User loses 1,010 ETH in confirmed Tornado Cash phishing attack on expired domain

A cryptocurrency user lost 1,010 ETH after clicking an outdated bookmark to the expired tornado.cash domain, which attackers had registered and used to deploy a fake frontend that stole deposit notes. The funds were drained within 12 hours. Onchain analysis from Etherscan shows the stolen ETH held mainly in addresses controlled by the perpetrators, including one address with approximately 810 ETH sourced from Tornado Cash's 100 ETH and 10 ETH pools. The remaining 200 ETH appears in other wallets associated with the same group. The incident underscores ongoing risks from outdated bookmarks and domain lapses following the 2022 OFAC sanctions on the privacy protocol. Legitimate Tornado Cash access remains available via IPFS and ENS gateways. Community reports indicate the operators have used similar tactics to steal nearly 4,000 ETH over the past 12 months. As of August 20, 2026, the assets remain under attacker control.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.