Hacker Exploits Tornado Cash, Laundering Stolen Funds Using the Same Service

In an unexpected twist, the hacker behind the Tornado Cash heist has made the surprising decision to relinquish control of the protocol and return it to the original team.

Adding to the irony of the situation, the criminal employed the exact service they targeted, Tornado Cash, to launder the funds obtained during the attack.

During the recent security breach, the hacker managed to seize a considerable amount of 483,000 TORN tokens. Following the theft, a significant portion of the stolen funds was converted into ETH using the protocol.

Unveiling the Hacker’s Tactics: Tornado Cash Hijack, Token Theft, and Money Laundering

On May 21, an attacker took advantage of a vulnerability in Tornado Cash’s governance system, which

ideally should be under the control of the community.

According to the incident report, the attacker gained control of the crypto mixer and managed to steal a

total of 483,000 TORN coins.

Blockchain researcher Samczsun uncovered that the hacker submitted a malicious governance proposal,

which was intended to be voted on by the community.

This tactic enabled the hacker to seize control of the protocol, granting them the ability to withdraw the

tokens held within the governance contract.

As reported by Nansen, the hacker converted the pilfered tokens into Ether (ETH) and proceeded to

launder approximately 472 ETH, equivalent to around $900,000, using the Tornado Cash platform.

In a peculiar turn of events, the hacker voluntarily surrendered control of the compromised system after

reaching out to the Tornado Cash community.

CoinGecko data reveals that the incident had a significant impact on the price of the TORN token, causing

it to plummet from over $7 to $4.

Despite the setback, the TORN token has demonstrated resilience and is displaying indications of a recovery.

It has been gradually regaining momentum and is currently trading slightly above $4, although it is still experiencing a bearish trend.

Tornado Cash’s Infamous Reputation for Facilitating Illicit Transactions and Money Laundering

Tornado Cash’s unparalleled privacy features and near-untraceable anonymous crypto transactions make it an ideal choice for those seeking to engage in money laundering activities.

As a result, Tornado Cash gained notoriety as the preferred platform for cybercriminals and hackers seeking to launder their illicit funds.

The protocol has faced significant backlash as various criminals, including North Korean hackers, take advantage of its privacy features to transfer their stolen assets.

According to data from Dune Analytics, an estimated amount of over $8 billion has been laundered by criminals using Tornado Cash since 2019.

That demonstrates the significant number of illicit transactions that the platform has facilitated throughout its existence.

In August 2022, the US Treasury Department’s Office of Foreign Assets Control (OFAC) imposed sanctions

on Tornado Cash for its involvement in violating anti-money laundering laws and facilitating illegal transactions.

According to the US Treasury, Tornado Cash was instrumental in assisting the Lazarus Group, a North Korean hacking group, in processing more than $455 million in stolen funds from various heist attacks.

The Office of Foreign Assets Control (OFAC) also alleged that criminals have laundered more than $7

billion in digital assets using Tornado Cash since its inception in 2019.

Despite public sentiment and the sanction imposed by the US Treasury, the Tornado Cash protocol

continues to serve as a conduit for money laundering activities by criminals.

