CryptoPotato
CryptoPotato
  • Crypto News
  • Margin Trading
  • Guides
    • Bitcoin & Crypto Guides 101
    • Bitcoin For Beginners
    • Editorials
  • DeFi & NFT
  • Buy
  • Language
    • Spanish
    • Turkish
    • German
    • Bulgarian
  • Crypto News
  • Bitcoin For Beginners
  • Cryptocurrency Guides 101
  • Editorials
  • Bitcoin & Crypto Margin Trading
  • DeFi & NFT News
  • Bitcoin Price Analysis
  • Ethereum (ETH) Price Analysis
  • Ripple (XRP) Price Analysis
  • Market Updates
  • Interviews
  • Buy Bitcoin with Card
  • CryptoPotato Spanish
  • CryptoPotato Turkey
  • CryptoPotato Germany
  • CryptoPotato Bulgaria
  • Market Updates
  • BTC Analysis
  • ETH Analysis
  • XRP Analysis
  • Interviews
CryptoPotato
CryptoPotato
  • Crypto News
  • Margin Trading
  • Guides
    • Bitcoin & Crypto Guides 101
    • Bitcoin For Beginners
    • Editorials
  • DeFi & NFT
  • Buy
  • Language
    • Spanish
    • Turkish
    • German
    • Bulgarian
  • Crypto News
  • Bitcoin For Beginners
  • Cryptocurrency Guides 101
  • Editorials
  • Bitcoin & Crypto Margin Trading
  • DeFi & NFT News
  • Bitcoin Price Analysis
  • Ethereum (ETH) Price Analysis
  • Ripple (XRP) Price Analysis
  • Market Updates
  • Interviews
  • Buy Bitcoin with Card
  • CryptoPotato Spanish
  • CryptoPotato Turkey
  • CryptoPotato Germany
  • CryptoPotato Bulgaria
Home » Crypto News » Tornado Cash Attacker Submits Proposal to Revert Governance Control, TORN Down 40% in 2 Days

Tornado Cash Attacker Submits Proposal to Revert Governance Control, TORN Down 40% in 2 Days

Author: Mandy Williams

Last Updated May 22, 2023 @ 06:37

The attacker had complete control over the mixer’s governance, but the new proposal could change everything.

Getting your audio player ready...

Popular crypto mixer Tornado Cash lost total control of its governance to an attacker who deployed a malicious contract to access thousands of votes. The incident was first detected by @samczsun, a researcher at web3-focused investment firm Paradigm, over the weekend.

According to samczsun’s tweet, the attacker claimed to have used the same logic as a proposal passed earlier in creating their malicious proposal without disclosing that they added an extra function.

In a more recent development, though, the attacker “posted a new proposal to restore the state of governance,” according to a post on the mixer’s community forum.

TornadoCash attacker deployed new proposal that, if executed, would seemingly revert the damage done to the Governance functionality. Either they’re giga trolling or it will end up being an expensive but not disastrous lesson in Governance security.https://t.co/QMWYFsi8kP

— 0xdeadf4ce (@0xdface) May 21, 2023

Attacker Seizes Tornado Cash Governance

Immediately after Tornado Cash voters passed the proposal, the exploiter implemented the emergencyStop function and updated the proposal logic to grant themselves 1.2 million fake votes. The attacker’s votes are more than 700,000 legitimate ones, so they have gained full control of the crypto mixer’s governance.

With complete control, the attacker can do whatever they want, like withdrawing all the locked votes, draining all tokens in the governance contract, and bricking the router. However, they cannot drain individual pools.

“Finally, what can we learn from this? Be careful what you vote for! While we all know that proposal descriptions can lie, proposal logic can lie too! If you’re depending on the verified source code to stay the same, make sure the contract doesn’t have the ability to self-destruct,” samczsun warned.

Over $2.1M TORN Tokens Stolen

Shortly after taking hold of Tornado Cash’s contract, the exploiter drained 473,000 TORN – the mixer’s native token – worth more than $2.1 million from the governance contract, according to a tweet from Web3 media group @WhaleCoinTalk. The bad actor sold the assets on-chain and deposited the profits back into Tornado.

Tornadosaurus-Hex, an active member of the Tornado Cash community, confirmed that the attack had compromised all funds in governance and asked all members to withdraw their assets locked in the contract.

While urging users to extract their funds, Tornadosaurus-Hex has also tried to deploy a contract that could revert the changes.

“A proposed solution for the attack which possibly might be viable is reverting the state changes that the attacker made to the contract, directly. As such, I’ve deployed a contract that should be able to do exactly this… Please check it out and if possible propose. Let’s see if we can get it through, otherwise we’re fucked I would say,” the community member said.

Somewhat expectedly, the project’s native token plummeted after the news surfaced. TORN jumped to $7.3 on May 20 but has lost roughly 40% of its value in the following days and now sits at $4.5.

SPECIAL OFFER (Sponsored)
Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Tags: Tornado Cash
Enjoy reading? Share with your friends
Facebook Twitter LinkedIn Telegram

About The Author

Mandy Williams
More posts by this author

Mandy Williams is a full-time reporter at CryptoPotato. She joined the cryptocurrency space in early 2017 during her search for financial freedom and has remained devoted to the industry.
Contact Mandy: Twitter

Join Our Community

FacebookX YouTubeTelegram


Editorials
5 Best Meme Coin Presales to Watch in May 2025

5 Best Meme Coin Presales to Watch in May 2025

Toobit Review 2025: Is Toobit a Safe Crypto Exchange?

Toobit Review 2025: Is Toobit a Safe Crypto Exchange?

Hyperliquid Bridge: How to Bridge USDC to Hyperliquid

Hyperliquid Bridge: How to Bridge USDC to Hyperliquid

11 Best Crypto Presales to Consider in May 2025

11 Best Crypto Presales to Consider in May 2025

Need for Speed – Only Ultra-Fast Blockchains Will Win the Adoption Race (Opinion)

Need for Speed – Only Ultra-Fast Blockchains Will Win the Adoption Race (Opinion)

The 5 Best Bitcoin Mining Pools in 2025: Complete Guide

The 5 Best Bitcoin Mining Pools in 2025: Complete Guide

The 5 Best Crypto Staking Platforms in 2025: Everything You Need to Know

The 5 Best Crypto Staking Platforms in 2025: Everything You Need to Know

Join Our Newsletter
Become a CryptoPotato VIP
One Weekly Email Can Change Your Crypto Life.
Sign-up FREE to receive our extended weekly market update and coin analysis report
We NEVER send spam. You can unsubscribe at any time.
Invalid email address
Thanks for subscribing!
Footer Logo
About
Advertise on CryptoPotato
About Us | Contact Us | Careers
Editorial Policy
Terms of service | Privacy Policy | GDPR
More Sections
IEO List | Evaluations
Airdrops
Scholarship
Disclaimer
Disclaimer: Information found on CryptoPotato is those of writers quoted. It does not represent the opinions of CryptoPotato on whether to buy, sell, or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk. Full disclaimer
© Copyright CryptoPotato 2016 - 2025
Scroll to top
One Daily Email Can Change Your Crypto Life.

Sign-up FREE to receive our extended daily market update and coin analysis report

We never send SPAM. You can unsubscribe at any moment
Invalid email address
Thanks for subscribing!