Disclaimer: Information found on CryptoreNews is those of writers quoted. It does not represent the opinions of CryptoreNews on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoreNews covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.
Tornado Cash Hacker Submitted New Plan to Reestablish Governance Authority
- The attacker appropriated 473,000 TORN, the native token of the mixer, valued at over $2.1 million.
- With over 700,000 votes, the assailant has gained total control of the administration.
An assailant exploited a fraudulent contract to gain access to thousands of votes, thereby seizing full control of the well-known cryptocurrency mixer Tornado Cash. Paradigm’s web3 research analyst @samczsun was the first to identify the issue over the weekend.
In a tweet from user samczsun, it was noted that the attacker asserted their malicious proposal was based on the same rationale as a previous proposal, without acknowledging the inclusion of an additional function. Recently, however, the attacker “posted a new proposal to restore the state of governance,” as detailed in a thread on the mixer’s community forum.
Complete Control of Administration
Once the request received approval from Tornado Cash users, the exploiter activated the emergency-stop mechanism and altered the proposal logic to grant themselves 1.2 million counterfeit votes. With over 700,000 legitimate votes, the attacker has assumed total control of the crypto mixer’s administration.
The assailant is now empowered to execute any actions they desire, including removing all locked votes, draining all governance contract tokens, and even disabling the router. However, they cannot empty specific pools.
A tweet from Web3 media collective @WhaleCoinTalk indicates that shortly after taking control of Tornado Cash’s contract, the exploiter misappropriated 473,000 TORN, the mixer’s native token, worth over $2.1 million from the governance contract. The malicious actor profited from the asset sales and reinvested funds into Tornado.
A community member known as Tornadosaurus-Hex stated that the attack has jeopardized all funds under governance and urged all members to withdraw their assets from the contract.
Recommended For You:
Hacker Takes Over Governance Control of Crypto Mixer Tornado Cash