Odaily Planet Daily News Paradigm researcher Samczsun said on social media that Tornado.Cash suffered a governance attack at 15:25:11 Beijing time on May 20. The attacker granted himself 1,200,000 votes through a malicious proposal (adding additional functions to the proposal that enable him to update the proposal logic to obtain false votes). Since this exceeds the number of approximately 700,000 legitimate votes, the attacker now has full control. Through governance control, the attacker can: extract all locked votes; drain all tokens in the governance contract; disable the router. However, the attacker still cannot drain individual funding pools. So far, the attacker has extracted and sold about 10,000 TORN.
