Drift hack funds linked to Backpack accounts; KYC records could be crucial lead

ChainCatcher reports that onchain analyst aryan said on X the attacker's address received funds through NEAR Intents eight days ago and stayed dormant until a sizable transfer arrived from the Drift treasury. The attacker then routed the assets through multiple laundering addresses. Notably, every one of those addresses received funds yesterday via Backpack, despite Backpack presumably having completed KYC checks for the related accounts. The laundering addresses subsequently bridged the funds to an Ethereum address via Wormhole; that destination address had previously been funded through Tornado Cash.