Expired Website Domain Used to Steal Over $1,000 ETH in Tornado Cash Phishing Attack
A phishing attack targeting users of Tornado Cash, a cryptocurrency mixing protocol, has resulted in the loss of 1,010 ETH after a victim accessed the service through an expired domain. Attackers appear to have taken control of the lapsed domain and used it to redirect users to a fraudulent site designed to steal funds.
This incident highlights a growing tactic among cybercriminals: acquiring expired or abandoned domains once used by legitimate services and repurposing them for phishing. Because the domain may have previously been trusted or bookmarked by users, victims can be caught off guard, believing they are accessing a genuine platform.
While this attack targeted a cryptocurrency service, the underlying technique applies broadly. Any business or individual relying on old bookmarks, links from emails, or outdated documentation to reach a website is at risk if that domain changes ownership. Regularly verifying that links and bookmarks point to current, legitimate destinations can help prevent falling victim to similar schemes.