1,010 ETH stolen via fake Tornado Cash site: expired domain

A user lost 1,010 ETH in 12 hours after using an outdated Tornado Cash link. Attackers took over the expired domain, stealing withdrawal notes via a fake web interface.

A cryptocurrency user lost 1,010 ETH after falling victim to a phishing attack that exploited Tornado Cash’s expired official domain. The user accessed the outdated site through a bookmark or old link, unaware that attackers had taken control of the domain and created a fake interface. This fraudulent site harvested deposit “notes,” which are required to withdraw funds from Tornado Cash’s official smart contracts. Importantly, the smart contracts themselves remained uncompromised; the attack specifically targeted the web interface layer. The incident unfolded within just twelve hours and highlights the significant risks associated with expired domain management in decentralized finance. Reports indicate that nearly 4,000 ETH have been stolen through similar methods in the past year, emphasizing the need for user vigilance and robust web infrastructure security for decentralized protocols.

Related Tokens

Related News