Cryptonews
Phishing Attack via Tornado Cash Domain Drains $2.3 Million in Ethereum
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Article Content
An Ethereum user lost 1,010 ETH, valued at approximately $2.3 million, in a phishing attack exploiting an expired Tornado Cash domain. The incident, reported by Wu Blockchain, involved the attacker registering the expired domain and creating a fake interface that mimicked the original service. The victim unknowingly authorized transactions, leading to the theft of funds over a 12-hour period. On-chain records confirmed 810 ETH of the loss, while the remaining 200 ETH is unaccounted for. The attack highlights vulnerabilities in domain management and the risks associated with phishing in the crypto space. Security experts warn that domain expiry is a common attack vector, and users should verify website authenticity. The stolen funds have not been recovered, and the incident reflects a broader pattern of similar attacks targeting defunct crypto domains.
Key Points: • 1,010 ETH worth $2.3 million was stolen in a phishing attack using an expired Tornado Cash domain. • The attacker registered the expired domain and created a fake interface to capture user credentials. • The incident underscores the security risks associated with domain mismanagement in the crypto ecosystem.