Tornado Cash website, discord offline after community finds malicious code in protocol's backend

cyptouser7 months agoCryptocurrencies News125

Crypto mixer Tornado Cash has reportedly fallen victim to a significant backend exploit that has put user deposits and sensitive data at risk.

The security breach was revealed in a Medium post by Gas404, a community member, on Feb. 26.

The exploit represents a critical vulnerability for Tornado Cash, whose trading volume already suffered a dramatic decline following sanctions from the US Treasury Department’s Office of Foreign Asset Control (OFAC) in August 2022.

The sanctions, which were part of broader measures targeting the crypto sector, had significantly reduced the mixer’s operational scale even before the exploit.

Malicious code

According to the Medium post, malicious JavaScript code was discovered in the protocol’s backend. It was reported injected through a compromised governance proposal submitted by an individual posing as a Tornado Cash developer on Jan. 1.

The code surreptitiously redirects user deposit information to a server controlled by the attacker, posing a dual threat — the exposure of deposit data and the outright theft of the deposits themselves.

One such theft has been confirmed through transaction records on Etherscan, highlighting the exploit’s immediate impact.

The exploit’s technical details were discussed at length in the community post, illustrating the sophisticated nature of the attack.

Specifically, the malicious code was designed to encode and exfiltrate private deposit notes, effectively breaching the anonymity and security that Tornado Cash users depend on.

Proposed solution

In response to the crisis, Gas404 has proposed a solution to mitigate the damage: reverting Tornado Cash to a prior version of its IPFS deployment.

The move aims to secure the platform against the current vulnerability by utilizing a previously established and ostensibly secure infrastructure setup.

The proposed change emphasizes the urgency of addressing security flaws within decentralized platforms, where governance proposals can be manipulated for malicious purposes.

The Tornado Cash website and Discord channel were taken offline following the revelation and have yet to come back online — an indication of the exploit’s severity and the ongoing efforts to contain its repercussions.

Mentioned in this article
Tornado Cash
The content on this website comes from the Internet. Due to the inconvenience of proofreading the authenticity and accuracy of the copyright or content of some content, it may be temporarily impossible to confirm the authenticity and accuracy of the copyright or content. For copyright issues or other issues caused by this, please Call or email this site. It will be deleted or changed immediately after verification.

related articles

Iggy Azalea's anti-scam plan: Burn her own coins

Iggy Azalea's anti-scam plan: Burn her own coins

55966e89˃Pop star and newly-minted crypto star Iggy Azalea announced she will burn her own coins whe...

Ethereum price soars on spot ETF rumor — How are ETH options markets positioned?

Ethereum price soars on spot ETF rumor — How are ETH options markets positioned?

55966e89˃On May 20, the price of Ether (ETH) surged over 18% after Eric Balchunas, a senior analyst...

SBF Trial Day 5 – How Caroline Ellison's testimony could become the smoking gun needed for a guilty verdict

The fifth day of the SBF trial included testimony from Alameda Research CEO Caroline Ellison, whose...

Bridging the gap: The Gensler controversy and the path to digital asset harmony

After severe boom and bust phases, how can we gauge the importance of blockchain-based assets? Will...

Blockchain education initiatives take off amid crypto bull market

Blockchain education initiatives take off amid crypto bull market

55966e89˃Amid an industry boom, crypto education initiatives are quickly gaining traction. On May 7,...

Telegram commits to TON blockchain, plans to support tokenized emojis and stickers NFTs

Telegram commits to TON blockchain, plans to support tokenized emojis and stickers NFTs

1205f261˃The Open Network's Pavel Durov committed the future of messaging application Telegram to bl...