Tornado Cash Phishing Drains 1,010 ETH — 810 Confirmed

An Ethereum user reportedly lost funds after visiting an alleged Tornado Cash phishing frontend. On-chain records confirm 810 ETH received; the claimed 1,010 ETH loss and a domain takeover remain unverified.

.
Tornado Cash Phishing Drains 1,010 ETH — 810 Confirmed

6 Minutes

Follow on Google

Ethereum user targeted by Tornado Cash phishing loses large ETH sum

An Ethereum wallet appears to have been drained after its owner followed an old Tornado Cash bookmark that led to a malicious frontend. On-chain activity confirms a major transfer of funds into a newly active address, but independent verification of the full loss and the claimed domain takeover remains incomplete.

Key takeaways

  • On-chain records show a wallet received 810 ETH in nine transfers on Aug. 18.
  • Community reports say a user lost 1,010 ETH after visiting a suspected phishing frontend.
  • The cited wallet retained about 810 ETH — roughly $1.86 million at the time of verification.
  • Allegations that attackers stole nearly 4,000 ETH across 12 months are unverified.
  • No official confirmation exists that the Tornado Cash domain was definitively taken over by attackers.

On-chain evidence: 810 ETH received, timing and structure

Blockchain records indicate the suspect wallet received nine incoming transactions on Aug. 18, totaling 810 ETH. Eight of those transfers were 100 ETH apiece and the final one was 10 ETH, with timestamps between 05:56 and 06:05 UTC. At the time investigators checked the balance on Etherscan, the address held approximately 810 ETH, estimated at about $1.86 million based on an ETH price near $2,295.

This verified activity leaves a 200 ETH shortfall relative to the 1,010 ETH loss reported by some community sources. That difference could reflect additional transfers to other addresses, but the supplied evidence did not include destination addresses or transaction hashes to account for the gap.

Community narrative vs. verified data

Multiple community accounts described a scenario in which a user clicked an old Tornado Cash bookmark and was redirected to an attacker-controlled frontend. Those posts asserted the site’s domain had expired and been re-registered, enabling the phishing page to capture private deposit notes. One widely shared tweet read:

User Loses Over 1,000 ETH in Phishing Attack After Using Tornado Cash’s Expired Official Domain

According to community users, a user clicked an old link left in a related bookmark and was redirected to a phishing site through the expired official domain tornado. cash, which had… pic.twitter.com/8j7eQl3qX2

— Wu Blockchain (@WuBlockchain) August 20, 2026

While the tweet and community posts circulated quickly, neither an authoritative domain record nor an official Tornado Cash statement confirming a domain takeover were available during reporting. When researchers checked the tornado.cash site later, it loaded a Tornado Cash interface — a state that neither proves nor disproves that a phishing frontend had been active earlier.

How Tornado Cash deposit notes enable theft

Tornado Cash uses private deposit notes as credentials that allow users to withdraw funds from anonymized pools. A valid deposit note functions like a secret key: anyone who possesses it can initiate a withdrawal corresponding to the original deposit. A fake frontend or malicious JavaScript injected into an interface can capture these notes when a user attempts to make a deposit or withdrawal.

This attack vector is distinct from approval phishing, where a wallet signature authorizes a drain contract to spend tokens. In the deposit-note scenario, the attacker does not need an on-chain approval flow — they simply submit the withdrawal using the stolen note before the legitimate owner can act.

Historical context and supply-chain concerns

Tornado Cash has experienced frontend security incidents before. In 2024, researcher Gas404 discovered malicious JavaScript in an open-source frontend that could expose private deposit notes. Checkmarx later documented a supply-chain compromise tied to that exposure. There is currently no public forensic link tying that earlier compromise to the recent transfers observed on Aug. 18.

It’s also important to understand how expired domains and stale bookmarks can be weaponized. Domains that lapse but retain backlinks and search visibility remain trusted by many users. Attackers who acquire such domains can present familiar UIs and harvest credentials or private keys from unsuspecting visitors.

Claims of a larger campaign remain unproven

Community posts additionally claimed the same threat actors had siphoned almost 4,000 ETH over the prior 12 months using similar phishing frontends. Those assertions were not accompanied by lists of related addresses, transaction hashes, or an attribution report from a recognized security firm. Without linked wallet addresses or forensic analysis, the 4,000 ETH figure cannot be independently verified.

Blockchain data clearly shows where funds moved, but identifying which party controlled an address or linking transfers to a specific phishing campaign requires more evidence — analytic clustering, exchange tagging, or a security firm’s report.

What to watch next

The immediate focus for investigators and the broader community should be monitoring the confirmed 810 ETH and any subsequent movements. If the ETH is sent to known exchange addresses, compliance teams on those platforms may have an opportunity to flag, trace, or freeze the assets, subject to their policies and applicable law.

Security researchers, exchanges and Tornado Cash community maintainers should look for linked addresses, suspicious deposit patterns, and any on-chain traces that would help corroborate or refute the broader campaign claims.

Recommendations for users and victims

If you or someone in your community may have used the same frontend, take these immediate steps:

  • Preserve browser history, bookmarked URLs, wallet logs and transaction receipts to aid any investigation.
  • Report the incident to your wallet provider, any exchanges where you had accounts, and local law enforcement.
  • Move unaffected assets to a secure wallet that has not been exposed; consider using a new device or a freshly installed wallet app for recovery.
  • Revoke suspicious token approvals from centralized dashboards (e.g., Etherscan or wallet management tools) and reset browser extensions where appropriate.
  • Verify official project domains and frontend URLs across multiple verified channels before reconnecting a wallet.

Final assessment

The available on-chain evidence supports a sizable Ethereum transfer into a newly active wallet, consistent with a successful phishing extraction of deposit credentials. However, the data does not yet independently prove the full 1,010 ETH loss widely circulated in community posts, nor does it confirm the alleged capture of the official Tornado Cash domain or the existence of a 4,000 ETH campaign.

As with many incidents in crypto, rapid public claims can outpace verifiable data. Careful chain analysis, exchange cooperation and forensic reporting will be essential to determine the scope of the theft, identify potential cash-out routes, and bolster defenses against future frontend phishing attacks.

Sourcecrypto.news
Zoya Akhtar
"I’m Zoya, and crypto is my playground. I dive deep into blockchain trends, DeFi, and how digital assets shape our future economy."

Leave a Comment

Comments

No comments yet. Be the first.