
An Ethereum user reportedly lost 810 ETH after visiting a phishing site mimicking Tornado Cash's interface through an expired domain. According to community reports, the incident unfolded over approximately 12 hours as attackers obtained the victim's Tornado Cash deposit credentials and withdrew the funds before transferring them to several addresses. Onchain records confirm that 810 ETH reached the cited wallet through nine transactions on August 18, with eight transfers carrying 100 ETH each and the final transfer carrying 10 ETH.
The verified transactions leave a 200 ETH gap between the reported 1,010 ETH loss and the 810 ETH held by the cited wallet. The remaining amount may have reached another address, but no additional destination was included in the supplied evidence. At Ether's price of approximately ₹1.9 lakh, the confirmed 810 ETH was worth about ₹1.86 crore when checked on August 20. The reported 1,010 ETH loss would be worth roughly ₹2.32 crore at the same price. The cited wallet retained approximately 810 ETH, valued by Etherscan at about ₹1.86 crore when checked.
Reports blamed the theft on the tornado.cash domain, claiming it expired after the project's team failed to renew it during the disruption caused by U.S. sanctions. According to the accounts, an attacker subsequently registered the address and installed a fake user interface. However, the domain was accessible and displayed a Tornado Cash interface when checked, with no authoritative domain record, official Tornado Cash warning or named security researcher confirming that the address had expired and changed ownership. The immediate priority is monitoring the confirmed 810 ETH, with transfers to exchanges potentially creating opportunities for platforms to identify or freeze assets.
Tornado Cash uses private deposit notes to let users withdraw assets from its pools, making the note comparable to a private credential. A fake frontend can capture this information when a user attempts to make a deposit or withdrawal, allowing the attacker to use the stolen note before the legitimate owner does. The attack differs from approval phishing, where a victim signs a malicious transaction that authorizes a drainer contract. Old bookmarks present another risk because users often assume previously trusted links remain safe, with expired or transferred domains preserving familiar names, search rankings and backlinks that make malicious replacements harder to identify.
Community reports also alleged that the same attackers stole almost 4,000 ETH through similar methods over the previous 12 months. However, without linked wallets, transaction hashes or a report from a security firm, the 4,000 ETH estimate cannot be independently verified. The incident highlights risks of using outdated bookmarks and the importance of verifying official domains before wallet interactions. Users who interacted with the same frontend should stop using it, move unaffected assets and revoke suspicious token approvals.