Tornado Cash suffers governance hijack

TL;DR Breakdown

  • Tornado Cash encountered a slight setback after its governance was hijacked by an attack.
  • The platform is seeking measures to salvage the situation.

In a concerning development, Tornado Cash, a decentralized crypto mixer, has encountered a significant setback as an attacker managed to seize full control of the platform’s governance through a malicious proposal. The incident unfolded on May 20 at 3:25 ET when the attacker granted themselves 1.2 million votes, effectively taking over Tornado Cash’s governance system. This exploit occurred despite the proposal receiving over 700,000 legitimate votes, allowing the attacker to manipulate the platform at will.

The attacker designed a malicious program to attack Tornado Cash

The details of the attack were shared by @samczsun, a member of Paradigm, a research-driven technology investment firm. According to @samczsun, the attacker cunningly designed the malicious proposal to resemble a previously successful one, exploiting the trust and familiarity of the community. However, this time, the proposal included an additional function.

Once the proposal gained sufficient votes, the attacker swiftly executed the emergency stop function, modifying the proposal logic to grant themselves the fraudulent votes. With complete control over Tornado Cash’s governance, the attacker proceeded to withdraw 10,000 votes as TORN and subsequently sold them for personal gain.

This incident serves as a stark reminder to crypto investors about the importance of scrutinizing proposal descriptions and logic before casting their votes. In response to the attack, Tornado Cash’s active community member known as Tornadosaurus-Hex or Mr. Tornadosaurus Hex confirmed that all funds within the Governance system are potentially compromised. They urged all members to withdraw their locked funds from governance to safeguard their assets.

In an effort to address the situation, the community attempted to deploy a contract to revert the changes and advised members to withdraw their funds. Meanwhile, a distressed call for help was issued by a community developer, confirming the attack and stating that the situation currently remains dire, with the attacker controlling the Governance system.

The platform is looking for ways to salvage the situation

The Tornado Cash team is actively seeking Solidity developers who can assist in salvaging the protocol from this critical situation. Additionally, they are seeking to establish contact with Binance, as the exchange holds more tokens than the attacker, potentially providing a path for mitigating the damage.

Meanwhile, a former Tornado Cash developer is reportedly working on creating a new crypto mixing service from scratch. This new solution aims to address the “critical flaw” present in Tornado Cash while empowering the community to protect against hackers without resorting to excessive regulation or compromising the core principles of cryptocurrencies.

As Tornado Cash faces the aftermath of this attack, the crypto community is reminded of the ongoing challenges and vulnerabilities present in the decentralized ecosystem. Efforts to enhance security measures and community involvement are essential to safeguarding the integrity and trustworthiness of these platforms in the future.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Tornado Cash suffers governance hijack

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年5月22日 20:06
Next 2023年5月22日 21:38

Related articles

  • Uniswap founder’s Twitter account breached to carry out scams

    TL;DR Breakdown The crypto community has been alerted to a potential scam being carried out on Uniswap founder’s account. Fighting scams in the rapidly evolving Web3 space. Description In a recent incident, members of the Crypto Twitter community swiftly identified and alerted others to a scam perpetrated through Uniswap founder Hayden Adams’ compromised account. The “Web3 Security Alerts” channel on Telegram was quick to notify followers about the breach, which occurred on July 20. During the breach, Adams’ Twitter account, with over 254,000 … Read more In a recent incident, members of the Crypto Twitter community swiftly identified and alerted others to a scam perpetrated through Uniswap founder Hayden Adams’ compromised account. The “Web3 Security Alerts” channel on Telegram was quick to notify followers about the breach, which occurred on July 20. During the breach, Adams’ Twitter account, with over 254,000 followers, released a false tweet claiming that the platform’s Permit2 contract had fallen victim to an unknown exploit, putting users’ tokens at risk. The tweet included a malicious link, attempting to lure users into a scam. Uniswap founder’s Twitter…

    Article 2023年7月22日
  • Why is the crypto market up today? BTC at $30k

    TL;DR Breakdown The total crypto market cap sits at $1.18 trillion, a 4.07% increase in the last 24 hours, while Bitcoin dominance sits at 49.54 % and trades at $30.136. According to Coinglass, in the past 24 hours, 62,196 traders were liquidated. The total liquidations come in at $218.43 million. In the last eight hours, a substantial whale purchase of 3,43 trillion PEPE coins has occurred, indicating a possible increase in market interest. Description Today, both the total Crypto Market Cap (TOTALCAP ) and the price of Bitcoin (BTC ) moved above their respective corrective patterns and are nearing new yearly highs. The crypto market is up today as Bitcoin, Cardano, Ether, and numerous altcoins surged after multiple large institutions filed for Bitcoin ETFs in the United States, following … Read more Today, both the total Crypto Market Cap (TOTALCAP ) and the price of Bitcoin (BTC ) moved above their respective corrective patterns and are nearing new yearly highs. The crypto market is up today as Bitcoin, Cardano, Ether, and numerous altcoins surged after multiple large institutions filed for…

    Article 2023年6月24日
  • Cryptocurrency lender Celsius’s bankruptcy plan faces creditor pushback

    TL;DR Breakdown   Celsius has made progress in relaunching operations by submitting an amended bankruptcy plan. The Fahrenheit consortium has won the bidding for Celsius’ assets. Creditor pushback is expected, with concerns raised over potential violations of consumer lending laws. Unexpectedly, cryptocurrency lender Celsius has made a significant stride forward in its efforts to relaunch operations by submitting an amended bankruptcy plan. Several high-profile investors, including Arrington Capital and US Bitcoin Corp., formed the Fahrenheit consortium and ultimately won the bidding for Celsius’ assets, reflected in the proposed strategy. With this result, NovaWulf could not take control of the corporation and its $2 billion in assets. The bankruptcy plan, submitted to the New York bankruptcy court in the early hours of Thursday, now awaits approval. However, creditor pushback seems inevitable, as some are already raising concerns. David Adler, a representative of borrowers from the McCarter & English law firm, took to Twitter to express his opposition to the proposed treatment outlined in the plan. Under the Plan, the Debtors have elected to treat the Retail Borrow Claims through the Set…

    Article 2023年6月18日
  • DFintoch exit scam: investors robbed of millions in shocking cryptocurrency deception

    TL;DR Breakdown DFintoch, a high-yield investment program (HYIP), is suspected of orchestrating an exit scam. DFintoch had falsely claimed to be owned by Morgan Stanley, a renowned financial institution, to attract investors. The Singapore Government and Morgan Stanley had previously issued advisories cautioning against investing in DFintoch, highlighting its fraudulent nature. In a stunning turn of events, the team behind the high-yield investment program (HYIP) known as DFintoch is suspected of orchestrating an exit scam, leaving investors dismayed and questioning the project’s legitimacy. The alleged scam involved a disappearance of approximately $31.6 million USDT on the Binance Smart Chain (BSC) after funds were transferred to multiple addresses on Tron and Ethereum, ultimately rendering investors unable to withdraw their money. News of the potential scam began circulating when prominent cryptocurrency commentator ZachXBT took to Twitter to raise the alarm. The tweet suggested that DFintoch, which touted a daily return on investment (ROI) of 1%, had abruptly ceased operations and vanished with substantial investors’ funds. It appears the team behind the ponzi @DFintoch has likely exit scammed with 31.6m USDT on BSC…

    Article 2023年5月26日
  • Top crypto tweets of the day – August 31st

    Description Contents hide 1 Another angle to understanding how Bitcoin works 2 US Courts are crumbling the entire SEC narrative on crypto 3 Bitcoin is the most egalitarian thing ever 4 Binance launches the Ordinals Inscription Service 5 Worldcoin token price nosedives 6 The inflation rate in the US goes up again 7 Curve Finance launches … Read more Contents hide 1 Another angle to understanding how Bitcoin works 2 US Courts are crumbling the entire SEC narrative on crypto 3 Bitcoin is the most egalitarian thing ever 4 Binance launches the Ordinals Inscription Service 5 Worldcoin token price nosedives 6 The inflation rate in the US goes up again 7 Curve Finance launches on Base network 8 US court rules that Bitcoin and ETH commodities in Uniswap case 9 Bloomberg analysts raise their spot Bitcoin ETF approval odds to 75% in 2023 10 Binance to slowly winddown BUSD services 11 Cambridge revises down Bitcoin energy estimates 12 ETH is standing out amongst top caps as the asset traders are growing most impatient with 13 BTC sees the most significant…

    Article 2023年9月1日
TOP