Bitcoin Mix
© 2026 mixerbtcpro.com | All rights reserved.
  • Protecting your privacy since 2017.
  • TOR v3: http://blenderxzgdsdrdsz5rkuh6e6fpe6zckdpos2tuscp4epmyngmbcqmqd.onion
  • Service address: 33M4cJM3egGFhLk65jbH5JTar8L5tYWWxD
  • PGP keys: B894D26778F08535
Security

Tornado Cash domain phishing shows bookmark risk

On 20 August 2026, Wu Blockchain reported that an Ethereum user may have lost funds after following an old bookmark tied to a former Tornado Cash domain. Public reports cite a 1,010 ETH loss, but independent checks do not confirm every detail, so the central lesson is not the exact number. It is the weakness of trusting a familiar address after infrastructure has changed.

Tornado Cash domain phishing shows bookmark risk

What was reported

According to Wu Blockchain, the user opened an old saved link associated with Tornado Cash and landed on a phishing frontend. Community reports said attackers obtained data needed to withdraw assets from the pools and moved the funds within roughly 12 hours.

The case matters beyond one protocol because it does not read like a smart-contract exploit. The risk appeared at the web interface, domain and user habit layer. For a wallet owner, that can be more dangerous than it looks: a familiar page can become hostile even when the underlying protocol has not been altered.

Why the deposit note mattered

In Tornado Cash classic pools, a private note is generated when a user deposits funds. The protocol documentation describes that note as the material needed to withdraw the deposit later. If someone else obtains it, that person can try to withdraw before the legitimate owner.

That is why a counterfeit frontend can be especially damaging in this kind of application. It does not need to break a wallet or modify a contract. It only needs to convince the user to enter sensitive data into an interface that appears familiar. The attack pattern is closer to credential theft than to a blockchain exploit.

Which details are still disputed

Public reports disagree on the amount. Wu Blockchain and several outlets cite 1,010 ETH, while FinanceFeeds notes that open evidence independently traces nine transfers totaling 810 ETH and that the remaining 200 ETH was not confirmed with the same level of public detail.

The domain-control claim also requires caution. Community accounts say the former tornado.cash domain expired during sanctions-related disruption and was later registered by attackers. Other checks reported no official Tornado Cash warning or authoritative domain record proving the transfer at publication time. The safer wording is therefore a reported phishing case involving a former domain, not a fully proven account of every infrastructure step.

Sanctions can widen infrastructure gaps

OFAC sanctioned Tornado Cash on 8 August 2022, describing it as a virtual currency mixer and linking its use to laundering stolen funds. That regulatory context does not explain away the phishing case, but it does show how legal pressure can disrupt the surrounding infrastructure of a protocol.

When a site, domain, documentation path or support channel is no longer maintained consistently, users may continue to operate in an old information environment. A browser bookmark, legacy tutorial or social-media link can outlive real control over the destination.

A bookmark is not proof of trust

A domain name is not cryptographic proof. It can expire, be transferred, be blocked, be affected by DNS problems or serve a malicious interface after ownership changes. The older a saved link is, the weaker the assumption that it still points to the same operator.

This is especially important for crypto services because the frontend can touch addresses, amounts, token approvals, transaction signatures and other sensitive actions. A wallet may show a technically valid transaction while the user is still acting through the wrong page.

What to check before using a wallet

A safer workflow starts with rechecking the source. Before interacting with any financial interface, users should open current official channels, verify the domain, read wallet warnings and confirm that contract addresses match expectations. Old links deserve this check every time.

Private keys, seed phrases, deposit notes and similar secrets should not be entered just because a page looks familiar. If an application asks for sensitive material, the user needs to understand why it is needed, where it is processed and whether a more verifiable path exists.

  • Do not treat an old bookmark as the only proof that a site is authentic.
  • Verify the domain through current official channels, not old articles.
  • Check contract addresses and transaction parameters before signing.
  • Do not enter secret notes or keys into an interface with uncertain provenance.

The practical lesson

The Tornado Cash case shows that an old crypto interface can become a new risk. Even when a blockchain and its smart contracts continue to operate under the same rules, web infrastructure, domains and user habits remain a separate attack surface.

Users need to verify both the transaction and the path that led to it. Services need to keep control of domains, publish clear warnings when infrastructure changes and reduce situations where sensitive data is typed into a web form without an additional trust check.

Back to blog Open Bitcoin Mix