BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Bitcoin

Tornado Cash Phishing Frontend Drains 1,010 ETH From User

A crypto user lost 1,010 ETH after following an old Tornado Cash bookmark into a phishing frontend that captured the private withdrawal credentials needed to access the deposited funds. The v

AnonymousCryptoCompass newsroom
August 21, 2026
3 min read
NEWS
Tornado Cash Phishing Frontend Drains 1,010 ETH From User
CryptoCompass editorial visual for bitcoin coverage.

A crypto user lost 1,010 ETH after following an old Tornado Cash bookmark into a phishing frontend that captured the private withdrawal credentials needed to access the deposited funds.

The victim deposited the ETH into legitimate Tornado Cash contracts, but the malicious interface obtained the private note generated during the process. The attacker then used those credentials to withdraw the assets within roughly 12 hours without compromising the underlying Tornado Cash smart contracts.

Phishing Frontend Targeted Private Withdrawal Notes

Tornado Cash separates deposits and withdrawals through zero-knowledge proofs. A deposit generates a private note that controls the subsequent withdrawal, meaning possession of that note is enough to claim the corresponding assets.

The malicious frontend copied the protocol interface while capturing those credentials before the victim could complete the withdrawal. A stale bookmark reportedly directed the user to the compromised page after the former Tornado Cash domain had lapsed during the disruption surrounding U.S. sanctions.

The attack closely resembles an earlier case in which the zkLend exploiter lost 2,930 ETH to a fake Tornado Cash frontend while attempting to move funds stolen from the lending protocol.

Nearly 4,000 ETH in thefts over the past 12 months has now been attributed to the phishing operation tied to the latest frontend.

810 ETH Appears Across Nine Visible Withdrawals

The reported loss totals 1,010 ETH, while the publicly traced withdrawal sequence accounts for 810 ETH across nine transactions. The remaining 200 ETH has not been tied as cleanly to the same visible destination path.

Phishing losses have continued to hit Ethereum users through several attack methods. A user lost $999,999 in USDT in July after signing a malicious token approval, giving the attacker permission to drain the wallet without obtaining its private key.

Another campaign drained an estimated $2.94 million from Polymarket users holding pUSD after victims interacted with malicious links, signatures or approvals.

The Tornado Cash case took a different route: the ETH reached the intended privacy contracts, but control of the deposits was lost when the frontend captured the withdrawal notes.

Victim Funds Trace Back To Whirlpool

The wallet behind the loss had received 73 BTC worth about $4.6 million from the Whirlpool Bitcoin mixer roughly two weeks earlier before part of the position moved into Ethereum and Tornado Cash.

The same user had claimed the Bitcoin was moved because of concerns around Coldcard wallet security, while wallet activity also connected the account to Telegram groups focused on private-key searching and brute-force tools. The transaction history has raised the possibility that the victim was itself involved in high-risk crypto activity.

Tornado Cash was removed from the U.S. Treasury sanctions list on March 21, 2025. Its current web interface lists app.tornado.cash alongside ENS and IPFS-based mirrors for accessing the protocol.

The post Tornado Cash Phishing Frontend Drains 1,010 ETH From User appeared first on Crypto Adventure.