Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
No Result
View All Result

Attacker hijacks Tornado Cash governance via malicious proposal

CryptoExpert by CryptoExpert
May 21, 2023
in Blockchain News
0
Attacker hijacks Tornado Cash governance via malicious proposal
  • Facebook
  • Twitter
  • Pinterest


You might also like

AAVE Price Prediction: $85 Breakdown Before Explosive Rally to $110+ by June

AAVE Price Prediction: $105 Target Within 48 Hours as Smart Money Accumulates

Dunamu, Hana Financial Take Blockchain Remittance System Live With POSCO

Adding to the existing roadblocks of the decentralized crypto mixer Tornado Cash, an attacker managed to gain full control of the governance through a malicious proposal. 

On May 20 at 3:25 ET, an attacker successfully granted 1.2 million votes to a malicious proposal. Given that the proposal received more than 700,000 legitimate votes, the attacker gained total control over Tornado Cash governance.

On 2023/05/20 at 07:25:11 UTC, Tornado Cash governance effectively ceased to exist. Through a malicious proposal, an attacker granted themselves 1,200,000 votes. As this is more than the ~700,000 legitimate votes, they now have full control.https://t.co/nY87XmrYgT pic.twitter.com/h9qjc3xRqz

— @samczsun.com (@samczsun) May 20, 2023

The information was shared by @samczsun of research-driven technology investment firm Paradigm, who revealed that, when sharing the malicious proposal, the attacker claimed that it used a logic similar to a proposal that had previously passed by the community. However, this time, the proposal had an additional function. 

Phemex

As explained by @samczsun:

“Once the proposal was passed by voters, the attacker simply used the emergencyStop function to update the proposal logic to grant themselves the fake votes.”

The total control over Tornado Cash governance allows the attacker to withdraw all of the locked votes, drain all of the tokens in the governance contract and brick the router. At the time of writing, the attacker “simply withdrew 10,000 votes as TORN and sold it all,” said @samczsun.

The attack comes as a reminder to crypto investors to vet proposal descriptions and logic. An active community of Tornado Cash, who goes by the name Tornadosaurus-Hex or Mr. Tornadosaurus Hex, confirmed that all funds in Governance are potentially compromised and requested all members to withdraw all funds locked in governance.

As shown above, they also attempted deploying a contract that could potentially revert the changes while still suggesting the community to withdraw their funds. Cointelegraph also came across a distress call from one of Tornado Cash’s community developer who confirmed the above developments, stating:

“There was an attack on the protocol this morning that you already know about. All day, another community developer and I thought about what to do, but the situation is close to hopeless – currently the attacker controls Governance.”

The team is currently in search of Solidity developers that can help save the protocol from extinction. They additionally stated that “we need contact with Binance – this exchange has more tokens than the attacker.”

Related: Allbridge offers bounty to exploiter who stole $573K in flash loan attack

A former Tornado Cash developer is reportedly working on building a new crypto mixing service from scratch, which addresses the “critical flaw” existing in Tornado Cash.

1/ We fixed @tornadocash 😇

v0 of https://t.co/Nt4b2Tgx1D is live on @optimismFND

test out the demo, but please note:- this is experimental code- it has not been audited- the trusted setup is untrusted

read the full story anon 🧵👇https://t.co/9nAU3RrgpN

— Ameen Soleimani (@ameensol) March 4, 2023





Source link

  • Facebook
  • Twitter
  • Pinterest
CryptoExpert

CryptoExpert

Recommended For You

AAVE Price Prediction: $85 Breakdown Before Explosive Rally to $110+ by June

by CryptoExpert
May 1, 2026
0
AAVE Price Prediction: Recovery to $226-246 Target by December 2025 Despite Current Weakness

Terrill Dicki Apr 30, 2026 08:43 AAVE's technical collapse through critical support levels points to an imminent drop to $85-87, but massive whale accumulation...

Read more

AAVE Price Prediction: $105 Target Within 48 Hours as Smart Money Accumulates

by CryptoExpert
April 30, 2026
0
AAVE Price Prediction: Recovery to $226-246 Target by December 2025 Despite Current Weakness

James Ding Apr 29, 2026 08:46 AAVE's technical neutrality masks aggressive whale positioning with 57.6% long bias and buying pressure dominance. The $100.26 resistance...

Read more

Dunamu, Hana Financial Take Blockchain Remittance System Live With POSCO

by CryptoExpert
April 30, 2026
0
Cointelegraph

South Korea's Hana Financial Group, POSCO International and Dunamu, the operator of the crypto exchange Upbit, have signed a trilateral memorandum of understanding (MoU) to launch their blockchain-based...

Read more

DeFi Exploits Push Builders to Rethink Emergency Controls

by CryptoExpert
April 30, 2026
0
Cointelegraph

Andre Cronje says much of decentralized finance is “no longer DeFi” in the strict sense, as builders debate whether circuit breakers and other emergency controls are now necessary...

Read more

Startale Group Embeds Privacy Boost, Enables Sub-500ms Shielded Asset Transfers

by CryptoExpert
April 29, 2026
0
Startale Group Embeds Privacy Boost, Enables Sub-500ms Shielded Asset Transfers

Key Takeaways: Startale Group chooses Sunnyside Labs to bring native privacy to its consumer-facing app. Privacy Boost delivers 1,800+ transactions per second on Soneium to solve blockchain transparency...

Read more
Next Post
Pudgy Penguins Smash Amazon Debut, Sells Over 20,000 Toys

Pudgy Penguins Smash Amazon Debut, Sells Over 20,000 Toys

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

Sitemap

  • Market Cap
  • Donations
  • Trading
  • Mining
  • Contact

Legal Information

  • Privacy Policy
  • Anti-Spam Policy
  • Copyright Notice
  • DMCA Compliance
  • Social Media Disclaimer
  • Terms Of Service

Categories

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

© Copyright 2024 InvestInCryptoNews.com

No Result
View All Result
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO

© Copyright 2024 InvestInCryptoNews.com

This website is using cookies to improve the user-friendliness. You agree by using the website further.

Privacy policy
bitcoin
Bitcoin (BTC) $ 77,121.00
ethereum
Ethereum (ETH) $ 2,283.67
tether
Tether (USDT) $ 0.999556
xrp
XRP (XRP) $ 1.38
bnb
BNB (BNB) $ 617.58
usd-coin
USDC (USDC) $ 0.999676
solana
Solana (SOL) $ 84.05
tron
TRON (TRX) $ 0.326038
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03
staked-ether
Lido Staked Ether (STETH) $ 2,265.05

Pin It on Pinterest

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?