Ethereum User Reportedly Loses 1,010 ETH in Tornado Cash Phishing Attack
Key Takeaways
- •An Ethereum user reportedly lost 1,010 ETH in a phishing attack after using an expired Tornado Cash interface, and the report has not been independently confirmed.
- •The loss stemmed from a malicious transaction approval signed by the victim rather than an exploit of Tornado Cash's underlying protocol code.
- •Tornado Cash was sanctioned by the US Treasury in August 2022, a Fifth Circuit ruling found the sanctions overreached in November 2024, and they were lifted in March 2025, after which the official site returned.
- •Security firm Coinspect has documented that expired zombie dApp domains can be re-registered or spoofed to harvest approvals from returning users.
- •Recommended protections include verifying exact URLs, reading transaction contents before signing, and revoking old token approvals using tools such as Revoke.cash or Etherscan's token-approval checker.

An Ethereum user has reportedly lost 1,010 ETH in a Tornado Cash phishing attack after interacting with what was described as an expired version of the privacy tool's front end, according to early reports that remain independently unverified.
What is known about the reported 1,010 ETH loss
The incident was flagged by crypto reporter WuBlockchain on X, which reported that a user lost the funds in a phishing attack. The report has not been independently confirmed at this stage.
A separate social post from Cryptopolitan described the same loss as occurring after the victim visited an expired Tornado Cash interface. The associated address can be reviewed on Etherscan for on-chain context.
- Reported loss: 1,010 ETH, attributed to a phishing attack.
- Named vector: a Tornado Cash-branded interface, reportedly expired.
- Status: reported, not independently confirmed.
How a Tornado Cash phishing lure can trap users
Phishing in crypto typically targets the user rather than the protocol. Instead of breaking a smart contract, an attacker tricks the victim into signing a malicious transaction or token approval that drains their wallet. In other words, the attack required the victim's own signature — an approval the attacker could not have obtained otherwise.
That distinction matters here. The reports frame the incident as phishing, not a protocol exploit, meaning the risk sat at the wallet-interaction layer rather than in Tornado Cash's underlying code hosted on the project's own site. Tornado Cash itself is a mixer that uses zero-knowledge proofs to break the on-chain link between sender and recipient, which made it one of Ethereum's most-used privacy tools before US authorities alleged it had also laundered billions of dollars, including funds tied to North Korea's Lazarus Group.
That legal history bears on how a lapsed front end becomes a trap. The US Treasury sanctioned Tornado Cash in August 2022, leaving the official interface offline for an extended stretch in which mirrors and archived copies circulated; a November 2024 Fifth Circuit ruling found the sanctions had overreached, and they were lifted in March 2025, after which the official site returned. A period without one canonical, always-live interface is exactly the environment where old bookmarks and remembered domains steer users toward stale or lookalike copies.
Abandoned or lapsed application domains are a known danger. Security firm Coinspect has documented how “zombie” dApps with expired infrastructure can be re-registered or spoofed, turning a once-trusted address into a trap that harvests approvals from returning users. Someone relying on an old bookmark or a remembered domain can be greeted by a page that looks authentic while collecting approvals.
What this means for Ethereum wallet security
A four-figure ETH loss underscores why front-end verification remains a persistent weak point, even for users comfortable with self-custody. Recognizable brand names offer no guarantee that the page loading in a browser is the legitimate one. Nor is this a niche threat: malicious approvals are delivered through rented “wallet drainer” kits, and on-chain security firms have measured hundreds of millions of dollars taken from victims via deceptive signatures in a single year.
Practical defenses center on scrutiny before signing. That means verifying the exact URL, reading each transaction's contents rather than blindly approving, and periodically reviewing and revoking token permissions granted to old applications — a task free tools such as Revoke.cash and Etherscan's token-approval checker are built for.
The same caution extends to onboarding and payment flows, where users have increasingly funded wallets through consumer-facing rails, and to jurisdictions formalizing retail access, such as Russia's move to allow public trading of Ethereum and other assets. Broader adoption widens the pool of targets that phishing operators try to reach.
Until the report is corroborated, the safest reading is a cautionary one: treat any privacy-tool interface, especially one that may have lapsed, as unverified until its domain and contract interactions are checked directly. The natural next checkpoints are independent confirmation from security researchers, on-chain tracing of the 1,010 ETH from the linked address, and identification of the domain implicated — none of which the early reporting has yet provided.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.