< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 2 sources · 13 days · First seen · Last updated

Tornado Cash security and exploitation incidents

Overview

The Tornado Cash mixing protocol has been central to several recent cryptocurrency security incidents involving the movement and theft of Ethereum.

Following an exploit of the Aztec Network private roll-up bridge in June 2026, a hacker has moved a cumulative 500 ETH into Tornado Cash. These transfers, totaling approximately $572,100 in the most recent batch, have been conducted in small, irregular increments to avoid the rapid laundering patterns typically seen in crypto thefts.

Separately, the protocol’s expired domain has been leveraged in phishing attacks. After the Tornado Cash team failed to renew the domain due to regulatory pressures and OFAC sanctions, attackers registered the abandoned domain to redirect users to fraudulent websites. One such incident resulted in the theft of 1,010 ETH, valued at roughly $2.4 million. Reports suggest this domain-based phishing scheme has been responsible for the theft of over 4,000 ETH within a 12-month period.

Entities

Tornado Cash · OFAC · PeckShield · Aztec Network · Wu Blockchain

Timeline

  1. 7 days ago

    [TECHNOLOGY] 2 sources
    Tornado Cash expired domain exploited in $2.4 million phishing theft

    A user lost over 1,000 ETH after a phishing attack exploited the expired official domain of Tornado Cash, which was left unrenewed following US sanctions.

  2. 19 days ago

    [TECHNOLOGY] 3 sources
    Aztec Network Exploit Funds Move 500 ETH to Tornado Cash

    The Aztec Network exploit attacker has moved a total of 500 ETH (~$1.1 million) to Tornado Cash in small batches, per PeckShield.

Sources

bitcoinethereumnews.com · bpmoney.com.br