Newsroom

Ethereum User Loses Over 1,000 ETH After Tornado Cash Bookmark Leads to Phishing Site

21 August, 2026   /   News   /  AI   /   Tags:  tornado, domain, cash, eth, frontend

Ethereum User Loses Over 1,000 ETH After Tornado Cash Bookmark Leads to Phishing Site

Community reports describe a rapid drain of 1,010 ETH via an old link to tornado.cash; on-chain data confirms 810 ETH moved into a single address as questions rise over domain control and the victim’s background

How the Alleged Theft Unfolded

An Ethereum user reportedly lost a substantial sum after following a bookmarked link once associated with Tornado Cash. According to community accounts, the link redirected through the domain tornado.cash to a site controlled by attackers. The user entered deposit credentials on the fake interface, allowing the operators to withdraw funds. The entire process reportedly took place within roughly 12 hours.

Community sources stated that 1,010 ETH was taken. Tracking indicated the stolen assets largely remained in addresses linked to the attackers. At prevailing prices near $2,295 per ETH, the reported total equated to approximately $2.32 million.

On-Chain Records Show Partial Confirmation

Blockchain data provides independent verification of a large portion of the claimed loss. A specific address received 810 ETH across nine transfers on August 18. Eight of those transfers carried 100 ETH each and the final one carried 10 ETH. The movements occurred between 5:56 a.m. and 6:05 a.m. UTC. At the time of review the address still held approximately 810 ETH, valued at about $1.86 million.

The 200 ETH difference between the community figure of 1,010 ETH and the confirmed 810 ETH has not been fully accounted for in public records. No outgoing transfers from the receiving address were observed during the initial review period.

Community accounts reported a total loss of 1,010 ETH drained within 12 hours. On-chain data independently confirms receipt of 810 ETH by one address on August 18.

Claims Surrounding the Domain

Reports attributed the incident to the expiration of tornado.cash. The original domain is said to have lapsed after the Tornado Cash team did not renew it while the protocol remained under OFAC sanctions. Attackers allegedly registered the available address and installed a cloned frontend designed to capture deposit notes.

Deposit notes function as private credentials in Tornado Cash. Possession of a valid note generally allows withdrawal of the corresponding funds from the protocol’s pools. A fraudulent interface can capture these notes when a user attempts to interact with the site.

Independent checks found the domain accessible and displaying a Tornado Cash interface. No official domain records, project warnings, or named security firm statements confirmed a change of ownership or prior malicious control at the time of reporting. Previous frontend compromises affecting Tornado Cash interfaces have been documented in earlier years, though no direct link to the current transactions has been established.

Broader Pattern Allegations Remain Unverified

The same group is alleged to have taken nearly 4,000 ETH through comparable methods over the preceding 12 months. That larger total has not been accompanied by lists of related addresses, transaction hashes, or formal attribution analysis from security researchers. Without such supporting data the figure cannot be independently confirmed.

Analyst Notes on the Victim’s Funds

On-chain analyst Specter examined the flow of assets connected to the reported victim. The analysis indicated that 73 BTC, valued at roughly $4.6 million, originated from the Whirlpool Bitcoin mixer approximately two weeks earlier. Those coins were then bridged to Ethereum and deposited into the suspected phishing frontend.

The reported victim stated the assets were moved after a hardware wallet compromise. Specter observed that routing funds through multiple mixers appears inconsistent with a simple escape from a compromised device. The same individual was also noted as active in Telegram groups focused on private-key cracking and brute-force tools. The analyst described the episode as a possible case of one threat actor targeting another.

No public statement from Tornado Cash, an established blockchain security firm, or the reported victim has independently confirmed every detail of the community narrative. The confirmed movement of 810 ETH into a newly active address stands as the clearest on-chain fact. Users who interacted with any similar interface have been advised in general guidance to cease use, secure remaining assets, and revoke unnecessary approvals while preserving relevant logs for any subsequent reports to service providers or authorities.

Associated cryptocurrencies
Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.