A researcher says hackers took over crypto mixer Tornado Cash on May 20 using a malicious governance proposal to give themselves fake votes to gain full control
Tornado Cash, a service that allows users to mask cryptocurrency transactions, suffered a hostile takeover by hackers through a malicious governance proposal.
Earlier coverage highlighted how decentralization can leave authorities without a clear operating target. A governance compromise tests the other side of that model: whether token-based control can be secured when no conventional operator is in charge.
First-order effects
The attackers allegedly obtain control of Tornado Cash’s governance process by manufacturing voting power, putting protocol decisions under their direction.
Users and other participants face immediate uncertainty over the integrity of governance actions and any changes made under the compromised control.
Second-order effects
Other token-governed crypto projects have a concrete reason to scrutinize proposal execution, voting-power validation, and emergency controls rather than treating on-chain voting as inherently secure.
The compromise compounds the credibility challenge created by the earlier US sanctions, giving users, infrastructure providers, and compliance teams another reason to reassess exposure to the service.
Third-order effects
If comparable exploits recur, decentralized governance will be judged not only on its resistance to censorship but also on whether its control mechanisms can withstand capture.
The case reinforces a wider tension in crypto: systems designed to minimize centralized operators can reduce clear accountability when governance or security fails.
The trend: This is one data point in the crypto legitimacy gap, where decentralized services must demonstrate both operational security and credible accountability under regulatory pressure.
#PeckShieldAler #rugpull @Swaprum on #Arbitrum rugged ~$3M, $SAPR has dropped -100%. @Swaprum already deleted its social accounts/groups. The scammers have bridged ~1,628 $ETH to #Ethereum and laundered 1,620 $ETH to Tornado Cash https://etherscan.io/... https://twitter.com/... …
On 2023/05/20 at 07:25:11 UTC, Tornado Cash governance effectively ceased to exist. Through a malicious proposal, an attacker granted themselves 1,200,000 votes. As this is more than the ~700,000 legitimate votes, they now have full control. https://openchain.xyz/... [image]
First, what does this mean for Tornado Cash? Through governance control, the attacker can: - withdraw all of the locked votes - drain all of the tokens in the governance contract - brick the router However, the attacker still can't: - drain individual pools
Correction: @CellierLael correctly pointed out that Tornado Cash Nova, deployed to Gnosis Chain, is a proxy that is administered by governance. Therefore, the attacker is also able to drain all of the ETH in that pool by upgrading the contract https://gnosisscan.io/... https://tw…
Now that they have all the votes, they can do whatever they want. In this case, they simply withdrew 10,000 votes as TORN and sold it all https://openchain.xyz/... [image]
This looks like the end of tornado cash. It's a governance attack. Seems like the token holders passed a malicious governance proposal that put the attacker in charge. Nation states couldn't shut it down, but some degen after 10k TORN could. C'est la vie. https://twitter.com/...
1/ The key to the success of the Tornado Cash DAO attack is that 1) blindly vote — vote without knowing the consequence; 2) a proposal contract can be updated through a well-designed trick — create and create2. Click to see the detailed attack steps: https://docs.google.com/... […
#PeckshieldAlert Tornado Cash Governance Exploiter has deposited 6K $TORN to #Bitrue. And swapped ~380K $TORN for $ETH and then transferred 372 $ETH into Tornado Cash https://etherscan.io/... [image]