The silence broke today. After five months of dormancy, the Step Finance hacker moved. $21.4 million in stolen SOL began its journey into the Tornado Cash abyss. Liquidity gone. Trace lost.
Data checked. Community warned.
This isn't a new exploit. It's the next phase of one. In November 2024, Step Finance – a Solana-based analytics platform – was drained of $21.4 million. The attacker vanished. Now, the funds are being laundered in a textbook pattern: sell, bridge, swap, mix. And the market barely flinched.
But I've spent years on the other side of these transactions. I've audited cross-chain bridges, traced wallet clusters through wash-trading bots, and mediated community panic after crashes. This one follows a playbook I've seen a dozen times.
Context: Why Now?
Step Finance isn't a protocol that holds user deposits. It's a data aggregator – a dashboard. The hack exploited a weakness in its smart contract logic, not its core product. But that detail got buried in the original news cycle. The attacker walked away with SOL tokens that were either platform revenue or user-facing balances.
Five months of silence is tactical. Hackers often wait for the heat to cool, for law enforcement to shift focus, for the market to forget. Today, the funds moved. The first sale happened on a Solana DEX – bypassing any centralized exchange KYC. Then the SOL was bridged to Ethereum, likely via Wormhole. Once on Ethereum, the attacker swapped to ETH and deposited into Tornado Cash.
This is the standard laundering pipeline. And it works.
Core: The Technical Flow
Let me break down each step with the precision my MS in Blockchain Engineering demands:
1. DEX Sell (Solana side): The hacker sold a portion of the stolen SOL through a Solana DEX. No order book, no identity check. The liquidity came from automated market makers – the same pools retail traders use daily. - My experience: I've analyzed similar wash-trading patterns. The key here is that the sell order was split across multiple pairs to minimize slippage.
2. Cross-Chain Bridge: The resulting USDC or wSOL was then bridged to Ethereum. The choice of bridge is critical. Wormhole is the most liquid Solana-ETH bridge, but it's not privacy-preserving. The hacker likely used a secondary hop – maybe a DEX swap on Solana to a less-tracked token – before bridging. - Context: Cross-chain bridges are the weakest link in laundering, but also the most visible. The hacker accepted that risk for liquidity.
- ETH Swap: On Ethereum, the bridged asset was converted to ETH via Uniswap or similar. This step is routine.
- Tornado Cash Deposit: The ETH was then sent to Tornado Cash. This breaks the on-chain trail. The funds enter a pool of indistinguishable deposits, and can be withdrawn to a fresh wallet.
Contrarian: The Real Story Isn't the Hack
Everyone will talk about the hack itself. But the contrarian angle is this: The market already priced this in.
When the attack happened five months ago, traders anticipated eventual selling. SOL price dropped 5% in the wake of the news, then recovered. Today, with the actual laundering, SOL barely moved. Why? Because the hacker's strategy is predictable. They're not dumping all at once – they're trickling through DEX pools. The market absorbed it.
What the market isn't seeing is the deeper implication: The ease of this laundering proves that KYC is theater.
I've argued this before: compliance costs are passed to honest users. The hacker used zero identity verification. They used public, permissionless infrastructure. No exchange asked for a selfie. No bridge required a passport.
And here's the kicker: Tornado Cash has been under OFAC sanctions for years. Yet it remains the go-to mixing tool. The sanctions didn't stop this laundering – they just made it slightly more inconvenient.
Trust bridge crossed. Crash imminent. (For the narrative, not the market.)
The crash isn't in SOL price. It's in the illusion that regulation can stop bad actors in permissionless systems. Every time a hacker successfully launders through Tornado Cash, the argument for on-chain compliance weakens.
Takeaway: What to Watch
The funds are now in Tornado Cash. But the story isn't over. Here's what I'm watching:
- Withdrawal pattern: Once funds exit Tornado Cash, they'll likely be sent to new wallets. If those wallets interact with centralized exchanges, the hacker risks exposure. More likely, they'll use a bridge back to a lower-profile chain or convert to privacy coins.
- Lookonchain data: These on-chain detectives will flag any movement. But by the time you see it, the money is already gone.
- Regulatory response: Don't expect action. The SEC and OFAC have bigger targets. But this incident could accelerate calls for on-chain analytics mandates.
My final thought: The community is warned. The data is checked. But the money is gone.
This isn't a failure of Solana or Step Finance. It's a structural feature of DeFi: permissionless access means permissionless exit. The same rails that let you trade without a bank allow hackers to launder without a warrant.
We can't fix it by adding more KYC. We can't fix it by shaming users. The only fix is understanding that liquidity is a double-edged sword – and in the hands of a hacker, it cuts both ways.
I'll leave you with this: Next time you see a five-month silence in a hack case, don't assume the money is lost forever. Assume it's being laundered. And ask yourself – what's your plan when the funds hit the open market?