Industry News

Expired Website Domain Used to Steal Over $1,000 ETH in Tornado Cash Phishing Attack

Blockonomi · 21 Aug 2026
Key Takeaway Always verify website URLs before entering sensitive information or transacting, especially if you're using an old bookmark or link, as expired domains can be bought and weaponised by attackers.

A phishing attack targeting users of Tornado Cash, a cryptocurrency mixing protocol, has resulted in the loss of 1,010 ETH after a victim accessed the service through an expired domain. Attackers appear to have taken control of the lapsed domain and used it to redirect users to a fraudulent site designed to steal funds.

This incident highlights a growing tactic among cybercriminals: acquiring expired or abandoned domains once used by legitimate services and repurposing them for phishing. Because the domain may have previously been trusted or bookmarked by users, victims can be caught off guard, believing they are accessing a genuine platform.

While this attack targeted a cryptocurrency service, the underlying technique applies broadly. Any business or individual relying on old bookmarks, links from emails, or outdated documentation to reach a website is at risk if that domain changes ownership. Regularly verifying that links and bookmarks point to current, legitimate destinations can help prevent falling victim to similar schemes.

phishing cryptocurrency domain security

Summarised by CISO AI from Blockonomi. We link back to every original so you can read it yourself.