Crypto

Ethereum user loses 1,010 ETH in Tornado Cash phishing attack



An Ethereum user reportedly lost 1,010 ETH after following an old Tornado Cash bookmark that allegedly redirected to a malicious frontend controlled by phishing attackers.

Summary

  • An Ethereum address received 810 ETH through nine transfers on August 18, onchain records confirm.
  • Community reports claimed 1,010 ETH was stolen after a user visited a suspected phishing frontend.
  • The cited wallet retained approximately 810 ETH, worth about $1.86 million when records were checked.
  • Claims that attackers stole nearly 4,000 ETH over twelve months remain independently unverified by researchers.
  • Tornado Cash’s website was accessible when checked, leaving the alleged domain takeover without official confirmation.

Community accounts said the incident unfolded over approximately 12 hours. They alleged that attackers obtained the victim’s Tornado Cash deposit credentials and withdrew the funds before transferring them to several addresses.

Onchain records provide partial confirmation. The cited wallet received 810 ETH through nine transactions on Aug. 18. Eight transfers carried 100 ETH each, while the final transfer carried 10 ETH.

The transactions occurred between 5:56 a.m. and 6:05 a.m. UTC. The address retained approximately 810 ETH, valued by Etherscan at about $1.86 million when checked on Aug. 20.

Ethereum records confirm 810 ETH, not the full claim

The verified transactions leave a 200 ETH gap between the 1,010 ETH loss reported by community users and the 810 ETH held by the cited wallet. The remaining amount may have reached another address, but no additional destination was included in the supplied evidence.

No public statement from Tornado Cash, an established blockchain security firm or the reported victim had independently confirmed the full amount when this article was prepared.

Community accounts claimed the victim tracked a total loss of 1,010 Ethereum, but the provided address independently confirms only 810 Ethereum.

The cited wallet had recorded nine transactions and no outgoing transfer at the time of review. Its balance therefore supports the claim that most of the reported funds remained under the suspected attacker’s control.

At Ether’s price of approximately $2,295, the confirmed 810 Ethereum was worth about $1.86 million. The reported 1,010 Ethereum loss would be worth roughly $2.32 million at the same price.

Tornado Cash domain takeover remains unconfirmed

Reports blamed the theft on the tornado.cash domain, claiming it expired after the project’s team failed to renew it during the disruption caused by U.S. sanctions. According to the accounts, an attacker subsequently registered the address and installed a fake user interface.

That account could not be fully verified. The domain was accessible and displayed a Tornado Cash interface when checked. No authoritative domain record, official Tornado Cash warning or named security researcher was found confirming that the address had expired and changed ownership.

Claims that the official domain was captured by an attacker therefore remain unconfirmed and should not be presented as an established cause.

A website loading correctly at the time of checking does not prove it was safe at an earlier time. Attackers can remove malicious code, redirect only selected visitors or restore a legitimate interface after collecting credentials.

Tornado Cash has faced previous frontend security problems. In 2024, researcher Gas404 found that malicious JavaScript had been inserted into an open source interface and could expose private deposit notes. Checkmarx later documented the supply chain compromise, although no evidence currently connects that episode with the latest transactions.

Deposit notes can give attackers control of funds

Tornado Cash uses private deposit notes to let users withdraw assets from its pools. Anyone who obtains a valid note can generally initiate the corresponding withdrawal, making the note comparable to a private credential.

A fake frontend can capture this information when a user attempts to make a deposit or withdrawal. The attacker can then use the stolen note before the legitimate owner does.

The attack differs from approval phishing, where a victim signs a malicious transaction that authorizes a drainer contract. In related coverage, crypto.news explained how wallet drainers exploit deceptive signatures to gain access to tokens and nonfungible assets.

Old bookmarks present another risk because users often assume previously trusted links remain safe. Expired or transferred domains preserve their familiar names, search rankings and backlinks, making malicious replacements harder to identify.

As crypto.news recently reported, fake websites continue draining Ethereum wallets after users approve transactions or enter sensitive information. The safest approach is to verify domains through several current project channels before connecting a wallet.

Nearly 4,000 ETH claim needs more evidence

Community reports also alleged that the same attackers stole almost 4,000 ETH through similar methods over the previous 12 months. No list of related addresses or attribution analysis accompanied that figure.

Without linked wallets, transaction hashes or a report from a security firm, the 4,000 ETH estimate cannot be independently verified. Blockchain transfers show where funds moved, but they do not automatically establish who controlled each address or which phishing campaign generated them.

The immediate priority is monitoring the confirmed 810 ETH. Transfers to exchanges could create an opportunity for platforms to identify or freeze assets, subject to their procedures and applicable law.

The victim should preserve browser history, bookmarked URLs, wallet logs and transaction records before reporting the incident to wallet providers, exchanges and law enforcement. Users who interacted with the same frontend should stop using it, move unaffected assets and revoke suspicious token approvals.

The available evidence supports a large Ethereum transfer into a newly active wallet. It does not yet prove the full 1,010 ETH loss, the alleged takeover of the official domain or the claimed 4,000 ETH campaign.





Source link

LEAVE A RESPONSE

Your email address will not be published. Required fields are marked *