Tornado Cash Phishing Attack via Expired Domain Drains 1,010 ETH
BitcoinWorld Tornado Cash Phishing Attack via Expired Domain Drains 1,010 ETH A cryptocurrency user lost 1,010 ETH (worth approximately $2.3 million at current prices) in a phishing attack that exploited the expired official domain of Tornado Cash, a privacy-focused crypto mixer.
The attack, reported by Wu Blockchain, highlights the ongoing security risks associated with domain mismanagement and the persistent threat of phishing in the crypto space.
How the Attack Unfolded The victim reportedly clicked on an old bookmarked link to tornado.cash, which had expired after the Tornado Cash team was unable to renew it due to sanctions imposed by the U.S. Treasury’s Office of Foreign Assets Control (OFAC).
The domain was then registered by an attacker, who set up a fake front-end interface that mimicked the original service. When the user interacted with this fraudulent site, they unknowingly authorized transactions that drained 1,010 ETH from their wallet within 12 hours.
This page shows the RSS-provided summary/preview. Full publisher content remains available at the original source.
Read Full Article at Source