On-chain records confirm 810 ETH reached a suspected attacker's wallet after a phishing site impersonated Tornado Cash.
On-chain records confirm 810 ETH reached a suspected attacker's wallet after a phishing site impersonated Tornado Cash.

On-chain records confirm 810 ETH reached a suspected attacker's wallet after a phishing site impersonated Tornado Cash.
An Ethereum user lost up to 1,010 ETH, worth about $2.32 million, after a phishing site impersonating Tornado Cash captured private deposit credentials, on-chain records show.
Community accounts first reported the incident on Aug. 20, citing tracking from Wu Blockchain. The cited wallet address on Etherscan received 810 ETH through nine transactions on Aug. 18, between 5:56 a.m. and 6:05 a.m. UTC.
Eight transfers carried 100 ETH each, with a final transfer of 10 ETH. The address retained approximately 810 ETH, valued at about $1.86 million at Ether's price of roughly $2,295. The remaining 200 ETH from the reported 1,010 ETH loss has not been traced to a specific destination.
The incident shows how expired or compromised domains can turn trusted bookmarks into attack vectors. Users who interacted with the fake frontend should move unaffected assets and revoke suspicious token approvals, while exchanges monitoring the confirmed wallet could freeze funds if transfers occur.
The verified transactions leave a 200 ETH gap between the 1,010 ETH loss reported by community users and the 810 ETH held by the cited wallet. No additional destination address was included in the supplied evidence, and no public statement from Tornado Cash, a blockchain security firm, or the reported victim had independently confirmed the full amount when this article was prepared.
The cited wallet had recorded nine transactions and no outgoing transfer at the time of review. Its balance therefore supports the claim that most of the reported funds remained under the suspected attacker's control.
Reports blamed the theft on the tornado.cash domain, claiming it expired after the project's team failed to renew it during the disruption caused by U.S. sanctions. According to the accounts, an attacker subsequently registered the address and installed a fake user interface. That account could not be fully verified — the domain was accessible and displayed a Tornado Cash interface when checked, and no authoritative domain record, official Tornado Cash warning, or named security researcher confirmed that the address had changed ownership.
A website loading correctly at the time of checking does not prove it was safe at an earlier time. Attackers can remove malicious code, redirect only selected visitors, or restore a legitimate interface after collecting credentials. Tornado Cash has faced previous frontend security problems: in 2024, researcher Gas404 found that malicious JavaScript had been inserted into an open source interface and could expose private deposit notes. Checkmarx later documented the supply chain compromise, although no evidence currently connects that episode with the latest transactions.
Tornado Cash uses private deposit notes to let users withdraw assets from its pools. Anyone who obtains a valid note can generally initiate the corresponding withdrawal, making the note comparable to a private credential. A fake frontend can capture this information when a user attempts to make a deposit or withdrawal, allowing the attacker to use the stolen note before the legitimate owner does. This differs from approval phishing, where a victim signs a malicious transaction that authorizes a drainer contract.
Community reports also alleged that the same attackers stole almost 4,000 ETH through similar methods over the previous 12 months, but no list of related addresses or attribution analysis accompanied that figure. Without linked wallets, transaction hashes, or a report from a security firm, the 4,000 ETH estimate cannot be independently verified.
The immediate priority is monitoring the confirmed 810 ETH. Transfers to exchanges could create an opportunity for platforms to identify or freeze assets, subject to their procedures and applicable law. The victim should preserve browser history, bookmarked URLs, wallet logs, and transaction records before reporting the incident to wallet providers, exchanges, and law enforcement.
The available evidence supports a large Ethereum transfer into a newly active wallet. It does not yet prove the full 1,010 ETH loss, the alleged takeover of the official domain, or the claimed 4,000 ETH campaign.
This article is for informational purposes only and does not constitute investment advice.