Headline: Ethereum user reportedly loses up to 1,010 ETH after following old Tornado Cash bookmark — on‑chain data confirms 810 ETH moved An Ethereum user is reported to have lost 1,010 ETH after clicking an old Tornado Cash bookmark that allegedly redirected them to a malicious frontend. Community accounts say attackers captured the victim’s Tornado Cash deposit credentials and withdrew funds over a roughly 12‑hour window, but independent on‑chain evidence only partially corroborates the full loss. What the blockchain shows - On‑chain records link a newly active wallet to nine incoming transfers totaling 810 ETH on Aug. 18. Eight of those transactions were 100 ETH each and one was 10 ETH, all executed between 05:56 and 06:05 UTC. - The cited address retained about 810 ETH after these transfers. At an Ethereum price of roughly $2,295 (Etherscan valuation checked on Aug. 20), that amount was worth about $1.86 million. - Community reports claim the victim lost 1,010 ETH — roughly $2.32 million at the same price — leaving a 200 ETH gap that has not been substantiated by the evidence provided. The missing portion could have moved to other addresses, but no additional transaction links, addresses, or proofs were supplied. Domain capture claim remains unverified Community members allege the theft stemmed from tornado.cash’s official domain expiring amid disruption tied to U.S. sanctions, allowing an attacker to register the name and host a fake interface. At the time reporters checked, the domain loaded a Tornado Cash‑style interface. However: - No authoritative domain records, official Tornado Cash warning, or named security researcher has confirmed the domain was captured. - A site appearing safe at the time of checking does not rule out earlier malicious behavior; attackers can remove malicious code, selectively target visitors, or restore a legitimate UI after harvesting credentials. How the attack likely worked — and how it differs from other scams Tornado Cash relies on private deposit notes that serve as the credential required to withdraw funds from mixing pools. If a fake frontend captures a valid note, an attacker can initiate the withdrawal before the rightful owner — a theft method distinct from approval phishing, where victims sign a transaction that grants a drainer contract permission to move tokens. Security context and previous issues Tornado Cash frontends have faced security problems before. In 2024, researcher Gas404 discovered malicious JavaScript inserted into an open‑source interface that could expose private deposit notes; Checkmarx later documented a supply‑chain compromise. There is currently no direct evidence linking that incident to these latest transfers. Unverified broader claims Community posts also alleged the same attackers stole nearly 4,000 ETH over the past 12 months using similar techniques. No address lists, transaction hashes, attribution analysis, or security‑firm reports accompanied that total, so it cannot be independently verified. Blockchain traces show where funds moved, but they don’t automatically identify who controlled implicated addresses or which campaign produced them. What to do now - Monitor the confirmed 810 ETH: transfers to centralized exchanges could give platforms an opportunity to identify or freeze assets, depending on their policies and legal obligations. - If you are the victim (or used the same frontend), preserve browser history, bookmarked URLs, wallet logs and transaction records before contacting wallet providers, exchanges and law enforcement. - Stop using the suspected frontend, move unaffected assets to new wallets, and revoke any suspicious token approvals. Bottom line Available evidence supports a substantial Ethereum transfer into a newly active wallet, but it does not yet prove the full 1,010 ETH loss, a hostile takeover of the Tornado Cash official domain, or the alleged 4,000 ETH campaign. Users should treat old bookmarks and familiar domains with caution, verify project domains through up‑to‑date official channels, and protect private deposit notes and wallet credentials. Read more AI-generated news on: undefined/news