All articles

Tornado Cash in 2026: status and phishing

Published: September 21, 2026

Also available in:Español

If tornado.cash is in your bookmarks, delete the bookmark, and do not follow the website link on Tornado Cash's GitHub page either. Someone else has held the domain since March 2025, and on 18 August 2026 a user who opened it from an old link entered deposit notes there and lost 1,010 ETH within hours. Tornado Cash itself is still working in 2026. Its contracts run on Ethereum, the US lifted its sanctions on 21 March 2025, and one of its developers faces a retrial in April 2027. This page sets out the status on one date, shows what we checked about the domain ourselves, and explains why pasting a note is all it takes to lose the money. We run notrace.exchange, a crypto mixer built the other way round, and one section below says how.

Timeline of the tornado.cash domain: put on hold after the US sanctions in August 2022, sanctions lifted on 21 March 2025, the name registered anew by someone else on 25 March 2025, 1,010 ETH lost through it on 18 August 2026, and on hold again from 18 September 2026

Is Tornado Cash still working?

Yes. Tornado Cash is a set of smart contracts on Ethereum, one pool for each fixed amount, and nobody can switch the pools off. The ETH pools in use today were deployed in December 2019. On 18 May 2020, after a trusted setup ceremony that collected 1,114 contributions, the developers set their operator address to zero, and their announcement two days later called the contracts "immutable and unstoppable". The court ruling that ended the sanctions turned on exactly that point.

Deposits fell after the sanctions but never stopped: one study found that the sanctions cut daily deposits by more than 80%. In June 2026 TRM Labs, a blockchain analytics firm, wrote that in 2026 Tornado Cash had "captured just over 20% of all mixer activity" and remained the largest mixer on Ethereum-based networks, with 10 to 80 million dollars coming in each week, after its share had recovered to more than 40% by the last quarter of 2025.

Not everything is immutable. The router, the governance contracts and Nova, the later pool for arbitrary amounts, can be changed by the DAO in which holders of the TORN token vote, and that matters in the attacks described further down.

What stopped working is the website people remember. Within hours of the sanctions on 8 August 2022 the site went offline, and GitHub suspended the developers' accounts. The DAO's own interface is published on IPFS under the ENS name tornadocash.eth, which its governance contract controls. The old domain passed to someone else, and that part of the story is still missing from the reference pages: Wikipedia, the first result after the domain itself in US search, points to an archived copy of the site from 8 August 2022 and mentions the domain only as taken down that month.

The tornado.cash domain no longer belongs to the project

This is what the registry of the .cash zone returned for tornado.cash through its public RDAP service on 21 September 2026:

  • Registration: 25 March 2025, 14:20 UTC. The domain as it exists today was created then, four days after the US Treasury took Tornado Cash off its sanctions list.
  • Transfer: 9 January 2026. The domain moved to another registrar.
  • Last change: 18 September 2026, with the statuses client hold, client transfer prohibited and client update prohibited. Client hold is set by the registrar and tells the registry to stop publishing the domain in DNS.
  • DNS: NXDOMAIN. The same day, Cloudflare's resolver answered that the name does not exist.

Archived WHOIS records show what came before. The project's own registration dated from 17 July 2019. On 10 August 2022, two days after the sanctions, the registrar put it on client hold, and it was due to expire on 17 July 2024. So the accounts that say the domain lapsed during the sanctions are right about the lapse. Why it was not renewed, nobody from the project has said on the record.

The name came back after the sanctions ended. An archived copy of tornado.cash from 28 March 2025 shows the holding page of Domain Recover, a service that catches expiring domains for its clients: "This domain name has recently been recovered for a client of Domain Recover." By 7 April the address served a page titled Tornado.cash again. In July 2025, in a thread on MetaMask's phishing blocklist, a GitHub user who said they owned the domain wrote that the security researcher samczsun had suggested handing it to the Ethereum Foundation and that they had declined; the site, they added, was identical to the interface the DAO had approved. The change that keeps tornado.cash on MetaMask's blocklist, submitted by samczsun, was merged the next day. In June 2026 another researcher reported in the same thread that the scripts behind app.tornado.cash copied users' notes and recovery keys into a global browser variable and passed them to a callback whenever one was present.

A hold is not an ending. The registrar can lift it as easily as it set it, and the registration itself runs until 25 March 2027. That is the practical reason to delete the bookmark now rather than wait for the name to die.

How 1,010 ETH was taken

On 20 August 2026 Wu Blockchain reported, "according to community users", that someone had clicked an old link left in a bookmark, landed on a phishing site at tornado.cash and lost 1,010 ETH, "drained by hackers within 12 hours". Messages attributed to the victim in the project's Telegram group, posted as a screenshot on X the same day, give a different entry point: "My entry point was Github official org."

That link still exists. On 21 September 2026 the official tornadocash organisation on GitHub gave https://tornado.cash as its website, and so did three of its repositories: tornado-core, tornado-relayer and tornado-classic-ui. The README of tornado-core sends readers to tornado.cash for the whitepaper and the audit reports. The repositories are archived, and their last commits date from July 2022.

The same messages name two addresses, and the chain shows what the note design predicts. On 18 August, between 05:56 and 06:05 UTC, the first received eight withdrawals of 100 ETH and one of 10 ETH from Tornado Cash pools; between 09:31 and 09:32 UTC the second received two more of 100 ETH. That is 1,010 ETH in eleven withdrawals, one for each note. Both addresses had been given their gas money six days earlier, on 12 August, by withdrawals from the 0.1 ETH pool of Tornado Cash itself, and on 21 September both balances were untouched. Several write-ups say only 810 ETH can be seen on-chain: they looked at one address.

A bigger number travels with the story too. Wu Blockchain wrote that the group had "allegedly stolen nearly 4,000 ETH through similar methods over the past 12 months". We found no list of addresses and no report by a security firm behind that figure, so we do not repeat it as fact.

Search engines kept sending people to the domain. We looked at Google's results for "tornado cash" in eight markets through Ahrefs, which keeps dated snapshots of results pages. In seven of them tornado.cash was the first result: the United States (snapshot of 15 September), India (16 September), Russia (20 August), Hong Kong and Taiwan (6 September), Mexico (11 September) and Spain (5 August). Only in the United Kingdom (7 September) did news stories hold the top. In the US snapshot, taken four weeks after the theft was reported, Google's AI Overview linked to the domain as well, and Ahrefs estimated the first position at about 1,800 visits a month from US searches alone. Another 110 or so US searches a month ask outright for the Tornado Cash website, official website or link. Every one of these snapshots predates the hold of 18 September.

How does Tornado Cash work?

Nobody had to break Ethereum, a wallet or a password to take that money. The design explains why.

A deposit starts with two random numbers generated in your browser or by a command-line tool: a nullifier and a secret, 31 bytes each. Their Pedersen hash is called a commitment. The deposit transaction sends the commitment to a pool contract together with the pool's fixed amount, 0.1, 1, 10 or 100 ETH, with separate pools for DAI, cDAI, USDC, USDT and WBTC, so that every deposit in a pool looks like every other. The contract adds the commitment as a leaf to a Merkle tree 20 levels deep, which leaves room for 1,048,576 deposits in each pool.

The note you are told to save is those two numbers written out, with a prefix naming the currency, the amount and the network: tornado-eth-100-1-0x followed by 124 hexadecimal characters. A withdrawal needs nothing else, and the interface says so in capitals: "Do not share your Note with anyone since it WILL be used to withdraw your funds!"

To withdraw, software holding the note builds a zero-knowledge proof, a Groth16 zk-SNARK, which says in effect: I know a nullifier and a secret whose commitment is one of the leaves under this tree root — without saying which leaf. Next to the proof it publishes a hash of the nullifier. The contract verifies the proof, records the nullifier hash and refuses any later withdrawal that presents the same one, with the error "The note has been already spent". The proof also fixes the recipient address, the relayer and its fee; a comment in the circuit says the extra constraints are there "to make sure that tampering with recipient or fee will invalidate the snark proof". A relayer is a third party that submits the withdrawal and takes its fee out of the amount, which helps when the new address holds no ETH for gas, and the proof stops it from changing where the money goes.

Now look at what the contract does not check. The withdrawal never asks who made the deposit or who is calling, and the deposit record holds only the commitment, its place in the tree and a timestamp: breaking the link to the depositor is the whole point of the design. So a note is a bearer secret. Whoever presents it first withdraws to an address of their choosing, and a thief's proof is exactly as valid as the owner's. Once the nullifier is spent, the owner's own proof is refused as a double spend, and there is nobody to appeal to: the pools have had no operator since May 2020. Eleven withdrawals in one morning is what emptying a stack of notes looks like.

A stolen note gives away the privacy as well as the money. The project's own command-line tool has a compliance command that takes a note and shows the deposit and the withdrawal it belongs to.

Tornado Cash Nova, launched on Gnosis Chain in December 2021, dropped both the fixed amounts and the note: funds there sit in a shielded account tied to your wallet, and the contracts can be upgraded by governance.

What Tornado Cash does not hide

The README of tornado-core still says that once ETH is withdrawn to a new address "there is no way to link the withdrawal to the deposit, ensuring complete privacy". Three studies measured how people actually use the pools:

  • Béres and colleagues, Blockchain is Watching You (IEEE DAPPS 2021, data to April 2020), linked 17.1% of the withdrawals from the 0.1 ETH pool and 5.3% of those from the 100 ETH pool using three signals: the same address on both sides, a distinctive gas price set by hand, and a direct transaction between the deposit and withdrawal addresses. Most users of the 0.1 ETH pool withdrew within a day.
  • Tutela, by Wu and colleagues (2022, data to October 2021), marked 42,800 of 97,300 deposits as potentially compromised and estimated that its heuristics cut the anonymity set by 37% on average.
  • Wang and colleagues (ACM Web Conference 2023) linked 18,705 pairs of Tornado Cash addresses on Ethereum and put the average reduction of its anonymity sets at 27%.

These are heuristic estimates, not identities. What they show is that the proof hides which deposit a withdrawal came from, and nothing else: amounts, timing, gas settings and the addresses on either side all stay public.

Attacks on Tornado Cash itself

Three attacks hit the parts of Tornado Cash that were not frozen: the pools before May 2020, the governance and the interface.

October 2019: the team hacked its own pool. A bug in the circuit library's implementation of the MiMC hash, found by Kobi Gurkan, would have let an attacker forge withdrawal proofs. On 12 October the team announced that it had "successfully exploited the tornado.cash smart contract": it generated 100 valid proofs for fake deposits, drained the pool and moved the deposits to fixed code. They sat for a while in a temporary contract that could still be upgraded, with a promise that "the final release version will not be upgradable".

May 2023: the governance takeover. An attacker submitted a proposal presented as a penalty for cheating relayers, with a hidden self-destruct that let them put different code at the approved address after the vote. On 20 May the new code granted them 1.2 million votes against about 700,000 legitimate ones. samczsun wrote the same day that governance had "effectively ceased to exist". The attacker took 483,000 TORN from the governance vault and sold about 379,000 of it for roughly 680,000 dollars of ether. samczsun pointed out that Nova, an upgradable proxy run by governance, could be drained as well. The attacker then passed a proposal of their own that gave control back, and on 28 May the vault was refilled from the DAO's treasury; the attacker kept the proceeds. The immutable ETH pools were out of reach throughout.

January to March 2024: the backdoored interface. A proposal titled "Just update UI and ui decentralized source" was executed on 2 January 2024 and pointed tornadocash.eth to a new build. Its minified code sent the notes of deposits in the largest pools, 100 ETH among them, to a private server. The researcher Gas404 exposed it on 24 February, and a further proposal restored the earlier build on 14 March. The name was genuine, the page was the one the DAO had approved, and the code sat in the very build that voters had been invited to review. How much was stolen through it has never been established publicly.

Have the Tornado Cash sanctions been removed?

Yes. Since 21 March 2025 Tornado Cash has not been on the US sanctions list, and a court has since barred the designation from being enforced. How it got on and off:

  • 8 August 2022. The Office of Foreign Assets Control (OFAC) added Tornado Cash, its website and its contract addresses to the Specially Designated Nationals list. The Treasury's press release said the mixer had "been used to launder more than $7 billion worth of virtual currency since its creation in 2019", including over 455 million dollars stolen by the Lazarus Group, which it links to North Korea, more than 96 million from the Harmony Bridge heist and at least 7.8 million from the Nomad heist.
  • 8 November 2022. OFAC delisted and at the same moment redesignated Tornado Cash, adding its North Korea sanctions authority to the cyber one. The new designation replaced the first entirely.
  • 26 November 2024. In Van Loon v. Department of the Treasury the Fifth Circuit held that "Tornado Cash's immutable smart contracts (the lines of privacy-enabling software code) are not the 'property' of a foreign national or entity", so they could not be blocked under IEEPA, the sanctions law, and OFAC had overstepped its authority.
  • 21 March 2025. The Treasury removed Tornado Cash from the list. Its statement said it remained "deeply concerned" about North Korea's hacking and money laundering, and that US persons "should exercise caution before engaging in transactions that present such risks".
  • 28 April 2025. Back in the district court in Texas, the judge set the designation aside and permanently barred the Treasury from enforcing it.

One name stayed on the list: Roman Semenov, a co-founder, sanctioned separately on 23 August 2023, remains designated under a North Korea program.

The delisting lifted a ban on transactions. It did not end the criminal cases, which concern the people who built and ran the service rather than the contracts.

Is it illegal to use Tornado Cash?

That depends on the country, and this page is not legal advice. The facts that can be stated on 21 September 2026:

  • In the US, transactions with Tornado Cash were prohibited to US persons from 8 August 2022 until the delisting on 21 March 2025. There is no such listing now, and the court judgment of April 2025 bars its enforcement.
  • In October 2023 FinCEN proposed to treat the mixing of virtual currency as a class of transactions of primary money laundering concern, with record-keeping and reporting duties for US financial institutions. FinCEN's own table of special measures, checked on 21 September 2026, still shows it as a proposal with no final rule.
  • In the EU, the Anti-Money Laundering Regulation will from 10 July 2027 forbid crypto-asset service providers to keep accounts that allow the anonymisation or increased obfuscation of transactions. It does not name mixers, and it binds providers rather than the people using a protocol.
  • The criminal cases about Tornado Cash itself, in the US and the Netherlands, have been brought against its developers.

Tornado Cash lawsuits and trials

Two civil lawsuits challenged the sanctions. Van Loon, described above, won in the Fifth Circuit. Coin Center v. Yellen lost in a federal court in Florida in October 2023, and after the delisting the appeals court let it be dismissed in July 2025. The criminal cases are the ones still open:

  • Roman Storm, United States. Arrested in Washington State on 23 August 2023 and charged in New York with conspiracy to commit money laundering, conspiracy to operate an unlicensed money transmitting business and conspiracy to violate sanctions. On 6 August 2025 the jury convicted him of the unlicensed money transmitting conspiracy, which carries up to five years, and could not agree on the other two; the court declared a mistrial on those. His motion for acquittal, argued on 9 April 2026, was still undecided at the last court filing we saw, on 11 September 2026, and he has not been sentenced. The retrial on the two open charges, set for 26 October 2026, was moved on 25 August to 26 April 2027, and on 10 September the judge refused his motion to dismiss those charges on speedy-trial grounds.
  • Roman Semenov. Charged in the same indictment. The prosecutors said at the time that he "remains at large".
  • Alexey Pertsev, the Netherlands. On 14 May 2024 the district court of Oost-Brabant, sitting in 's-Hertogenbosch, convicted him of habitual money laundering, putting the amount laundered at 535,809 ETH, about 1.2 billion dollars, and sentenced him to 64 months. He was released on 7 February 2025 under electronic monitoring to prepare his appeal. In October 2025 the appeal court ordered further investigation and an independent expert, and DL News reported that a judge had allowed the ankle monitor to come off. No appeal hearing date had been announced by September 2026.

The US government's line has moved since the indictment. In April 2025 the Justice Department said it would no longer target mixing and tumbling services "for the acts of their end users or unwitting violations of regulations". In August 2025 the acting head of its Criminal Division said that "merely writing code, without ill-intent, is not a crime", and that new charges of the kind Storm was convicted on would not be approved against the makers of truly decentralised software that holds no user funds. The Storm case goes on regardless.

A note is a key: do not paste it into a page

Everything above comes down to one rule. A note is a bearer secret, like a private key, and any page that receives it can spend it: a page reached through a bookmark, a search result, a link on a project's own GitHub page or a link in a chat and, as 2024 showed, even the page the DAO approved. If you still hold notes from years ago, the deposits behind them are still in the pools. The contracts have no expiry, and the first person to use a note gets the money.

How notrace.exchange differs

We run a different kind of mixer, and the difference is exactly the note. Ours is custodial: you send coins to a deposit address, and the payout leaves in two transfers to two addresses you name when you create the order, each after its own delay of up to six hours, in ETH or in another coin. There is no secret that pays whoever presents it. The two addresses are fixed when the order is created and are listed in a letter signed with our PGP key before you pay, and nothing on the order page changes them. The other side of that trade is custody: while a delay runs, the funds for that transfer are held by us, as section 8 of the terms says. Our fee on 21 September 2026 was 0.5%, and the current one is always in the FAQ. The Ethereum mixer page opens the form on ETH.

Further reading

Share: