Share this article

Tornado Cash DAO Attacker Starts to Move Ether, TORN Tokens

The attacker holds over 20 ether in their wallet, and continues to have access to potentially all of Tornado Cash’s treasury funds as of Thursday.

Updated May 25, 2023, 7:05 a.m. Published May 25, 2023, 7:05 a.m.
A illustrative example of a Tornado. (NOAA)
A illustrative example of a Tornado. (NOAA)

The attacker behind a takeover of Tornado Cash DAO has apparently started to move their illicitly gained tokens, blockchain data shows.

Addresses tied to the attacker moved 100 ether and 38,000 torn (TORN) tokens in two transactions using the Tornado Cash protocol on Wednesday night, Etherscan data shows.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters

The DAO handling the privacy-focused crypto mixer's operations, funds and future plans was taken over by an unidentified attacker, or attackers, on Saturday.

The attacker holds over 20 ether ($35,684) in their wallet, and continues to have access to potentially all of Tornado Cash’s treasury funds.

The attacker floated a malicious proposal that hid a code function that granted them fake votes that can now be used to handle some aspects of Tornado Cash, such as torn tokens held in the main governance contract or withdrawal of locked torn tokens.

DAOs, short for decentralized autonomous organizations, allow token holders to lock up their holdings as votes for proposing changes to a project. These changes can range from deploying treasury funds to purposes that benefit the project to expansion on other networks.

The attack does not impact the actual Tornado Cash protocol – which allows users to pass funds through the service to mask or obscure the movements of funds and crypto addresses. This attack was not an exploit of any smart contracts or technology related to the working of Tornado Cash.

As such, there’s still hope for Tornado Cash.

The attacker floated a proposal to revert all malicious changes before the takeover earlier this week – sending torn prices up 10% at the time.

The proposal looks as though it will pass when voting closes on May 26, though it's unclear when the action will be executed. However, if it does, the malicious code will be removed and the governance of Tornado Cash's DAO will go back to token holders.

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

El Salvador Partners with Elon Musk’s Grok in AI-Powered Education for 1M Students

The National Palace in San Salvador, El Salvador.

The nation that first adopted bitcoin as legal tender is looking to pioneer AI-powered education in 5,000 Salvadoran schools with xAI’s Grok

What to know:

  • El Salvador is partnering with Elon Musk's xAI to launch the world's first national AI-powered public education system.
  • The initiative will deploy xAI's Grok chatbot to over 5,000 public schools, benefiting more than a million students and thousands of teachers.
  • The project aims to create new AI datasets and frameworks for education, focusing on local context and responsible AI use.