An Ethereum user reportedly suffered a loss of 1,010 ETH due to a single click on an old link stored in their browser bookmarks. However, new on-chain data confirms the movement of 810 ETH, worth $1.86 million, which was drained into the hacker’s wallet within a nine-minute window on August 18, specifically between 05:56 and 06:05 UTC. The transfer of these high-value assets occurred through nine consecutive transactions, consisting of eight transfers of 100 ETH each and one transfer of 10 ETH. The 200 ETH discrepancy between the victim’s initial report and the on-chain trail has not yet been confirmed through independent investigation. The hacker’s wallet still holds the stolen 810 ETH in its entirety at the time of writing.
How a Legitimate Domain Can Change Hands
Community reports indicate that the incident began with the user’s habit of accessing the site via an old bookmark pointing to tornado.cash. This popular domain is highly suspected to have expired while the project’s development team was facing operational disruptions due to pressure from United States government sanctions. This temporary lapse in control is believed to have been exploited by the attackers to re-register the domain name. After successfully seizing control, they set up a fake interface designed to look identical to the original to deceive returning visitors.
Claims regarding the domain ownership change have not been officially confirmed by any independent authority. If accessed today, the link still displays the standard Tornado Cash interface, making it natural for ordinary users not to suspect anything. The method used by the attacker targets the most critical element: the fake interface is specifically programmed to intercept the deposit notes of Tornado Cash users. Once these secret notes are recorded in the malicious system, the attacker immediately moves to withdraw the funds long before the victim realizes what has happened and can save their assets.
Not the First Interface Attack
This front-end trap recalls a series of issues that previously hit the Tornado Cash ecosystem. In 2024, a security researcher going by the pseudonym Gas404 discovered malicious JavaScript injected into the project’s open-source interface code. Security firm Checkmarx documented the findings at the time as a supply chain compromise, proving that third-party code can serve as an exploit entry point.
The level of suspicion within the community has now widened. Some community members even claim that the perpetrator behind this latest hack is the same attacker who has amassed a total of nearly 4,000 ETH using similar methods over the past 12 months. Although these linked allegations have not been independently verified, the loss of hundreds of ETH serves as clear proof that threats still loom.
For anyone interacting with coin mixing services, double-verification is now non-negotiable. Relying on history or saved browser links has proven to be fatal. Users are strongly advised to always double-check the validity of the domain through the project’s official channels before connecting wallets or entering secret notes. Reporting by crypto.news.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




