Analysts from the security-focused company Wu Blockchain reported that the owner of the Ethereum followed an outdated browser bookmark to the crypto mixer's website. By that time, the domain had already been seized by attackers, who deployed a fake interface imitating the original page. The victim thought they were depositing funds into the genuine Tornado Cash smart contracts but instead provided the scammers with access to their assets. The money was withdrawn within 12 hours of the investor's first interaction with the fake site.
The Etherscan service shows that the stolen ETH is now located across a large number of addresses controlled by the criminals. The cryptocurrency was withdrawn from the victim's wallet in small batches — mostly 100 $ETH and 10 $ETH.
The Tornado Cash team lost control of the old domain because they were unable to renew it following the decision by the US Treasury Department's Office of Foreign Assets Control (OFAC) in 2022. At that time, the attackers registered the domain and deployed a phishing copy of the interface. Currently, the crypto mixer continues to operate through decentralized channels — specifically, via IPFS gateways and ENS.
According to Wu Blockchain specialists, the owners of the fake site have stolen a total of around 4,000 ETH from various users over the past 12 months.
Earlier, blockchain security experts at Bitdefender reported that scammers have begun distributing a program for stealing digital assets, Lumma Stealer, disguised as pirated copies of the recently released film "Oppenheimer" by director Christopher Nolan. The viruses are masquerading as high-quality video files of the film, WEBRip and Blu-ray, with file names imitating torrent releases.
end-content







