Key Insights:
- According to onchain, 810 ETH were transferred into the wallet on 18 August, via nine transactions.
- Community reports place the victim’s total loss at 1,010 ETH, leaving 200 ETH unaccounted for.
- Evidence has not confirmed claims of a domain takeover or a wider 4,000 ETH phishing campaign.
Tornado Cash phishing attack reports say an Ethereum user lost 1,010 ETH after accessing a website through an old bookmark. Onchain evidence confirms 810 ETH reached the cited wallet on August 18. But some of the facts surrounding the theft have not been confirmed.
The case reveals a flaw in the security that transcends blockchain code. Today, crypto users continue to rely on websites and domains, browsers, and private credentials to enter into decentralized services.
User Loses Over 1,000 ETH in Phishing Attack After Using Tornado Cash’s Expired Official Domain
According to community users, a user clicked an old link left in a related bookmark and was redirected to a phishing site through the expired official domain tornado. cash, which had… pic.twitter.com/8j7eQl3qX2
— Wu Blockchain (@WuBlockchain) August 20, 2026
Onchain trail confirms $1.86 million
Ethereum records provide the strongest evidence surrounding the reported theft.
The cited wallet received nine transactions between 5.56 a.m. and 6.05 a.m. UTC on August 18. Eight transfers contained 100 ETH each, while another carried 10 ETH. Those transactions brought the address to 810 ETH. The wallet retained that amount when reviewed on August 20.
Etherscan valued the holdings at approximately $1.86 million at the time. Ether traded near $2,295 based on the figures provided. Community accounts, meanwhile, put the victim’s total loss at 1,010 ETH. That amount would carry a value near $2.32 million at the same price.
The available transaction evidence does not explain the 200 ETH difference. No additional destination wallet accompanied the information supporting the larger figure. Therefore, blockchain records establish a substantial transfer but do not independently prove the entire reported loss.
Old bookmark sits at center of phishing claim
Community reports said the victim accessed an old bookmark associated with the privacy service.
The reports allege that attackers controlled the destination and operated a fraudulent frontend resembling the familiar interface. The victim then reportedly provided sensitive deposit information through that website. Attackers allegedly used those credentials to withdraw funds during a roughly 12-hour period.
Some accounts also claimed the project’s original domain expired during disruption linked to U.S. sanctions. According to that version, malicious operators later registered the address and converted it into a phishing site. Yet the available evidence does not confirm that sequence.
The website displayed a working interface when reviewed. More importantly, no authoritative domain record provided with the allegations established an ownership transfer.
An operational website today cannot establish what happened earlier. Attackers can selectively redirect traffic to specific individuals or to delete malicious code. However, with these allegations, the domain takeover is so far a claim, not a proven fact.
Private deposit credentials create another risk
The attack method is reported to be different from the typical wallet draining attacks.
Its privacy protocol allows users to withdraw funds from its pools with the help of private deposit notes. Anyone who gets a valid note will be able to withdraw the corresponding assets. A fake front-end could take advantage of that feature by getting the credential straight from a user. The attacker might then do something before the withdrawals are finished for the rightful owner.
This would not involve compromising with Ethereum. Also, attackers would not necessarily have to exploit the underlying smart contracts of the protocol. Rather, attackers would be targeting the human side of the blockchain application’s infrastructure.
Old bookmarks further compound that risk as it is perceived that they are linked to past trust. But websites can change hands or be compromised for long after users have saved them.
Security concerns on the front end were already identified for the service before. Gas404 researcher discovered malicious JavaScript in an open source interface in 2024. Later, Checkmarx documented the supply-chain compromise. There is no evidence so far that links the earlier episode to the next transfers.
Wider 4,000 ETH allegation lacks evidence
The attackers have been suspected of siphoning nearly 4000 ETH from their victims over the past year.
This amount would indicate that it was a continued phishing scheme, not a one-off theft. But there is insufficient evidence available to attribute that to the material. There is no definitive list of suspected wallets to support the number. Also, the reports do not contain any transaction hashes that link all the alleged thefts to a common operator.
The blockchain can be used to track money from one address to another, but this is only a first step to attribution—more evidence is needed. However, just because someone or some group moved the wallet, it does not mean they had multiple addresses.
The incident nevertheless raises a broader concern for decentralized finance.
Security audits generally concentrate on smart contracts, bridges, and blockchain vulnerabilities. Yet users access those systems through conventional internet infrastructure that can also fail.
Domains, hosting services, browser bookmarks, and web interfaces remain important security boundaries. A secure smart contract cannot protect credentials voluntarily entered into a convincing counterfeit website.
Conclusion
The blockchain trail shows that a total of 810 ETH was deposited into the mentioned address in nine quick transactions. The other allegations need to be substantiated.
The investigators still have to figure out how the other 200 ETH got behind the 1,010 ETH reported loss. There should also be independent evidence to show if the attackers ever had control of the disputed domain.
The same standard would be applied to claims of almost 4,000 ETH in previous thefts. The case includes a practical warning for crypto users. A legitimate link may not be always be trusted when bookmarked.
It is important to check out the type of channels before submitting if you have already existing channels. The journey to a protocol is as important as the protocol itself in decentralized finance.









