Tornado Cash Reportedly Suffers Backend Exploit, User Deposits at Risk
The exploit has the function to steal deposit data and deposited funds.

- Tornado Cash deposits and deposit data is reportedly at risk.
- A proposal has been made to revert back to a previous version of the protocol's IPFS deployment.
User deposits on token mixer Tornado Cash are reportedly at risk following the insertion of malicious code in the protocol's back end, according to a Medium post by community member Gas404.
The post explains that a malicious javascript code was hidden from a two-month-old governance proposal submitted by an alleged Tornado Cash developer on Jan. 1. The code redirects deposit data to a public server hosted by the alleged developer.
The function of the exploit is to leak Tornado Cash deposit data and there is also a function to steal a deposit itself. According to Gas404, one deposit was stolen out of this batch seen on etherscan.
Tornado Cash trading volume nosedived by more than 90% after the U.S. Treasury Department’s Office of Foreign Asset Control (OFAC) sanctioned Tornado Cash in August 2022.
Gas404 has proposed that Tornado Cash should revert to a previous IPFS ContextHash deployment used in a previous version of TornadoCash.
More For You
Protocol Research: GoPlus Security

What to know:
- As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
- GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
- Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.
More For You
French Banking Giant BPCE to Roll Out Crypto Trading for 2M Retail Clients

The service will allow customers to buy and sell BTC, ETH, SOL, and USDC through a separate digital asset account managed by Hexarq.
What to know:
- French banking group BPCE will start offering crypto trading services to 2 million retail customers through its Banque Populaire and Caisse d’Épargne apps, with plans to expand to 12 million customers by 2026.
- The service will allow customers to buy and sell BTC, ETH, SOL, and USDC through a separate digital asset account managed by Hexarq, with a €2.99 monthly fee and 1.5% transaction commission.
- The move follows similar initiatives by other European banks, such as BBVA, Santander, and Raiffeisen Bank, which have already started offering crypto trading services to their customers.










