# Tornado Cash security and exploitation incidents

> Live situation record from CLSTR: https://clstr.news/situations/tornado-cash-security-and-exploitation-incidents
> Updated: 2026-08-20T12:26:09.000Z. Sources: 2. Developments: 2.

The Tornado Cash mixing protocol has been central to several recent cryptocurrency security incidents involving the movement and theft of Ethereum.

Following an exploit of the Aztec Network private roll-up bridge in June 2026, a hacker has moved a cumulative 500 ETH into Tornado Cash. These transfers, totaling approximately $572,100 in the most recent batch, have been conducted in small, irregular increments to avoid the rapid laundering patterns typically seen in crypto thefts.

Separately, the protocol’s expired domain has been leveraged in phishing attacks. After the Tornado Cash team failed to renew the domain due to regulatory pressures and OFAC sanctions, attackers registered the abandoned domain to redirect users to fraudulent websites. One such incident resulted in the theft of 1,010 ETH, valued at roughly $2.4 million. Reports suggest this domain-based phishing scheme has been responsible for the theft of over 4,000 ETH within a 12-month period.

## Timeline

### 2026-08-20: Tornado Cash expired domain exploited in $2.4 million phishing theft

A user lost over 1,000 ETH after a phishing attack exploited the expired official domain of Tornado Cash, which was left unrenewed following US sanctions.

2 sources. https://clstr.news/cluster/tornado-cash-expired-domain-exploited-in-24-million-phishing-theft

### 2026-08-08: Aztec Network Exploit Funds Move 500 ETH to Tornado Cash

The Aztec Network exploit attacker has moved a total of 500 ETH (~$1.1 million) to Tornado Cash in small batches, per PeckShield.

3 sources. https://clstr.news/cluster/aztec-network-exploit-funds-move-500-eth-to-tornado-cash

---
Cite as: Tornado Cash security and exploitation incidents. CLSTR, https://clstr.news/situations/tornado-cash-security-and-exploitation-incidents
