ADVERTISEMENT

Events

IAMTN Annual Summit 2026
14 Oct 26
London
Money20/20 USA 2026
18 Oct 26
Las Vegas

Ethereum User Loses 1,010 ETH in Tornado Cash Phishing Attack

An Ethereum user reportedly lost 1,010 ETH after using an old Tornado Cash bookmark that allegedly redirected to a malicious frontend, according to community accounts tracking the incident. The reported loss is worth about $2.32 million at Ether’s price of roughly $2,295.

Onchain data partially confirms the incident but does not establish the full amount. A wallet identified in connection with the attack received 810 ETH across nine transactions on August 18, including eight transfers of 100 ETH and one of 10 ETH between 5:56 a.m. and 6:05 a.m. UTC.

Attack leaves 810 ETH in suspected wallet

The cited wallet had not made an outgoing transfer when reviewed and held about 810 ETH, valued at approximately $1.86 million, according to Etherscan data. That leaves a 200 ETH difference between the amount reported by community accounts and the funds independently linked to the wallet.

The alleged attack relied on obtaining Tornado Cash deposit credentials. Because valid deposit notes can authorize withdrawals from the corresponding privacy pool, a malicious interface can expose funds without requiring the victim to approve a conventional wallet-draining transaction.

Claims that the tornado.cash domain itself was taken over after expiring remain unconfirmed. The site displayed a Tornado Cash interface when checked, and no authoritative domain record, official warning or named security researcher had confirmed the alleged ownership transfer.

How can a fake crypto website steal funds without draining a wallet

Phishing attacks can target credentials rather than wallet approvals. That makes them particularly difficult to spot because the victim may believe they are interacting with a familiar service while voluntarily entering information that later enables a withdrawal.

Old bookmarks, search results and backlinks can continue directing users to familiar-looking domains even after ownership or website infrastructure changes. A legitimate-looking interface therefore does not guarantee that sensitive information is being handled safely.

Tornado Cash has also faced frontend security issues before. In 2024, researcher Gas404 identified malicious JavaScript in an open-source interface that could expose private deposit notes, while Checkmarx later documented the related supply-chain compromise. There is no evidence connecting that incident to the latest transactions.

What happens next

The immediate focus is tracing the confirmed 810 ETH and determining whether the remaining 200 ETH moved to separate addresses. Community claims that the same attackers stole nearly 4,000 ETH over the past year also require wallet addresses, transaction records or independent attribution before they can be treated as established.

Users who interacted with the suspected frontend should preserve transaction and browser records, avoid the site and review their wallets for suspicious activity. Exchanges receiving the stolen funds could also become important points for identification or potential freezes. Until that evidence emerges, the blockchain confirms a major transfer, but not the full scope or cause of the alleged theft. 

 

Enjoyed this? Bookmark DeFi Planet, explore related topics, and follow us on Twitter, LinkedIn, Facebook, Instagram, Threads, and CoinMarketCap Community for seamless access to high-quality industry insights

Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.

ADVERTISEMENT
ADVERTISEMENT

Spotlight

-
00:00
00:00
Update Required Flash plugin
-
00:00
00:00