and an August 8 event without a year. If we are in August 2026, the exploit is recent. If the June reference is a typo, the window shifts. The inconsistency matters; it separates an active bleed from a post-mortem.
Do the arithmetic. Total loss: $2.165 million. A 300 ETH tranche: $572,000. Implied price: $1,906. Stolen principal: roughly 1,136 ETH. The difference between those numbers is the story. The attacker has laundered 500 ETH. Approximately 636 ETH remains unmixed. This is the hidden number. Most coverage focuses on the latest transaction; the structural fact is that over half the stolen funds remain under attacker control, waiting for the next mix.
This matches my forensic experience. In audit work, attackers rarely dump in one transaction. They batch. They test. They calibrate to the mixer's anonymity set. The 300 ETH deposit is not an outlier; it is a scheduled payment to a laundering pipeline.
Tornado Cash mechanics matter. The contract takes deposits and issues a commitment. Withdrawals require a valid nullifier; the deposit-withdrawal link hides behind a zero-knowledge proof. For law enforcement, the trace ends at the mixer's root. For the attacker, the withdrawal is clean. This is not theory. This is how the protocol operates, and the attacker has spent 500 ETH through precisely this path. Each deposit grows the anonymity set. Each mix lowers the probability of recovery.
The deeper problem is what the public record does not contain. No contract address for the bridge. No vulnerability class. No audit firm. No statement on whether a multi-signature wallet controlled the bridge, and whether the compromise was code or keys. Private Rollup Bridge implies a rollup-based architecture. That means a sequencer, a prover, and a settlement contract. Each is a potential fault surface. Without disclosure, we cannot determine which one failed.

Verification precedes trust, every single time. That is why I structure every bridge review the same way: first the contract arithmetic, then the access control model, then the upgrade path. None of that information is public here. The absence of information is itself information. A project that does not disclose its failure mode cannot credibly claim to have fixed it.

Competent incident response follows a sequence: pause the contract, rotate admin keys, notify users, disclose the vulnerability class, publish a post-mortem with code references. None of those steps appear in the public record. That silence is unusual. In my due diligence for a zero-knowledge rollup, the first question I asked was not about tokenomics; it was about the incident response playbook. The answer determines whether capital survives an attack. This project has not answered that question publicly.
There is also an operational signal. The funds flow to Tornado Cash, not to a centralized exchange. This tells us the attacker values long-term concealment over liquidity. They are not in a rush. The rhythmic deposits suggest a scripted process, possibly tied to a mixer queue. Code is law, but history is the judge. The history here is a sequence of deposits that reads like a schedule.
The counter-intuitive conclusion: this event may hurt legitimate privacy projects more than it hurts the attacker. Tornado Cash is sanctioned. Every ETH that enters it deepens the regulatory association between privacy tooling and money laundering. The damage to Aztec-like projects will be a discount on trust, not a discount on liquidity.
Another blind spot: funds entering Tornado Cash may never reach the open market. If they dissolve into the mixer's anonymity set, they do not generate sell pressure on exchanges. The direct PnL damage disappears. The lasting damage is narrative. And the record is permanent. The chain remembers what the ego forgets.
Then there is the remaining 636 ETH. If the attacker completes the schedule, expect another Tornado deposit within days. If the deposits stop, ask why. Pauses in laundering often signal a negotiated settlement, a partial recovery, or a security team gaining ground. None of that has been disclosed.
There is a deeper irony. Aztec builds privacy infrastructure. The attacker uses privacy infrastructure. The tool is identical; the intent is different. That single fact will drive the next regulatory cycle. Privacy protocols will be asked to prove their infrastructure does not become a laundering corridor. The burden of proof has shifted.
The pattern is set. The bulk of the stolen principal is still unmixed, and the pipeline remains active. The next block will tell us whether the attacker completes the schedule. Time favors the mixer; every block dilutes the trail. Privacy protocols must now answer a harder question: can they prove their infrastructure does not become a laundering corridor? The chain records that proof for them. Verification precedes trust, every single time.