MIM hacker launders $7.5m worth of stolen funds through Tornado Cash

2025/06/19 18:38

On-chain data reveals that the attacker behind the Magic Internet Money or MIM hack in March 2025 recently sent through $7.5m worth of stolen funds into crypto mixer platform Tornado Cash.

According to on-chain data from blockchain security firm CertiK, the MIM attacker was caught sending 3,001 ETH (ETH) or approximately $7.57 million from a crypto wallet address beginning with 0x51baB into the decentralized crypto mixer Tornado Cash.

This transaction amounts to more than half of the stolen funds from the attack on Abracadabra Finance’s stablecoin, which was $13 million in losses.

“The MIM_Spell exploiter has just sent 3,001 ETH (~$7.57M) to Tornado Cash from 0x51baB,” wrote CertiK in its recent post.

The chain of wallet transfers represented by a chart created by CertiK showed that the funds were moved through four different Ethereum-based addresses. The first transfer moved 6,261 ETH, which is equal to amount of stolen from MIM, then the second and third wallets moved 3,001 ETH before sending it to a known Tornado Cash address.

How did the MIM hack happen?

On March 25 2025, MIM Spell was exploited for 6,261.13 ETH, which was equal to nearly $13 million. The MIM hack targeted its gmCauldron smart contracts, specifically the integration between decentralized exchange GMX and Abracadabra’s lending contracts.

According to the CertiK analysis paper, the exploit allowed the attacker to borrow funds without repaying them and liquidate the funds.

“This was due to the liquidation process not overwriting records in RouterOrder that counted as collateral, allowing exploiter to falsely borrow additional funds after liquidation,” wrote CertiK.

Shortly after the hack, MIM’s parent company Abracadabra Finance declared that it has bought back 50% of the losses it suffered in the $13 million exploit. The protocol also confirmed that user funds were unaffected by the attack.

The team said that it is currently working towards restoring the stolen crypto it had lost in the exploit. However, it is becoming increasingly difficult to track the funds once the hackers have put them through crypto mixers like Tornado Cash.

Clause de non-responsabilité : les articles republiés sur ce site proviennent de plateformes publiques et sont fournis à titre informatif uniquement. Ils ne reflètent pas nécessairement les opinions de MEXC. Tous les droits restent la propriété des auteurs d'origine. Si vous estimez qu'un contenu porte atteinte aux droits d'un tiers, veuillez contacter service@support.mexc.com pour demander sa suppression. MEXC ne garantit ni l'exactitude, ni l'exhaustivité, ni l'actualité des contenus, et décline toute responsabilité quant aux actions entreprises sur la base des informations fournies. Ces contenus ne constituent pas des conseils financiers, juridiques ou professionnels, et ne doivent pas être interprétés comme une recommandation ou une approbation de la part de MEXC.
Partager des idées

Vous aimerez peut-être aussi

The Future Of Crypto In Asia-Middle East

The Future Of Crypto In Asia-Middle East

The post The Future Of Crypto In Asia-Middle East appeared on BitcoinEthereumNews.com. Opinion by: Dipendra Jain, co-founder of TCX Regulation has become the baseline for crypto. From the United States’ regulatory enforcement to Dubai’s comprehensive crypto rulebook and India’s renewed debate on formalizing Bitcoin reserves, governments are rewriting the rules of digital finance. As listed institutions, retailers and social networks weigh in on digital asset rails, stablecoins and yield mechanisms, the real story is no longer what’s next, but who is building what comes next.  Speculation once drove adoption, but structured compliance catalyzes scale across the Asia-Middle East corridor. Hubs like the United Arab Emirates and India represent the treatment of regulation as the backbone of innovation. The UAE is pushing a unified virtual asset service providers (VASP) framework to accelerate global crypto ambitions. At the same time, India is opening the door for offshore crypto exchanges to return, with approvals now subject to the review of the Financial Intelligence Unit (FIU).  As regulatory frameworks formalize, platforms must align with new taxation, data governance and licensing rules to access expanding markets without friction. The global center of gravity is tilting eastward, and the question is: Who will master the age of “permissioned scale,” where sustainable growth comes from thriving within regulation, not skirting them? Jurisdictional intelligence and the demographic interplay Once sufficient for market entry, understanding jurisdictional rules is no longer enough. The Dubai Virtual Assets Regulatory Authority (VARA) has issued 36 full licenses and supports over 400 registered companies. VARA is also piloting tokenized gold and DeFi products, which promise growing enthusiasm to experiment with real-world assets beyond established solutions within a controlled environment.  But regulation alone renders platforms powerless if they fail to meet users where they are. With over 1.12 billion cellular mobile connections in India, 55.3% have internet access, and only 27% of adults meet basic financial literacy…
Partager
BitcoinEthereumNews2025/08/24 21:34
Partager