Ethereum Phishing Attack Reportedly Drains 1,010 ETH Through Tornado Cash Link
Key Takeaways
- •WuBlockchain cited community reports that a victim was routed from an old tornado.cash link to a fake frontend and lost 1,010 ETH.
- •Separate reports challenged both the reported size of the theft and the claim that Tornado Cash’s former domain was controlled by attackers.
- •The stolen funds have not been moved from the attacker’s addresses, according to the report.
- •Onchain investigator Specter said the victim’s original 73 Bitcoin came from Whirlpool two weeks earlier and was partly bridged to Ethereum.
- •Malwarebytes and Check Point Research have both described broader phishing campaigns in which fake services and hacked websites are used to steal crypto wallets and spread malware.

An Ethereum phishing attack reportedly drained 1,010 ETH from a user who visited a Tornado Cash-linked website. WuBlockchain cited community reports saying the victim reached a fraudulent frontend through an old tornado.cash link.
The reported loss was worth roughly $2.3 million as Ethereum traded above $2,200. However, separate reports disputed both the exact amount stolen and claims that attackers had taken control of Tornado Cash’s former domain.
Onchain Analyst Questions Phishing Victim Background as Ethereum Crosses $2,000
The incident comes as Ethereum has been trading strongly, with the token climbing above $2,300. That would put the victim’s loss at well over $2.3 million in the phishing incident.
So far, there are no signs that the attacker has moved the stolen funds out of their addresses. The phishing also appears to have used similar techniques to steal up to $4 million over the past 12 months, underscoring how frequently wallet-draining scams continue to rely on familiar tactics rather than new exploits.
The incident has drawn reactions from several crypto users, and the victim has also come under scrutiny. Onchain investigator Specter suggested that the victim may be a threat actor.
In a post on X, Specter said the original 73 Bitcoin came from a Whirlpool mixer two weeks ago, with part of it bridged to Ethereum. According to the pseudonymous investigator, it is unusual that the victim used two mixers to avoid a compromise of a hardware wallet.
Specter added that the victim was also seen in private-key-finder and brute-force Telegram groups, which further supports the theory that the individual may be a threat actor.
Crypto Threat Actors Rely on Fake and Hacked Websites for Phishing Attacks
The incident is part of a growing trend of threat actors using fake or hacked websites to target crypto users. According to a report by Malwarebytes, scammers are using fake anti-money laundering services to drain users’ wallets.
These services let users check whether a crypto wallet has interacted with illicit or stolen funds. However, scammers are cloning legitimate platforms or creating fake ones with generic names that require users to connect their wallets to complete the checks, making the phishing flow look like a routine verification step.
Another report by Check Point Research said bad actors hacked nearly 2,000 WordPress sites to steal crypto wallets and spread malware.
The report said the operation is part of the StopAndProtect ransomware attack, with hackers deploying malware on compromised websites.
Users who visit hacked websites are targeted with a fake CAPTCHA that prompts them to run a command that installs malware on their computers. The malware steals private credentials, including wallet seed phrases, and can spread through networks and USB drives.
According to Check Point researchers, the infrastructure can also lock the screen of infected devices and deploy ransomware.