TLDR:A malicious Tornado Cash frontend captured withdrawal notes and enabled attackers to drain 1,010 ETH from one user.Attackers allegedly stole nearly 4,000 ETH through similar expired-domain phishing operations during the previous 12 months.On-chain data traced 73 BTC through Whirlpool before part of the funds moved to Ethereum and Tornado Cash.The incident shows how expired domains and outdated bookmarks can expose users despite legitimate underlying smart contracts.A Tornado Cash phishing attack has cost one user 1,010 ETH after an old bookmarked link led to a malicious website. The attackers reportedly controlled Tornado Cash’s expired tornado.cash domain and used it to imitate the protocol’s interface. The victim deposited funds into legitimate smart contracts but exposed private withdrawal information through the malicious frontend. Reports also linked the stolen funds to suspicious Bitcoin activity, raising questions about the victim’s earlier transactions.Tornado Cash Phishing Attack Exploits Expired Official DomainAccording to Wu Blockchain, the user accessed the malicious website through an old bookmark. The expired tornado.cash domain redirected the user to an attacker-controlled frontend.The victim then deposited ETH through Tornado Cash’s legitimate smart contracts. However, the fake interface reportedly captured private withdrawal notes required to later access the funds.Attackers allegedly drained the 1,010 ETH within 12 hours of the deposit. The stolen assets now remain largely in addresses connected to the attackers.Tornado Cash lost control of the domain after U.S. sanctions targeted the protocol in 2022. The team reportedly failed to renew the domain during that period, allowing attackers to register it later.The attackers then recreated a frontend resembling the original Tornado Cash interface. Wu Blockchain reported that similar phishing operations may have stolen nearly 4,000 ETH during the past year.User Loses Over 1,000 ETH in Phishing Attack After Using Tornado Cash’s Expired Official DomainAccording to community users, a user clicked an old link left in a related bookmark and was redirected to a phishing site through the expired official domain tornado. cash, which had… pic.twitter.com/8j7eQl3qX2— Wu Blockchain (@WuBlockchain) August 20, 2026The incident shows how expired domains can create risks even when underlying smart contracts remain legitimate. Users who rely on old bookmarks may unknowingly interact with attacker-controlled interfaces.The phishing website did not require attackers to alter Tornado Cash’s smart contracts. Instead, the operation targeted sensitive information generated during the withdrawal process.Users generally need those private notes to recover deposited funds. Once attackers obtained them, they could potentially claim the associated ETH.On-Chain Data Adds Another Layer to Tornado Cash AttackOn-chain researcher Specter examined the victim’s earlier transactions and questioned the source of the funds. He said the wallet moved 73 BTC, worth roughly $4.6 million, from a Whirlpool mixer.Part of those Bitcoin funds later moved across chains into Ethereum. The assets eventually reached the phishing Tornado Cash interface, according to the transaction trail.The victim reportedly claimed that an earlier Coldcard-related incident prompted the Bitcoin-to-Ethereum transfer. Specter questioned why the wallet used multiple mixing services before the phishing event.The victim could be a threat actor, and the funds may themselves have been stolen.He claimed to have moved his funds from Bitcoin to Ethereum because of the Coldcard hack.Looking on-chain, however, the 73 BTC ($4.6m) originally came from a Whirlpool mixer two weeks ago which… https://t.co/6x2jKeCjjF pic.twitter.com/KrZQUG9PQ9— Specter (@SpecterAnalyst) August 20, 2026Specter also reported connections between the individual and Telegram groups focused on private-key discovery and brute-force activity. The available information does not independently establish the person’s role or ownership of earlier stolen funds.Still, the transaction history created a second layer of scrutiny around the case. It also raised the possibility that the stolen ETH originated from another suspicious source.The immediate loss, however, followed the expired-domain phishing operation. The case centered on a malicious frontend rather than a failure within Tornado Cash’s smart contracts.The incident adds to a broader security concern surrounding dormant crypto domains. Old bookmarks can remain active long after project teams lose control of a website.The post Tornado Cash Phishing Attack Drains 1,010 ETH Through Expired Domain appeared first on Blockonomi.