An Ethereum user reportedly lost 1,010 ETH after interacting with a malicious frontend that appeared after the official Tornado Cash domain expired and was allegedly registered by attackers. The incident was first highlighted by community accounts and Wu Blockchain on August 20, 2026.
Onchain records provide partial confirmation. A cited wallet received 810 ETH through nine transactions on Aug. 18 between 5:56 a.m. and 6:05 a.m. UTC. Eight transfers carried 100 ETH each, while the final transfer carried 10 ETH. At the time of review, the address retained approximately 810 ETH, valued at about $1.86 million based on an Ether price of roughly $2,295. The reported total loss of 1,010 ETH would be worth around $2.32 million at the same price. This leaves a 200 ETH gap between the confirmed balance and the community-reported loss, with no additional destination included in the supplied evidence.
According to community reports, the victim clicked an old bookmark for tornado.cash. The domain had allegedly expired because the Tornado Cash team was unable to renew it amid U.S. Treasury OFAC sanctions. An attacker is said to have registered the domain and installed a fake user interface that mimicked the original service. When the user interacted with the fraudulent site, sensitive deposit credentials may have been captured, allowing the attacker to withdraw funds within approximately 12 hours.
No public statement from Tornado Cash, an established blockchain security firm, or the reported victim had independently confirmed the full amount when the article was prepared. The domain was accessible and displayed a Tornado Cash interface when checked, but that does not prove it was safe earlier. Claims that attackers stole nearly 4,000 ETH over twelve months using similar domain-expiry tactics also remain unverified, as no linked addresses, transaction hashes, or security firm report accompanied that figure.
The attack highlights risks around expired or transferred domains, old bookmarks, and the sensitivity of Tornado Cash private deposit notes, which can allow anyone holding a valid note to withdraw funds. It differs from approval phishing, where a victim signs a transaction authorizing a drainer contract. Tornado Cash has faced previous frontend security problems; in 2024, researcher Gas404 found malicious JavaScript in an open source interface, and Checkmarx later documented a supply chain compromise, although no evidence connects that episode with this incident. The broader implication is a security gap created by regulatory pressure: OFAC sanctions restricted Tornado Cash operations and may have contributed to the domain lapse. Users are advised to verify domains through multiple current project channels before connecting wallets, preserve evidence after incidents, and revoke suspicious approvals.