UXLink exploit returns as attacker sends $8.1M ETH to Tornado Cash

UXLink, a Internet 3 social community that was focused in September 2025, is making headlines as soon as once more. In line with Specter, an on-chain investigator, the attacker chargeable for the UXLink exploit has began relocating the stolen property.
To obfuscate transaction trails, the wrongdoer transformed a few of the stolen DAI stablecoins into Ethereum [ETH]. Going ahead, the illicit actor then deposited roughly $8.1 million value of ETH into Twister Money.
Funds laundered
According to the investigator, 46 distinct deposits of 100 ETH every had been made as a part of the laundering course of.


For these unaware, it is a widespread technique to conflate unlawful funds with authorized transactions and make blockchain tracing harder.
With this most up-to-date motion, the attacker has now reportedly laundered a complete of $19.1 million in stolen property.
Nevertheless, the truth that the exploiter nonetheless has management over about $16 million in funds regardless of these transfers raises the potential of additional laundering.
How was UXLink attacked?
Effectively, back in September 2025 the exploiter had revamped $800 billion, or 9 trillion $UXLINK. Apparently, even hours after the unique exploit, the hacker saved their entry and saved minting extra tokens.
The exploiter then began shifting the proceeds to centralized exchanges and offloading the fraudulent tokens via decentralized exchanges. This in flip resulted within the depletion of Uniswap’s liquidity.


Notably, the attacker didn’t cease there, and signed a malicious transaction and misplaced 542 million UXLINK tokens to a different malicious actor—sometimes called “theft stolen from theft.”
Even with this setback, the principle exploiter nonetheless held about 900 million UXLINK tokens, placing a large portion of compromised property within the fingers of malicious actors.
What’s extra?
This coincded with ETH declining by 1.01% over the day before today to commerce at $1,745.11 at press time.
As well as, on the twelfth of June Humanity Protocol reported a focused phishing assault towards one among its administrators.
This had resulted within the attacker utilizing administrative credentials that had been stolen to improve contracts, switch tokens throughout Ethereum, and mint new $H tokens on the BNB Good Chain.
Moreover, on the fifteenth of June, a suspicious transaction involving the depletion of property valued at roughly $2.19 million occurred in Aztec Community’s Router contract.
Last Abstract
- From September 2025 to the current time, the attackers have reportedly laundered a complete of $19.1 million in stolen property from the UXLink exploit.
- Again then, the exploiter had revamped 9 trillion $UXLINK, saved their entry, and saved minting extra tokens.





