It has been revealed that approximately $4.39 million (about 6.2 billion Korean won) was stolen from an early wallet of Solana (SOL) through the Ethereum‑based protocol Tornado Cash. Onchain Lens, an on‑chain analysis service, confirmed similar movements in two addresses (0xd229…9D15 and 0x501…f051) that were connected by the attacker. The incident was disclosed at 9 a.m. KST and appeared to have recurred about a month after the prior theft of $1.42 million.
Although the target of this theft was a Solana wallet, the actual fund transfers occurred on the Ethereum network. Tornado Cash links deposits and withdrawals to different addresses, making it difficult to trace the flow of funds. This feature allowed the attacker to repeatedly transfer money from the same wallet.
The old wallet named “OG,” which had no conventional transactions before, was the subject of this incident. The fact that its previous holdings were removed raised questions about wallet security. By using the features of an Ethereum‑based protocol, the attacker could move funds from a single address, and as a result on‑chain analysis firms quickly traced and disclosed the addresses involved.
Such cases illustrate how dangerous Tornado Cash can be in practice. It becomes increasingly necessary to strengthen measures for monitoring fund movements on blockchains and to enhance the vigilance of wallet holders.