Cointime

Download App
iOS & Android

Who Will Be the Next Target After Tornado Cash Governance Attack?

On May 20, 2023, Tornado Cash fell victim to a governance attack, resulting in a loss of approximately $1 million. The attacker initiated the attack by submitting a malicious proposal with a misleading description, which was later approved by the voters. Once the malicious proposal was executed, the attacker gained control over the governance of Tornado Cash.

Let's analyze how this attack unfolded and examine the underlying reasons behind it.

By examining the transaction records, we can trace the details of the attack. The attacker used two addresses: Attacker A (https://etherscan.io/address/0x092123663804f8801b9b086b03b98d706f77bd59) and Attacker B (https://etherscan.io/address/0x592340957ebc9e4afb0e9af221d06fdddf789de9).

The transaction details can be found here: https://etherscan.io/tx/0x65fa5b475f34a954a10f88f2c84f316a048a0e67d273c7abb098717b1a4a46a3.

The code for the malicious proposal is stored at the following address: https://etherscan.io/address/0xc503893b3e3c0c6b909222b45f2a3a259a52752d#code.

The contract that was attacked is TornadoVault (https://etherscan.io/address/0x2f50508a8a3d323b91336fa3ea6ae50e55f32185#code).

The attack unfolded as follows:

1. Attacker B created the malicious proposal at address 0xc503893b3e3c0c6b909222b45f2a3a259a52752d

2. Attacker B submitted a deceptive proposal labeled as #20.

3. Attacker A manipulated multiple accounts to lock 0 TORN tokens.

4. Deceived users voted for proposal #20.

5. After reaching the required number of votes, the attacker launched the attack:

  • The old proposal was destroyed. Attacker B invoked the emergencyStop function, destroying the old proposal at address 0xC50389 (https://etherscan.io/tx/0xd3a570af795405e141988c48527a595434665089117473bc0389e83091391adb
  • The proposal contract was updated. Attacker B created a new proposal contract at the same address 0xC50389 (https://etherscan.io/tx/0xa7d20ccdbc2365578a106093e82cc9f6ec5d03043bb6a00114c0ad5d03620122
  • Proof of Concept: A test file (https://github.com/MetaTrustLabs/SmartContractAttackPoC/blob/main/test/TornadoCash) was created to simulate the attacker's steps, including the creation and destruction of malicious contracts and the creation of new contracts at the same address.

6. Token transfers

  • Attacker B transferred tokens to Tornado.Cash: Governance Staking.
  • Attacker A transferred tokens to the attacker-controlled account.

Eventually, Attacker A obtained tokens worth $1 million through this attack.

The root causes of this governance attack can be attributed to two factors: the approval of a malicious proposal and the destruction and recreation of the proposal contract by the attacker.

Firstly, the attacker lured voters into making a misjudgment by creating a malicious proposal, leading them to approve it without fully understanding its potential risks. This deceptive description may have concealed the true intentions of the attack and misled voters into believing that the proposal was beneficial or harmless.

Secondly, the attacker took measures to destroy the original proposal contract and recreate it at the same address. By invoking the emergencyStop function, the attacker successfully disrupted the logic of the original proposal, causing its execution results to deviate from expectations. This action provided the attacker with an opportunity to seize control of the governance and laid the foundation for subsequent attacks.

The combination of these two factors enabled the attacker to successfully carry out the governance attack and take control of Tornado Cash. The approval of the malicious proposal and the destruction and recreation of the proposal contract paved the way for the attacker to utilize the controlled governance for further operations.

This attack highlights the importance of security and risk management in decentralized governance processes. Developers and communities should strengthen the review of proposals to ensure accurate and transparent descriptions, as well as enhance the security audit of contracts to prevent attackers from exploiting vulnerabilities and engaging in malicious activities. Additionally, users and voters need to carefully evaluate proposal content and ensure they understand the potential risks and consequences.

For projects like Tornado Cash and similar ones, this governance attack should be considered a lesson to strengthen their governance processes and security mechanisms, thereby improving the overall system's security and resilience against risks. Only through continuous security audits, risk assessments, and increased community participation and awareness can we establish a safer and more reliable blockchain ecosystem.

About Us

At MetaTrust, our primary focus is on creating a secure infrastructure that caters to the needs of developers in the WEB 3.0 space. We offer an array of AI-Driven automation tools and security services to assist Web3 developers and project stakeholders in achieving a secure development environment.

Website | Twitter | Telegram | Try MetaScan for FREE

Comments

All Comments

Recommended for you

  • AI Big Model Empowers Cryptocurrency Market, BitradeX Leads Industry Transformation with Forward looking Layout

    The latest industry analysis from BitradeX points out that the explosion of AI big model technology is bringing revolutionary changes to the 24/7 uninterrupted operation of the cryptocurrency market. The all-weather trading characteristics and high market volatility provide unique advantages for AI enabled quantitative trading. BitradeX has been the first to launch an AI Bot product by deeply integrating cutting-edge big model technology with high concurrency quantization systems, achieving millisecond level market analysis and intelligent decision-making. The platform believes that the combination of AI and encryption will reshape the industry landscape, and in the future, the competition core of exchanges will shift from simple trading to intelligent investment services. BitradeX has taken the lead in laying out and leading this wave of change. Official website address: bitradex.com

  • DWF Labs Partners: Hold USD1 to get Falcon Finance closed beta test qualification

    On April 12th, DWF Labs managing partner Andrei Grachev posted on social media that as long as users have the stablecoin USD1 in their on-chain wallet, they can directly access the closed beta testing of the stablecoin protocol Falcon Finance and enjoy its profits earlier than others. Falcon Finance is a synthetic USD stablecoin protocol launched by DWF Labs. Today, DWF Labs has started adding USD1 liquidity on-chain.

  • DWF Labs has deployed USD1 liquidity on ETH and BSC, and USD1 will be officially launched

    according to @EmberCN monitoring, DWF Labs has begun deploying the USD1 liquidity of the DeFi project WLFI supported by the Trump family on the chain, marking that the stablecoin now supports on-chain circulation and trading. Data shows that in the past 8 days, the DWF Labs address has received 11 million USD1 tokens from WLFI on both the Ethereum and BSC chains.

  • 🚀NEXUS 2140 KOREA

    🌍AI· WEB3· ECOMGLOBAL EXPO📍 Goyang, South Korea📅 2025.6.21-22✅ Convergence of 🌟 top-level resources🇰🇷 Supported by the Korean government | 🤝 500 Global Enterprises 🌐 | 150 Investment Institutions 💰 | 3000 KOL 📢✅ Frontier field coverage 🚀AI 🤖 | Web3 🌐 | ECOM's 🛒 three tracks, detonating future business opportunities! 💥✅ High-spec exposure 📡100M media traffic 🎥 | 30K Social Buzz 💬 | The world's top media cooperation 🌎✅ Celebrity event blessing 🎉Summit Forum 💼 | Project Roadshow 🏆 | 15,000 people concert 🎤🌟 | Community dinner 🥂 for 1,000 peopleStrong support from the government, international recognition and praiseConvergence of cutting-edge fields|Industry elites gathered———————————————🚀 Infinite innovation, unlimited 🔥 business opportunities

  • CointimeSG ·

    Nexus 2140: Exploring the Convergence of AI, Web3 & ECOM for Future Opportunities

    The highly anticipated Nexus 2140: AI · Web3 · ECOM Global Expo will take place on June 21-22, 2025, at the KINTEX Convention Center in Goyang, South Korea.

  • EU Trade Commissioner proposes zero-to-zero tariffs on goods to US

    European Commission Trade Commissioner Dombrovskis: We propose zero tariffs on goods to the United States, and if no trade agreement is reached, we are also prepared to respond. If necessary, we are prepared to take retaliatory measures.

  • BTC breaks through $82,000

    market shows BTC breaking through $82,000, now reported at $82,025.05, with a 24-hour increase of 0.19%. The market fluctuates greatly, please be prepared for risk control.

  • The State Council Tariff Commission: Adjustment of tariffs on imported goods originating from the United States

    on April 10, 2025, the U.S. government announced that the tariff rate for Chinese goods imported into the U.S. will be further increased to 125%. The U.S. imposing excessively high tariffs on China seriously violates international economic and trade rules, as well as basic economic laws and common sense, and is completely unilateral bullying and coercion. In accordance with the "Customs Law of the People's Republic of China," the "Customs Law of the People's Republic of China," the "Foreign Trade Law of the People's Republic of China," and other laws and regulations, as well as basic principles of international law, with the approval of the State Council, the measures of imposing tariffs on imported goods originating in the U.S. will be adjusted starting from April 12, 2025. The relevant matters are as follows:

  • Plastic Labs Completes $5.35 Million Pre-Seed Funding and Launches AI Identity Platform Honcho

    Plastic Labs has completed a $5.35 million Pre-Seed round of financing, led by Variant, White Star Capital, and Betaworks, with participation from Mozilla Ventures, Seed Club Ventures, Greycroft, and Differential Ventures. Angel investors include Scott Moore, NiMA Asghari, and Thomas Howell. At the same time, its personalized AI identity platform "Honcho" is now open for early access.

  • Trump: There will be problems during the transition, but it will ultimately be an incredible thing

    President Trump of the United States: There will be problems in the transition phase, but in the end it will be an incredible thing.