An Ethereum user reportedly lost 1,010 ETH, worth more than $2 million, after accessing what community reports described as a malicious Tornado Cash frontend through an old bookmark.
The incident has raised fresh concerns about phishing attacks that target trusted crypto websites and outdated links. However, the available blockchain evidence only confirms 810 ETH moving into the wallet linked to the suspected attacker, meaning part of the reported loss remains unverified.
The case also highlights one of the biggest risks associated with privacy protocols such as Tornado Cash: anyone who gains access to a valid deposit note may be able to withdraw the corresponding funds.
Onchain Data Confirms 810 ETH
According to onchain records, the wallet cited in connection with the attack received 810 ETH through nine separate transactions on Aug. 18.
Eight of those transfers were for 100 ETH each, while the final transaction carried another 10 ETH.
The transfers occurred within a short period between approximately 5:56 a.m. and 6:05 a.m. UTC.
When the wallet was checked on Aug. 20, it still held roughly 810 ETH.
At an Ethereum price of around $2,295, that balance was worth approximately $1.86 million.
Community reports, however, claimed that the total amount stolen from the victim was 1,010 ETH.
At the same market price, the full reported loss would be worth approximately $2.32 million.
200 ETH of the Reported Loss Remains Unverified
The blockchain data creates an important gap between what can be independently confirmed and what has been claimed publicly.
The reported loss stands at 1,010 ETH, but the cited wallet only confirms receipt of 810 ETH.
That leaves approximately 200 ETH unaccounted for.
It is possible that the remaining funds were sent to another address, but no additional wallet was provided in the available evidence.
At the time of review, the suspected wallet had not made any outgoing transfers, meaning most of the confirmed stolen funds appeared to remain in the same address.
No official statement from the reported victim, Tornado Cash or a major blockchain security company had independently confirmed the entire 1,010 ETH loss.
For that reason, the 810 ETH transfer is the strongest confirmed part of the incident.
Reports Blame an Alleged Tornado Cash Phishing Frontend
Community accounts claimed that the victim accessed Tornado Cash through an old bookmarked website.
According to those reports, the link allegedly directed the user to a malicious frontend controlled by attackers.
The attackers were then said to have obtained the user’s Tornado Cash deposit credentials and used them to withdraw the funds.
However, reports claiming that the official Tornado Cash domain itself had expired and been taken over by attackers have not been independently confirmed.
When the website was checked, the domain was accessible and displayed a Tornado Cash interface.
No official Tornado Cash warning, authoritative domain ownership record or named security researcher had confirmed that the domain had changed ownership.
As a result, the alleged domain takeover should still be treated as an unverified explanation rather than a confirmed cause of the theft.
A Website Can Look Normal After an Attack
The fact that a website appears legitimate now does not necessarily prove that it was safe earlier.
Attackers can use several techniques to avoid detection.
For example, malicious code can be removed after credentials are collected. A website can also redirect only certain users while serving a legitimate interface to everyone else.
This makes frontend-based phishing particularly difficult to identify.
Users may see a familiar domain, interface and branding and assume that the website is safe.
Old bookmarks can make that problem worse because people often continue using links they trusted months or even years earlier without checking whether anything has changed.
Tornado Cash Has Faced Frontend Security Issues Before
Tornado Cash has previously experienced frontend-related security problems.
In 2024, security researcher Gas404 discovered malicious JavaScript inserted into an open-source Tornado Cash interface.
The malicious code was capable of exposing private deposit notes.
Security company Checkmarx later documented the supply-chain compromise and described how malicious code could remain active for extended periods.
There is currently no confirmed evidence linking that older incident to the latest Ethereum transfers.
Still, it demonstrates why frontend security is especially important for privacy protocols.
A blockchain smart contract may continue working exactly as designed while a compromised interface steals sensitive information before it reaches the contract.
Why Tornado Cash Deposit Notes Are So Sensitive
Tornado Cash uses private deposit notes as part of its privacy system.
When users deposit funds, they receive information that is later required to withdraw those assets.
Anyone who obtains a valid deposit note may be able to initiate the withdrawal.
In practice, that makes the deposit note similar to a highly sensitive private credential.
If a phishing website captures the note, the attacker may be able to withdraw the funds before the legitimate owner does.
This creates a different type of attack from the approval phishing commonly seen with wallet drainers.
How This Attack Differs From Wallet Drainers
Traditional crypto phishing attacks often trick users into signing malicious blockchain transactions.
A victim may believe they are approving a legitimate interaction, while the transaction actually grants a malicious smart contract permission to move their tokens.
Once the approval is granted, the wallet drainer can transfer assets.
A stolen Tornado Cash deposit note works differently.
The victim may not need to sign a malicious approval at all.
Instead, an attacker only needs to capture the sensitive withdrawal information.
That makes fake frontends particularly dangerous because users may not immediately realize that anything has gone wrong.
Old Crypto Bookmarks Can Become a Security Risk
The incident also highlights the risks associated with old bookmarks.
Crypto users often bookmark websites they trust so they do not have to search for the project again.
That usually reduces the risk of clicking fake search advertisements or lookalike domains.
However, a bookmark is only safe as long as the destination remains under the control of the legitimate project.
If a domain expires, changes ownership or becomes compromised, the bookmarked link may still look completely familiar.
Attackers can take advantage of the domain’s reputation, search ranking and existing backlinks to convince victims that nothing has changed.
For this reason, users should periodically verify important crypto websites through several current official channels rather than assuming an old bookmark remains trustworthy forever.
Claims of Nearly 4,000 ETH Stolen Remain Unverified
Community reports made an even larger claim, alleging that the same attackers may have stolen close to 4,000 ETH over the previous 12 months.
So far, there is not enough publicly available evidence to confirm that figure.
No complete list of associated wallets, transaction hashes or professional blockchain attribution report accompanied the claim.
Blockchain data can confirm that funds moved between addresses, but it cannot automatically prove who controlled each address or whether those transfers belonged to the same phishing campaign.
Without additional evidence, linking thousands of ETH in historical transactions to the same attackers would remain speculative.
The Confirmed 810 ETH Is Now the Main Focus
The immediate focus is likely to remain on the confirmed wallet holding 810 ETH.
If those funds begin moving, blockchain investigators will be able to follow the transactions.
Transfers to centralized exchanges could be especially important.
Exchanges may be able to identify users connected to deposit addresses and, depending on applicable laws and internal procedures, potentially freeze suspicious funds.
However, attackers often attempt to make tracking more difficult by splitting funds across multiple wallets, using decentralized exchanges or moving assets through privacy-focused services.
At the time the wallet was reviewed, the confirmed ETH had not yet been moved.
What Affected Users Should Do
Anyone who believes they interacted with the same suspected frontend should stop using it immediately.
Users should verify the website through multiple current official sources before reconnecting a wallet.
If a wallet interacted with a suspicious site, users should review and revoke unnecessary token approvals.
Unaffected assets may also need to be moved to a fresh wallet if there is reason to believe sensitive credentials were exposed.
Victims should preserve as much evidence as possible, including browser history, bookmarked URLs, wallet logs, transaction hashes and screenshots.
These records may help blockchain security companies, exchanges or law enforcement understand what happened and follow the movement of stolen funds.
What Is Actually Confirmed So Far?
The available evidence supports one clear conclusion: a wallet associated with the reported attack received 810 ETH across nine transactions.
It does not yet independently establish that the victim lost the full 1,010 ETH.
There is also no definitive evidence confirming that Tornado Cash’s official domain was taken over by an attacker.
Likewise, allegations that the same phishing operation stole nearly 4,000 ETH over the previous year remain unsupported by sufficient publicly available blockchain attribution.
The distinction is important.
Crypto security incidents often spread quickly on social media, and early reports may mix confirmed blockchain activity with assumptions about how the attack happened.
Until further evidence emerges, the 810 ETH transfer remains the strongest independently verifiable part of the case.
The incident nevertheless provides another reminder that users need to protect more than private keys. Bookmarks, frontend websites, deposit notes and wallet permissions can all become attack surfaces in the crypto ecosystem.





















































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































