Tornado Cash Phishing Attack Exposes Users Through Expired Domain
A phishing attack on Tornado Cash has resulted in the loss of over 1,010 ETH after a user accessed a malicious frontend through an expired domain.
The attackers controlled the tornado.cash domain, which had been left unattended since US sanctions targeted the protocol in 2022.
The victim deposited funds into legitimate smart contracts but exposed private withdrawal information, allowing the attackers to drain the ETH within 12 hours.
On-chain data revealed that the stolen assets were linked to suspicious Bitcoin activity, raising questions about the source of the funds.