/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A researcher says hackers took over crypto mixer Tornado Cash on May 20 using a malicious governance proposal to give themselves fake votes to gain full control

Tornado Cash, a service that allows users to mask cryptocurrency transactions, suffered a hostile takeover by hackers through a malicious governance proposal.

Bloomberg Sidhartha Shukla

Context & Ripple Effects

Tornado Cash was already under intense pressure after the US Treasury sanctioned the mixer and related wallets, while Dutch authorities separately arrested a suspected developer. The episode adds an internal-control failure to a story previously dominated by enforcement.

Earlier coverage highlighted how decentralization can leave authorities without a clear operating target. A governance compromise tests the other side of that model: whether token-based control can be secured when no conventional operator is in charge.

First-order effects

  • The attackers allegedly obtain control of Tornado Cash’s governance process by manufacturing voting power, putting protocol decisions under their direction.
  • Users and other participants face immediate uncertainty over the integrity of governance actions and any changes made under the compromised control.

Second-order effects

  • Other token-governed crypto projects have a concrete reason to scrutinize proposal execution, voting-power validation, and emergency controls rather than treating on-chain voting as inherently secure.
  • The compromise compounds the credibility challenge created by the earlier US sanctions, giving users, infrastructure providers, and compliance teams another reason to reassess exposure to the service.

Third-order effects

  • If comparable exploits recur, decentralized governance will be judged not only on its resistance to censorship but also on whether its control mechanisms can withstand capture.
  • The case reinforces a wider tension in crypto: systems designed to minimize centralized operators can reduce clear accountability when governance or security fails.

The trend: This is one data point in the crypto legitimacy gap, where decentralized services must demonstrate both operational security and credible accountability under regulatory pressure.

Discussion

  • @peckshieldalert @peckshieldalert on x
    #PeckShieldAler #rugpull @Swaprum on #Arbitrum rugged ~$3M, $SAPR has dropped -100%. @Swaprum already deleted its social accounts/groups. The scammers have bridged ~1,628 $ETH to #Ethereum and laundered 1,620 $ETH to Tornado Cash https://etherscan.io/... https://twitter.com/... …
  • @samczsun @samczsun on x
    On 2023/05/20 at 07:25:11 UTC, Tornado Cash governance effectively ceased to exist. Through a malicious proposal, an attacker granted themselves 1,200,000 votes. As this is more than the ~700,000 legitimate votes, they now have full control. https://openchain.xyz/... [image]
  • @samczsun @samczsun on x
    First, what does this mean for Tornado Cash? Through governance control, the attacker can: - withdraw all of the locked votes - drain all of the tokens in the governance contract - brick the router However, the attacker still can't: - drain individual pools
  • @samczsun @samczsun on x
    Correction: @CellierLael correctly pointed out that Tornado Cash Nova, deployed to Gnosis Chain, is a proxy that is administered by governance. Therefore, the attacker is also able to drain all of the ETH in that pool by upgrading the contract https://gnosisscan.io/... https://tw…
  • @samczsun @samczsun on x
    Now that they have all the votes, they can do whatever they want. In this case, they simply withdrew 10,000 votes as TORN and sold it all https://openchain.xyz/... [image]
  • @drnicka @drnicka on x
    This looks like the end of tornado cash. It's a governance attack. Seems like the token holders passed a malicious governance proposal that put the attacker in charge. Nation states couldn't shut it down, but some degen after 10k TORN could. C'est la vie. https://twitter.com/...
  • @technology @technology on x
    Tornado Cash is a blockchain protocol that is governed by a network of computers https://www.bloomberg.com/...
  • @eowynchen @eowynchen on x
    Watch out for potential exploits through Tornado Cash governance #security 🚨 https://twitter.com/...
  • @blocksecteam @blocksecteam on x
    1/ The key to the success of the Tornado Cash DAO attack is that 1) blindly vote — vote without knowing the consequence; 2) a proposal contract can be updated through a well-designed trick — create and create2. Click to see the detailed attack steps: https://docs.google.com/... […
  • @alistairhaimes Alistair Haimes on x
    If all we had was crypto, and then somebody invented normal currency, it would be hailed as a massive step forward. https://twitter.com/...
  • @peckshieldalert @peckshieldalert on x
    #PeckshieldAlert Tornado Cash Governance Exploiter has deposited 6K $TORN to #Bitrue. And swapped ~380K $TORN for $ETH and then transferred 372 $ETH into Tornado Cash https://etherscan.io/... [image]
  • @apoorvlathey Apoorv Lathey on x
    Technical Deep Dive: How Tornado Cash governance exploiter was able to deploy a new malicious contract at the same address 🧵 (1/6) [image]