One user of the Ether Workshop has recently been alleged to have lost 1,010 ETH for access to suspected fake frontend pages of Tornado Cash. However, the existing chain records only confirm that 810 of these ETH have been transferred to a newly active wallet address and that 200 of the remaining ETH have not been publicly evidenced.
810 ETH have been identified on the chain.
According to community accounts, the incident lasted approximately 12 hours. The attackers allegedly obtained the victim ' s Tornado Cash deposit certificates, which were subsequently withdrawn and transferred out.
The current independently verifiable part is a related address that received 9 transfers on 18 August, totalling 810 ETH. Of these, 8 were 100 ETH each, and the last 1 was 10 ETH.
- Transfer time is concentrated on UTC time 5:56 to 6:05
- No transfer records were available at the address review
- 810 at current prices
This means that there is still a difference of 200 ETH between the total loss claimed by the community for the 1010 ETH and the amount that has been confirmed for the address. The available material does not provide additional receiving addresses and does not fully complete the funding path.
Domain name takeover is not confirmed.
Some of the community accounts attributed the incident to the re-registration of the attacked person after the expiry of the Tornado.cash domain name and the deployment of a false interface. At the time of publication, however, this claim had not been independently confirmed by Tornado Cash official, well-known security companies or well-known researchers.
The report mentions that the site is still accessible at the time of the inspection and shows the Tornado Cash interface. This does not reverse a certain degree of security in the past, as the attackers may have placed malicious pages only on some of the visitors, or may have returned to normal interfaces once the documents had been stolen.
In other words, the current evidence supports the conclusion that “a substantial ETH transfer has taken place”, but it is not sufficient to substantiate the conclusion that “official domain names have been taken over”.
The deposit certificate is leaked and the money can be collected directly.
Tornado Cash relies on private deposit certificates. As long as a valid certificate is available, a corresponding withdrawal can normally be initiated. As a result, such documents are in effect close to sensitive information at the private key level.
The risk of falsifying the front end is that the user, whether in deposit or withdrawal, can be intercepted by the assailant if the relevant information is entered on the page. Old bookmarks are also a common source of risk, as users often acquiesce that past credible links remain secure.
Tornado Cash has also experienced front-end security problems in the past. In 2024, researchers found that their open-source interface had been inserted into malicious JavaScript, which could expose the user ' s confidential deposit information. However, there is currently no evidence of a direct link between the incident and the transfer.
There's not enough evidence for 40000 ETH.
The community also alleged that similar methods had caused nearly 400 ETH losses over the past 12 months. However, this figure is currently not supported by a wallet address, a trader, or a security agency report and cannot be independently validated.
It is more clear at this stage that 810 ETH have entered a new active address and remained there at the time of review. If follow-up funds flow to the trading platform, the platform may identify or restrict asset flows according to its own processes.
