Crypto Ecosystems • May 21, 2023, 5:05AM EDT
Quick Take
- A malicious proposal passed by the Tornado Cash DAO gave an attacker complete control over its governance system.
- The attacker has already drained locked votes from the system and sold many of them.
Stay updated on Pro Crypto Ecosystems news by locking ACS tokens with The Block.
Connect/Create Wallet You can unlock at any time.* No wallet? No problem. You can set one up for free. We recommend Torus for first-time users.*a 2% locking fee will be added at the time of locking. Learn more about Access Protocol
An attacker managed to get a malicious proposal passed by the Tornado Cash DAO, one that handed them complete control over its governance system.
Tornado Cash is the crypto mixing service that runs on Ethereum and was sanctioned by the U.S. Treasury. Its governance system controls upgrades to the protocol and is run by those holding the project’s native TORN tokens.
The governance system approved on May 20 an upgrade that was purportedly the same as a previous upgrade that had passed. Yet that wasn’t true as the attacker had added an extra function, according to a pseudonymous security researcher known as Samczsun on Twitter. Once the upgrade was passed, the attacker used this function to hand themselves an extra 1.2 million votes, giving them effective control over the entire governance system.
The attacker has already used this control to their advantage. Straight away, they withdrew 10,000 votes in the form of TORN tokens and sold them all for $25,600. Then they drained the remainder of the locked votes, Samczsun said.
In total, 483,000 TORN was taken from the vault, according to on-chain analyst EmberCN. They claimed 6,000 TORN was deposited on crypto exchange Bitrue, that 379,000 was sold on-chain for $680,000 of ether and just under 100,000 TORN remains under the attacker’s control.
Binance said it would stop deposits and withdrawals of TORN, according to Wu Blockchain, while Justin Sun said on Twitter that deposits and withdrawals of the token remain open on Huobi.
Samczsun noted that with the control over the governance system, the attacker can drain all of the tokens in the governance contract and effectively stop the router from working, a core part of how the protocol operates. On the flip side, the reseacher noted that the attacker isn’t able to drain the funds that are held within the protocol — such as ether that’s being used for mixing — except for one pool on Gnosis Chain, which is upgradeable.
The price of TORN fell from a high of $7.3 yesterday to as low as $3.75 today. It has since rebounded to $4.60.