Tornado Cash phishing attack drains 1,010 ETH via expired domain

A cryptocurrency user has lost more than 1,000 ETH after falling victim to a Tornado Cash phishing attack that exploited an expired official web address once tied to the sanctioned mixing protocol. According to reporting from Wu Blockchain, the victim clicked an old bookmarked link that redirected to a fraudulent site built on the abandoned domain, triggering a rapid and costly theft that highlights a growing risk across decentralized finance: what happens when a project’s own web infrastructure quietly slips out of its control.
Key takeaways
- A user lost over 1,000 ETH after being redirected through Tornado Cash’s expired official domain, tornado.cash.
- Hackers drained 1,010 ETH from the victim within just 12 hours of the phishing site going live.
- The domain lapsed because Tornado Cash failed to renew it while operating under OFAC sanctions.
- Attackers registered the abandoned domain and built a fake frontend designed to harvest deposit credentials.
- Nearly 4,000 ETH has reportedly been stolen through similar phishing schemes tied to this domain over the past 12 months.
Phishing Attack Exploits Tornado Cash Expired Domain
The core of the incident is straightforward but painful: a user reused an old, bookmarked link to what they believed was the legitimate Tornado Cash portal. That link, however, no longer pointed to the real protocol. Instead, it led to a look-alike site controlled by attackers who had quietly taken over the lapsed domain, according to community reports cited by Wu Blockchain.
… Continue reading the full article at the original source below.


