Tornado Cash Phishing Attack Drains $1.5M via Expired Domain
A Tornado Cash user has fallen victim to a phishing attack that exploited an expired official web address, losing over 1,000 ETH in the process.
The attackers registered the abandoned domain tornado.cash and built a fake frontend designed to harvest deposit credentials. The victim clicked on an old bookmarked link that redirected them to the fraudulent site, allowing the hackers to drain 1,010 ETH within just 12 hours.
The incident highlights a growing risk in decentralized finance: what happens when a project's own web infrastructure quietly slips out of its control?