Security & Hacks
1,000+ ETH Stolen Through Fake Tornado Cash Site After US Sanction
A forgotten domain turned into a powerful phishing trap, exposing a growing threat that can catch even experienced crypto users off guard.
22h ago 4,280
A forgotten domain turned into a powerful phishing trap, exposing a growing threat that can catch even experienced crypto users off guard.

Good things are always accompanied by an evil counterpart, and such was the case this week as Bitcoin rallied and brought profits, while a scammer caused a $1.88 million loss to another.
This, however, has cemented another major medium of scam that investors and amateur traders should be wary of.
On-chain data shows a user lost 1,010 ETH after phishing via Tornado Cash's expired domain, which was hijacked following the sanctions to steal deposit notes through a fake frontend. The stolen amount is worth roughly $2.29 million at current prices.
In this style of attack, victims deposit real ETH into Tornado Cash's genuine smart contracts, but the malicious site captures the cryptographic notes required for later withdrawal, letting attackers claim the funds instead.
One wallet linked to the scammers, tracked on Etherscan, shows a balance of approximately 810 ETH, worth around $1.88 million, with the funds arriving mainly through withdrawals from Tornado Cash's 100 ETH and 10 ETH pools in the days before the incident came to light. The remaining ETH is believed to sit in other wallets tied to the same group.

Tornado Cash has stayed silent, with its official X account inactive since 2022. The project was banned by the US Treasury's OFAC in August 2022 over alleged money laundering ties, including Lazarus Group activity.
While Tornado published a list of banned mirror sites at the time, its primary domain was overlooked. Even after the sanctions were lifted last year, maintenance of official infrastructure, including domain renewals, became complicated after sanctions were imposed.
As a result, the original web address eventually fell into a scammer's hands, who repurposed it as a lookalike frontend.
Website-based phishing has plagued crypto users repeatedly in recent weeks. In May, two scammers stole roughly $400,000 through a phishing advertisement impersonating Uniswap that ran on Google.
Attackers mimicked the exchange's interface to trick users into connecting wallets and approving malicious transactions. This was achieved by sponsored search placements pushing the fake link above Uniswap's real one.
Security group SEAL said it had already blocked over 356 similar malicious ad links tied to a broader, months-long campaign. Fake domains, deceptive ads, and cloned interfaces continue to be the weapon of choice, since they exploit user trust rather than any contract-level vulnerability.
The Tornado Cash case follows an identical playbook: an official-looking address, a convincing copy of the real product, and no way to reverse the loss once funds move.
Website scams aren't the only threat. Apple is currently defending a lawsuit after three plaintiffs said they collectively lost more than $1.8 million after downloading a fraudulent crypto wallet from the App Store, called Sparrow Wallet, despite the real Sparrow Wallet only existing as desktop software.
The complaint alleges Apple's App Store review process failed, and that the company took little to no action even after users flagged the fraud. Apple maintains that it swiftly removes impersonating apps once discovered and has blocked billions in fraudulent transactions industry-wide.
Together, these incidents highlight a widening gap between official platforms and the fake copies exploiting them, whether through an abandoned domain, a paid ad, or an app store listing that slipped past review.
Thus, users are advised to always rely on official channels to find the right link, app, or wallet to prevent malicious attacks on their funds. And as always DYOR!
No comments yet
Be the first to share your take when accounts launch.