A cryptocurrency user has lost more than 1,000 ETH after falling victim to a Tornado Cash phishing attack that exploited an expired official web address once tied to the sanctioned mixing protocol. According to reporting from Wu Blockchain, the victim clicked an old bookmarked link that redirected to a fraudulent site built on the abandoned domain, triggering a rapid and costly theft that highlights a growing risk across decentralized finance: what happens when a project’s own web infrastructure quietly slips out of its control.
Summary
Key takeaways
- A user lost over 1,000 ETH after being redirected through Tornado Cash’s expired official domain, tornado.cash.
- Hackers drained 1,010 ETH from the victim within just 12 hours of the phishing site going live.
- The domain lapsed because Tornado Cash failed to renew it while operating under OFAC sanctions.
- Attackers registered the abandoned domain and built a fake frontend designed to harvest deposit credentials.
- Nearly 4,000 ETH has reportedly been stolen through similar phishing schemes tied to this domain over the past 12 months.
Phishing Attack Exploits Tornado Cash Expired Domain
The core of the incident is straightforward but painful: a user reused an old, bookmarked link to what they believed was the legitimate Tornado Cash portal. That link, however, no longer pointed to the real protocol. Instead, it led to a look-alike site controlled by attackers who had quietly taken over the lapsed domain, according to community reports cited by Wu Blockchain.
User loses over 1,000 ETH via phishing
Once the victim interacted with the fake platform and submitted deposit information, the attackers moved fast. Within 12 hours, hackers drained 1,010 ETH from the compromised account — a theft carried out entirely through the trust users had placed in a familiar, once-official web address.
Attackers set up fake frontend to steal credentials
The mechanics of the exploit were simple in design but effective in execution. After the original tornado.cash domain became available, phishing operators registered it and built a cloned frontend mimicking the real interface. Anyone entering deposit credentials on that fake site handed their access directly to the attackers, who were then able to siphon funds without needing to breach any smart contract or wallet directly.
Domain Expiration Linked to OFAC Sanctions
This expired domain exploit traces back to a regulatory decision rather than a technical failure. Tornado Cash’s original web address lapsed after the project’s team failed to renew it, a lapse that occurred while the protocol remained under sanctions imposed by the U.S. Treasury’s Office of Foreign Assets Control, known as OFAC.
That sanctions status effectively froze the project’s ability to operate normally, including basic administrative tasks like domain renewal. Once the registration expired, the address became available on the open market — and attackers were quick to claim it, turning a compliance consequence into an attack vector.
This is where the story moves beyond a single victim’s bad luck. When regulatory pressure disrupts a protocol’s ability to maintain even routine web infrastructure, it creates openings that bad actors are ready to exploit. The OFAC crypto sanctions against Tornado Cash were designed to curb illicit fund flows, yet the fallout from those same sanctions appears to have enabled a fresh wave of theft aimed at ordinary users still trying to reach the platform.
Broader Impact and Historical Scope of Phishing Attacks
This single case is not isolated. Tracking by the victim showed the stolen 1,010 ETH sitting mainly in addresses controlled by the hackers, and the same group is allegedly responsible for a much larger pattern of theft. Over the past 12 months, that group has reportedly stolen nearly 4,000 ETH through similar methods connected to the same expired domain infrastructure.
That scale turns what might look like a one-off scam into a sustained campaign. Each new victim likely follows the same path: an old link, a familiar-looking site, and a fast, quiet drain of funds before anyone notices. The recurring nature of this ETH theft phishing pattern suggests attackers have found a reliable formula and have little incentive to stop.
For the wider crypto industry, the episode is a pointed reminder that blockchain security isn’t just about smart contract audits or wallet safety. Web domains, DNS records, and other pieces of conventional internet infrastructure remain a soft target, especially for protocols operating under legal or regulatory constraints that limit their ability to maintain them. When a sanctioned project loses control of its own front door, users who trust old bookmarks or search results can walk straight into a trap without any warning signs.
FAQ
How did the phishing attack on Tornado Cash occur?
Attackers took over the expired official domain tornado.cash, set up a fake frontend, and stole deposit credentials when users accessed the phishing site.
Why was the Tornado Cash domain available to attackers?
The Tornado Cash team failed to renew the official domain tornado.cash amid OFAC sanctions, allowing attackers to register it once it lapsed.
How much Ethereum was stolen in the reported phishing attack?
The attackers drained 1,010 ETH from a user within 12 hours through the phishing site built on the hijacked domain.
Has phishing via the expired Tornado Cash domain been a recurring issue?
Yes. Nearly 4,000 ETH has reportedly been stolen through similar phishing methods connected to this domain over the past 12 months, according to tracking cited in the report.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

