An Ethereum user reportedly lost 1,010 ETH, worth approximately $2.3 million at current prices, after using an old Tornado Cash bookmark that allegedly redirected to a phishing frontend designed to steal credentials needed to withdraw funds. The incident was reported August 20 by Wu Blockchain, citing community accounts that said the victim accessed an old link associated with Tornado Cash. The reports claim the protocol’s former tornado.cash domain had expired and was subsequently obtained by an attacker, who deployed a counterfeit interface.
The victim allegedly supplied Tornado Cash deposit information to the fraudulent frontend, allowing the attacker to withdraw the corresponding assets. Community reports place the loss at 1,010 ETH over approximately 12 hours. On-chain evidence independently confirms most, but not all, of that amount. A wallet identified in connection with the incident received nine transfers totaling 810 ETH on August 18 — eight transactions of 100 ETH followed by one of 10 ETH — between approximately 5:56 a.m. and 6:05 a.m. UTC.
On-Chain Evidence Leaves 200 ETH Unaccounted For
The discrepancy means the widely reported 1,010 ETH loss should not yet be treated as fully independently verified. The identified address retained approximately 810 ETH when reviewed on August 20, worth about $1.86 million at an ETH price near $2,295. At the same price, the claimed 1,010 ETH theft would be worth roughly $2.32 million. The remaining 200 ETH may have been transferred to another attacker-controlled address, but publicly cited evidence has not yet established that destination. No statement from the reported victim or established blockchain-security firm has independently confirmed the complete 1,010 ETH figure.
Claims surrounding the domain itself also require caution. Community reports say tornado.cash expired after its operators were unable to renew it during disruption associated with U.S. sanctions, allowing attackers to register the domain and deploy a malicious frontend. However, an independent check by Crypto.news found the domain accessible with a Tornado Cash interface on August 20. It found no authoritative domain record, official Tornado Cash warning or named security researcher independently confirming that ownership had transferred to an attacker.
Phishing Attack Did Not Require Smart-Contract Exploit
If the reported attack mechanism is confirmed, the incident differs fundamentally from a smart-contract exploit. Tornado Cash allows users to deposit cryptocurrency and later withdraw it using private deposit information. Anyone obtaining the necessary deposit note can potentially initiate the withdrawal, making that information a high-value credential. A counterfeit frontend can therefore capture a user’s deposit credentials without compromising Ethereum, Tornado Cash’s smart contracts or the victim’s underlying wallet. The attacker can subsequently use the credentials to withdraw the deposited assets before the legitimate owner does. The incident also illustrates a less conventional cryptocurrency security risk: trusted links can become dangerous after infrastructure changes ownership. Bookmarks, old social-media posts and documentation can continue directing users toward domains long after their original operators stop controlling them.
Tornado Cash has previously faced frontend-related security problems, including malicious JavaScript discovered in an open-source interface in 2024 that could expose private deposit notes, although there is currently no evidence connecting that incident with the latest reported theft. Community accounts have additionally claimed that nearly 4,000 ETH has been stolen through related phishing activity over the past year. That figure has not been independently verified.
For now, the strongest verifiable evidence establishes that 810 ETH reached the identified address. The larger 1,010 ETH loss and the reported takeover of Tornado Cash’s former official domain remain credible community claims awaiting independent confirmation.
