A user lost over 1,000 $ETH due to a phishing attack through an outdated official Tornado Cash domain. This was reported by the resource Wu Blockchain on social media X on August 20, 2026.
The domain previously belonged to the protocol's team but ceased to be owned by them after the developers chose not to renew the registration amidst sanctions from the U.S. Office of Foreign Assets Control (OFAC). Malicious actors took advantage of this: they registered the now-available address and deployed a fake frontend on it, visually copying the original Tornado Cash interface. Through the fake site, the hackers gained access to the user's deposit notes — the data required to withdraw funds from the protocol's pools. As a result, 1,010 $ETH were withdrawn by the attackers within 12 hours.
According to the victim, the stolen coins mostly ended up in the attackers' wallets, and the group itself may have stolen about 4,000 $ETH in a similar manner over the past 12 months.
Where the Stolen Coins Went
One of the addresses associated with the withdrawal of funds is 0xd8B356356d7B143D7ece9F5876FE4b954E93b745. Etherscan shows that at the time of checking, the wallet's balance was about 810.1 $ETH. The funds arrived via nine withdrawal transactions from Tornado Cash pools on August 18, 2026 — eight operations for 100 $ETH and one for 10 $ETH.
Analyst Questions the Victim's Status
On-chain analyst Specter pointed out that the story of the theft does not look as straightforward as the victim himself presents it. According to his version, the person who called himself a victim may in fact be connected to illegal activity, and the stolen coins may have a questionable origin.
The victim explained his actions as follows: his Coldcard hardware wallet was compromised, so he hastily transferred assets from Bitcoin to Ethereum to save them. But blockchain data tells a different story. Two weeks before the attack, 73 BTC (about $4.6 million) were deposited into his addresses — and they came not from anywhere, but from the Whirlpool service, which is used to obfuscate the origin of coins and hide who is transferring them where. Part of these funds was then converted into Ethereum and transferred via the fake copy of the Tornado Cash site — meaning they ended up exactly where they were subsequently "stolen" from.
Specter notes: if the person was truly rescuing money from a hack, he would not have needed to run them through several different services to obfuscate the trail. Furthermore, according to his information, the same user was a member of Telegram groups where methods for hacking others' wallets and guessing passwords are exchanged. All this, in the analyst's opinion, looks more like a conflict between two groups of malicious actors than a story about an accidental phishing victim.
What is Known About the Domain
According to WHOIS data, the tornado.cash domain was registered on March 25, 2025, and updated on August 12, 2026; its validity expires on March 25, 2027. The registrar is TLD Registrar Solutions Ltd., and the current owner's data is hidden by the Whois Privacy Corp. service.
The incident shows how the expiration of a domain belonging to a once-major protocol can turn into a direct threat to users who continue to follow old bookmarks. Meanwhile, the origin of the stolen funds and the status of the victim himself remain the subject of a separate investigation based on on-chain data.
AI Opinion
From the perspective of machine data analysis, this case fits into the broader statistics of crypto market losses from social engineering. Analysis by Hash Telegraph indicates that in 2025, the market lost over $1.8 billion due to fraud and exploits, with the majority of losses occurring not from technical hacks, but from convincing the victim to follow a familiar but compromised link — exactly as happened with the old bookmark for tornado.cash.
The technical aspect left out of the article is the very nature of domain expiration as an attack vector: the protocol officially abandoned renewing the address due to OFAC sanctions, yet the domain's reputation in search engines and users' memory persisted for years to come. A similar disconnect between the legal status of a domain and audience trust may repeat with other projects facing restrictions. Will the practice of "domain legacy" remain a risky zone for DeFi users even after this case?
end-content







