Crypto Investor Loses 1,010 ETH on Obsolete Tornado Cash Website

cryptonews.ruPublished on 2026-08-20Last updated on 2026-08-20

Abstract

A cryptocurrency investor lost 1010 ETH after using an outdated browser bookmark to access the Tornado Cash mixer website. According to security analysts from Wu Blockchain, the domain had been seized by malicious actors who deployed a fake interface mimicking the original service. The victim, believing they were interacting with genuine Tornado Cash smart contracts, inadvertently granted the scammers access to their wallet. The funds were drained within 12 hours, transferred out in small batches of primarily 100 and 10 ETH. The team behind Tornado Cash lost control of the old domain after being unable to renew it following sanctions imposed by the US Office of Foreign Assets Control (OFAC) in 2022. Criminals subsequently registered the domain and set up the phishing copy. The mixer now operates via decentralized channels like IPFS and ENS. Wu Blockchain estimates the fake site's operators have stolen a total of roughly 4000 ETH from various users over the past year. Separately, blockchain security firm Bitdefender reported that scammers are distributing the Lumma Stealer malware disguised as pirated copies of Christopher Nolan's recent film "Oppenheimer."

Analysts from the security-focused company Wu Blockchain reported that the owner of the Ethereum followed an outdated browser bookmark to the crypto mixer's website. By that time, the domain had already been seized by attackers, who deployed a fake interface imitating the original page. The victim thought they were depositing funds into the genuine Tornado Cash smart contracts but instead provided the scammers with access to their assets. The money was withdrawn within 12 hours of the investor's first interaction with the fake site.

The Etherscan service shows that the stolen ETH is now located across a large number of addresses controlled by the criminals. The cryptocurrency was withdrawn from the victim's wallet in small batches — mostly 100 $ETH and 10 $ETH.

The Tornado Cash team lost control of the old domain because they were unable to renew it following the decision by the US Treasury Department's Office of Foreign Assets Control (OFAC) in 2022. At that time, the attackers registered the domain and deployed a phishing copy of the interface. Currently, the crypto mixer continues to operate through decentralized channels — specifically, via IPFS gateways and ENS.

According to Wu Blockchain specialists, the owners of the fake site have stolen a total of around 4,000 ETH from various users over the past 12 months.

Earlier, blockchain security experts at Bitdefender reported that scammers have begun distributing a program for stealing digital assets, Lumma Stealer, disguised as pirated copies of the recently released film "Oppenheimer" by director Christopher Nolan. The viruses are masquerading as high-quality video files of the film, WEBRip and Blu-ray, with file names imitating torrent releases.

end-content

Trending Cryptos

Related Questions

QWhat was the method used by the criminals to steal the crypto investor's 1010 ETH?

AThe criminals tricked the victim by taking control of an old Tornado Cash domain and deploying a fake website interface. The investor, using an outdated browser bookmark, interacted with this fake site, unknowingly granting the attackers access to their wallet.

QWhat prevented the Tornado Cash team from maintaining control over their old domain name?

AThe Tornado Cash team could not renew the old domain after the U.S. Office of Foreign Assets Control (OFAC) imposed sanctions on the service in 2022. This allowed criminals to register the domain.

QAccording to the report, how much total Ethereum have the fake site operators stolen in the past year?

AAccording to Wu Blockchain specialists, the operators of the fake website have stolen a total of approximately 4000 ETH from various users over the past 12 months.

QHow is Tornado Cash currently accessible to users following the loss of its old domain?

ATornado Cash continues to operate through decentralized channels, specifically via IPFS gateways and the Ethereum Name Service (ENS).

QWhat other recent malware threat is mentioned in the article besides the Tornado Cash phishing site?

AThe article mentions that cybersecurity experts from Bitdefender reported a malware called Lumma Stealer being distributed disguised as pirated copies of Christopher Nolan's recent film 'Oppenheimer'. The viruses are masked as high-quality video files.

Related Reads

Trading

Spot

Hot Articles

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of ETH (ETH) are presented below.

活动图片