Newsroom
21 August, 2026 / News / AI / Tags: tornado, domain, cash, eth, frontend

Community reports describe a rapid drain of 1,010 ETH via an old link to tornado.cash; on-chain data confirms 810 ETH moved into a single address as questions rise over domain control and the victim’s background
An Ethereum user reportedly lost a substantial sum after following a bookmarked link once associated with Tornado Cash. According to community accounts, the link redirected through the domain tornado.cash to a site controlled by attackers. The user entered deposit credentials on the fake interface, allowing the operators to withdraw funds. The entire process reportedly took place within roughly 12 hours.
Community sources stated that 1,010 ETH was taken. Tracking indicated the stolen assets largely remained in addresses linked to the attackers. At prevailing prices near $2,295 per ETH, the reported total equated to approximately $2.32 million.
Blockchain data provides independent verification of a large portion of the claimed loss. A specific address received 810 ETH across nine transfers on August 18. Eight of those transfers carried 100 ETH each and the final one carried 10 ETH. The movements occurred between 5:56 a.m. and 6:05 a.m. UTC. At the time of review the address still held approximately 810 ETH, valued at about $1.86 million.
The 200 ETH difference between the community figure of 1,010 ETH and the confirmed 810 ETH has not been fully accounted for in public records. No outgoing transfers from the receiving address were observed during the initial review period.
Reports attributed the incident to the expiration of tornado.cash. The original domain is said to have lapsed after the Tornado Cash team did not renew it while the protocol remained under OFAC sanctions. Attackers allegedly registered the available address and installed a cloned frontend designed to capture deposit notes.
Deposit notes function as private credentials in Tornado Cash. Possession of a valid note generally allows withdrawal of the corresponding funds from the protocol’s pools. A fraudulent interface can capture these notes when a user attempts to interact with the site.
Independent checks found the domain accessible and displaying a Tornado Cash interface. No official domain records, project warnings, or named security firm statements confirmed a change of ownership or prior malicious control at the time of reporting. Previous frontend compromises affecting Tornado Cash interfaces have been documented in earlier years, though no direct link to the current transactions has been established.
The same group is alleged to have taken nearly 4,000 ETH through comparable methods over the preceding 12 months. That larger total has not been accompanied by lists of related addresses, transaction hashes, or formal attribution analysis from security researchers. Without such supporting data the figure cannot be independently confirmed.
On-chain analyst Specter examined the flow of assets connected to the reported victim. The analysis indicated that 73 BTC, valued at roughly $4.6 million, originated from the Whirlpool Bitcoin mixer approximately two weeks earlier. Those coins were then bridged to Ethereum and deposited into the suspected phishing frontend.
The reported victim stated the assets were moved after a hardware wallet compromise. Specter observed that routing funds through multiple mixers appears inconsistent with a simple escape from a compromised device. The same individual was also noted as active in Telegram groups focused on private-key cracking and brute-force tools. The analyst described the episode as a possible case of one threat actor targeting another.
No public statement from Tornado Cash, an established blockchain security firm, or the reported victim has independently confirmed every detail of the community narrative. The confirmed movement of 810 ETH into a newly active address stands as the clearest on-chain fact. Users who interacted with any similar interface have been advised in general guidance to cease use, secure remaining assets, and revoke unnecessary approvals while preserving relevant logs for any subsequent reports to service providers or authorities.









