The Latest Crypto News
Friday, 25 September 2026 BTC -- / --
🔍

1,010 ETH stolen via expired Tornado Cash domain

Make The Latest Crypto News preferred on Google
Stylized tornado icon above an Ethereum coin on an expired domain warning screen.
Stylized tornado icon above an Ethereum coin on an expired domain warning screen.

A user has lost more than 1,000 Ethereum after visiting a phishing site through an old bookmark that was operating on the expired official domain of Tornado Cash. The domain was not renewed by the team, partly as a result of sanctions from the US authorities, after which attackers registered it and placed a fake interface on it. On-chain analyst Specter argues, however, that the alleged victim may himself be a malicious actor.

In brief:

  • A user lost 1,010 ETH via a fake version of Tornado Cash on an expired domain
  • The attacker group allegedly stole nearly 4,000 ETH in twelve months using similar methods
  • On-chain data suggests the alleged victim may himself be involved in illegal activities

Expired domain became a phishing trap

Tornado Cash, the well-known crypto mixer on Ethereum, did not renew its official domain after sanctions from the US Office of Foreign Assets Control (OFAC). Attackers seized that opportunity and registered the domain again to set up a fake version of the interface.

The victim clicked on an old link that was still in his bookmarks and ended up on the fake site. Within twelve hours, the hackers drained 1,010 ETH from his wallet. According to the trail kept by the victim himself, the stolen funds remain at the attackers’ addresses for now. The group behind this attack is said to have stolen nearly 4,000 ETH in total over the past twelve months using similar tricks.

Was the victim himself an attacker?

On-chain analyst Specter raises questions about the alleged victim’s story. According to Specter, available blockchain data indicates that the funds may originate from illegal activities.

The victim claimed to have transferred his holdings from Bitcoin to Ethereum because of a compromised hardware wallet. But on-chain data shows that the 73 BTC, worth around $4.6 million at the time, had come out of the Whirlpool Bitcoin mixer two weeks earlier, before being transferred to Ethereum and deposited on the fake interface.

Specter notes that routing funds through multiple mixers is not consistent with someone simply trying to escape a hacked hardware wallet. In addition, the same person was active in Telegram groups focused on cracking private keys and brute force tools. Specter describes the situation as possibly a case of two malicious parties stealing from each other.

The case shows how expired domains of well-known crypto projects pose a danger to users who rely on old links or bookmarks. Whether the victim is a legitimate user or another attacker has not yet been established.

Summarize this article with AI

Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.

Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.

More Scam News

More news ›