🚨 1,010 ETH evaporated overnight!
It wasn’t a contract hack—turns out an “old bookmark” caused the problem?
Group: 点击进入玖玖的粉丝群
Reports say a user lost 1,010 ETH after clicking a previously saved old Tornado Cash bookmark, which led them to a fake phishing interface. What’s especially noteworthy is that Tornado Cash’s underlying smart contracts were not attacked at all. The issue was with the “front-end.”
In Tornado Cash’s deposit and withdrawal mechanism, it generates critical private credentials used for later asset extraction. Once those credentials are obtained by a malicious website, the attacker can directly use them to complete withdrawals. In simple terms: your assets may still be in the original contract, but the “key to open the safe” has already been taken by someone else. 🔑
Reports indicate the attacker then moved the funds within about 12 hours.
On-chain records show that roughly 810 ETH is tied to multiple visible withdrawal transactions, while the remaining portion’s specific destinations still need further confirmation.
This also brings to mind similar incidents in the past.
In recent times, attack methods such as phishing sites, malicious approvals, and fake interfaces have become increasingly common. Attackers don’t even necessarily need to crack your wallet—or attack the underlying protocol.
They only need to make you:
- open the wrong website,
- connect your wallet,
- sign incorrect information,
- or leak key credentials.
One slip-up can lead to irrecoverable losses.
The biggest warning from this incident is: don’t blindly trust old bookmarks in your browser. 📌
Website domains can change, old links can break, and they can also be maliciously exploited. Even if you visited the same site before, it doesn’t mean the page you open today is still the official entry point.
Especially when performing on-chain actions, be sure to develop a few habits:
- First, verify official channels and check that the URL is correct.
- Don’t connect your wallet casually.
- Don’t sign information you don’t understand.
Click the profile photo to watch the livestream + join the Jiuji chat group to get daily strategies 🚀
#ETH #以太坊 #网络钓鱼诈骗
It wasn’t a contract hack—turns out an “old bookmark” caused the problem?
Group: 点击进入玖玖的粉丝群
Reports say a user lost 1,010 ETH after clicking a previously saved old Tornado Cash bookmark, which led them to a fake phishing interface. What’s especially noteworthy is that Tornado Cash’s underlying smart contracts were not attacked at all. The issue was with the “front-end.”
In Tornado Cash’s deposit and withdrawal mechanism, it generates critical private credentials used for later asset extraction. Once those credentials are obtained by a malicious website, the attacker can directly use them to complete withdrawals. In simple terms: your assets may still be in the original contract, but the “key to open the safe” has already been taken by someone else. 🔑
Reports indicate the attacker then moved the funds within about 12 hours.
On-chain records show that roughly 810 ETH is tied to multiple visible withdrawal transactions, while the remaining portion’s specific destinations still need further confirmation.
This also brings to mind similar incidents in the past.
In recent times, attack methods such as phishing sites, malicious approvals, and fake interfaces have become increasingly common. Attackers don’t even necessarily need to crack your wallet—or attack the underlying protocol.
They only need to make you:
- open the wrong website,
- connect your wallet,
- sign incorrect information,
- or leak key credentials.
One slip-up can lead to irrecoverable losses.
The biggest warning from this incident is: don’t blindly trust old bookmarks in your browser. 📌
Website domains can change, old links can break, and they can also be maliciously exploited. Even if you visited the same site before, it doesn’t mean the page you open today is still the official entry point.
Especially when performing on-chain actions, be sure to develop a few habits:
- First, verify official channels and check that the URL is correct.
- Don’t connect your wallet casually.
- Don’t sign information you don’t understand.
Click the profile photo to watch the livestream + join the Jiuji chat group to get daily strategies 🚀
#ETH #以太坊 #网络钓鱼诈骗