A crypto user lost 1,010 ETH after clicking an old bookmarked link that redirected to a phishing site impersonating Tornado Cash, hosted on the privacy protocol's expired official domain. According to community reports, the victim believed they were interacting with the legitimate tornado.cash frontend, when in fact the domain had lapsed and been repurposed by attackers.
The mechanics of the attack were straightforward but devastating: the fake frontend captured the victim's deposit credentials, which attackers then used to withdraw the funds before moving them across several addresses to obscure the trail. The stolen assets remained under the attackers' control as of the most recent on-chain tracking.
The root cause traces back to Tornado Cash's legal history. After the protocol's smart contracts were sanctioned by the U.S. Treasury's OFAC in 2022, maintaining official infrastructure — including simple tasks like domain name renewals — became legally and practically complicated for a protocol with no clear ongoing operator. The underlying smart contracts continue to function through decentralized access points like IPFS and ENS gateways, but many users still have years-old bookmarks pointing to the old primary domain, which is exactly what left this victim exposed. The stolen funds' movement can still be traced on-chain via Etherscan.
Part of a broader rebound in phishing losses
The incident lands amid a sharp reversal in phishing trends. Wallet-drainer losses had fallen to roughly $83.85 million across 2025 — an 83% drop from the year before — but January 2026 alone saw phishing losses exceed $300 million, driven in large part by a single $284 million theft from an investor tricked into revealing a hardware wallet recovery phrase. Security researchers have described the shift as a move toward “whale hunting,” with attackers abandoning mass campaigns aimed at large numbers of small wallets in favor of fewer, far larger targets.
What the incident underscores for users
Sanctioned or legally contested protocols present a particular version of this risk: without a company actively maintaining the official web presence, expired domains can sit unclaimed until an attacker registers them. Security practitioners generally recommend navigating to decentralized frontends via freshly verified IPFS or ENS links rather than relying on old browser bookmarks, particularly for any protocol whose official maintenance status is uncertain.
Related: US Charges 17 Iranian Hackers Over $6M Bitcoin Extortion, University Data Theft
The case is a reminder that phishing risk in crypto doesn't require a smart contract bug or an exchange hack — sometimes the vulnerability is simply an out-of-date bookmark pointed at infrastructure nobody is actively renewing anymore.