A phishing attack linked to the expired official Tornado Cash domain has reportedly resulted in the theft of approximately 1,010 ETH, highlighting the risks of interacting with outdated crypto links and decentralized finance (DeFi) platforms.

According to reports from community members, a user clicked an old link saved in a related bookmark and was redirected to a phishing website hosted on tornado dot cash, the former official Tornado Cash domain. The domain had reportedly expired after the Tornado Cash team failed to renew it amid ongoing sanctions from the U.S. Office of Foreign Assets Control (OFAC).
After the domain expired, attackers reportedly registered it and created a fake Tornado Cash frontend designed to trick users into revealing sensitive deposit information. Within just 12 hours, hackers allegedly drained around 1,010 ETH from victims who interacted with the fraudulent website.
Blockchain tracking indicates that much of the stolen Ethereum remains in addresses controlled by the attackers. The incident also appears to be part of a broader pattern of crypto phishing attacks targeting users through compromised or expired websites.
According to the victim’s tracking efforts, the same group may have stolen nearly 4,000 ETH over the past 12 months using similar phishing techniques.
The incident serves as another warning for cryptocurrency users to verify website domains carefully before connecting a wallet, approving transactions, or entering any sensitive information. Even a familiar-looking crypto website can become dangerous if its domain expires or is taken over by malicious actors.
Users should avoid relying on old bookmarks and saved links when accessing DeFi platforms. Instead, they should verify the official domain through trusted sources and carefully check the website address before connecting a crypto wallet.
The Tornado Cash domain incident demonstrates how seemingly simple domain hijacking can lead to significant cryptocurrency losses, particularly when attackers recreate a familiar interface and exploit users’ trust in a previously legitimate website.
