Incident case file
Sign in to watchTornado Cash Fake Frontend Phishing — 810 ETH Drained via Deposit-Note Theft
2 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatAug 12, 17:08:59 UTC: Attacker wallet 0xd8B356... is gas-seeded with 0.0979 ETH withdrawn from Tornado Cash's 0.1 ETH pool via relayer 0x2bCE4567..., paying a 0.00212 ETH fee — the only relayer-routed transaction the wallet ever makes. Aug 18, 05:56:47-06:05:35 UTC (8 minutes 48 seconds): Nine self-sent withdrawals land at the attacker wallet directly from Tornado Cash pools — eight of exactly 100.000000 ETH and one of 10.000000 ETH — totaling 810.0972347991 ETH. Community reports (originating from the purported victim) claim a total loss of 1,010 ETH over a 12-hour window, attributing the theft to an old bookmark redirecting to a hijacked, expired official domain (tornado.cash), allegedly re-registered by an attacker after the project failed to renew it amid OFAC-related disruption. Domain forensics cited in support: registration 25 Mar 2025 (four days after OFAC delisting), registrar transfer 9 Jan 2026, SSL certificates for the apex and all subdomains reissued 9 Aug 2026 (a full clone of the original layout), and a live clone confirmed via urlscan at 02:11 UTC on Aug 18 — three hours forty-five minutes before the first withdrawal. Separately, the victim's own account (posted under the handle 'Thundra' in the TornadoCash Official DAO Telegram) describes a different entry vector: 'I was extra careful to check Github org, repos, stars and then clicked the link... My entry point was Github official org' — implicating a compromised or spoofed GitHub repository rather than the domain. Aug 20: Wu Blockchain publishes the community account (1,010 ETH, 12-hour window, domain-takeover narrative). Aug 20-21: Independent verification by on-chain analyst BlockWatchdog and by KuCoin News/ChainGPT confirms only 810 ETH moved on-chain in 8 minutes 48 seconds (not 12 hours), states plainly that 'no domain takeover has been officially confirmed,' and that the extra 200 ETH 'has not been linked to any destination in the supplied evidence and remains unverified.' Specter's threat-actor allegation against the victim is publicly challenged by other on-chain analysts disputing the Whirlpool attribution. As of Aug 21, the 810 ETH remains fully intact and unmoved at the attacker's address; no domain, GitHub, or exchange-side confirmation of the precise entry vector has been published by any authoritative party.
Sources and coverage
- Articlex.comhttps://x.com/WuBlockchain/status/2090356831289528430
- Articlex.comhttps://x.com/BlockWatchdog
- Articleetherscan.iohttps://etherscan.io/address/0xd8B356356d7B143D7ece9F5876FE4b954E93b745
- Articlekucoin.comhttps://www.kucoin.com/news
- Articlex.comhttps://x.com/SpecterAnalyst/status/2090440369175449965
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)