On August 20, 2025, a wallet dormant for 9 months executed a 38.5M USD ETH buy at $2,109 per ETH. The capital source? Tornado Cash. The previous sell? $3,308 per ETH — a 36% price difference captured in a single round-trip. Chain analyst Yu Jin traced the flow back to a September 2024 sale where the same address offloaded 18,250 ETH into DAI/USDS. Today, it reversed the trade.
This is not a whale. This is a hacker. And the transaction is a case study in market timing, liquidity mechanics, and the evolving cat-and-mouse game between on-chain surveillance and financial privacy.
Context: The Anatomy of a Timed Exit
The address in question first appeared in September 2024, receiving ETH from Tornado Cash — a mixer sanctioned by the U.S. Treasury in August 2022. At that time, ETH traded near $3,308. The hacker converted the entire stack into stablecoins, locking in a fiat-denominated profit. Then silence. For nine months, the wallet sat perfectly still, earning no yield, no compounding. Just a static stablecoin position.
On August 20, 2025, with ETH trading at $2,109, the address re-entered the market, buying back the same quantity of ETH plus a 10% premium (approx. 20,000 ETH). The total value: 38.5 million USD. The transaction was executed in a single block, likely using a decentralized aggregator to minimize slippage.

Core: Order Flow Analysis — The Hacker’s Edge
Let’s break down the numbers. The initial sale at $3,308 represents a near-perfect top. ETH had peaked in March 2024 near $4,000 and was in a corrective downtrend by September. The hacker sold into a declining market, exiting before the November 2024 collapse to $2,000. The current buy at $2,109 is equally precise — within 5% of the local bottom seen in July 2025. This is not random. This is data-driven execution.

Code doesn’t lie. The on-chain footprint is clear. The hacker used a scripted approach: a single large limit order through a DEX aggregator, likely with a TWAP (time-weighted average price) algorithm to avoid impact. The transaction cost ~0.15 ETH in gas, implying a manual override of the default gas price to ensure priority inclusion. The buy was timed during a 3% intraday rally, suggesting the hacker anticipated momentum continuation.
From my own experience — during the 2020 Curve liquidity mining experiments, I wrote Python scripts to simulate rebalancing under different volatility regimes. The hacker’s timing is eerily similar to a machine-learning optimized exit: sell into fear, buy into strength. But the source of funds complicates the narrative.
Contrarian: Smart Money or Dirty Money?
The market’s knee-jerk reaction: "A whale just bought 38.5M ETH. Bullish." Some KOLs will frame this as a bottom signal. I see the opposite. The capital came from Tornado Cash. That means the funds are almost certainly illicit — hacks, ransomware, or sanctions evasion. This is not a confident institutional re-entry. This is a liquidity event forced by operational necessity.
Consider: why would a rational trader with a 36% profit lock in stablecoins for nine months, earning zero yield? The answer: they couldn’t move the funds. The wallet was likely under surveillance, and the hacker waited until the market structure allowed a clean re-entry without triggering red flags. The buy is not a bet on ETH’s future. It’s a step in a money-laundering sequence — converting stablecoins back to a more liquid, harder-to-seize asset.
Trust the audit, verify the stack, ignore the hype. The audited part is the chain: every transaction is public. The stack is the privacy layer — Tornado Cash — which failed to protect the hacker’s identity for nine months. The hype is the bullish narrative. Strip it away.
Takeaway: Actionable Signals for the Sideways Market
The hacker’s address is now long 20,000 ETH. If they sell again, it will be through the same channels: DEX aggregators, possibly cross-chain bridges to avoid detection. The next sell order will likely come during a liquidity flush — a 5-10% intraday drop — to maximize impact on TVL-sensitive protocols.
For traders: this event confirms that large block orders are being executed by sophisticated actors with access to private data (e.g., exchange order books, validator mempools). The era of retail sentiment reading is over. The market rewards those who read the source code — and the chain data.
Yield is the interest paid for patience and risk. The hacker earned zero yield in nine months, yet the round-trip generated a 36% return in fiat terms. That’s an annualized rate of ~48% — far exceeding any DeFi strategy. The cost? The risk of asset seizure, prosecution, and the impossibility of ever using a bank account again.
My recommendation: monitor the address (0x...). Use free tools like Etherscan’s token tracker or Dune dashboards. If the ETH moves to a centralized exchange, expect a short-term sell-off. If it stays on-chain, the hacker is likely waiting for a higher price. Either way, this is a signal, not a trade.
Final thought: The chain is transparent. The actors are not. The most profitable strategy in this market is not to follow the smart money — it’s to understand the constraints that shape their behavior. Code doesn’t lie. But the narrative around it often does.