Crackdown on Tornado Cash

DeHacker
DeHacker Security
Published in
3 min readAug 19, 2022

On August 8, 2022, the official website of the U.S. Treasury’s Office of Foreign Assets Control of the US Department of the Treasury (OFAC) showed that some addresses that interact with or related Ethereum addresses under the Tornado Cash agreement were placed on the SDN List.

Tornado Cash is a mixer, meaning that it helps obfuscate the origins and destinations of cryptocurrency transactions and makes them harder to trace, even for law enforcement. People can send funds to a smart contract on the Ethereum blockchain, which then mixes the funds, which are then withdrawn from another address.

In many hacking incidents, we can always see the figure of Tornado Cash.

In the recent Nomad security incident, hackers also used Tornado Cash to make coin shuffle.

Coin Shuffle is a decentralized privacy feature that allows users to quickly and efficiently mix funds with other users, creating random mappings between existing user accounts and new accounts after shuffling , thus achieving complete anonymity.

In the first half of 2022, approximately $1,140.7 million of stolen funds were transferred into Tornado Cash by hackers, accounting for approximately 60% of the total amount lost.

WHY HACKERS ALWAYS CHOOSE TORNADO CASH?

If users of Tornado Cash want to transfer or mix an asset anonymously, they first need to transfer the asset to the smart contract of Tornado Cash. Tornado Cash gives the user a randomly generated key as a credential, which can prove that you have executed deposit, but did not disclose the original address; when withdrawing, you only need to submit the random key given by the previous system to Tornado Cash, and after the user submits a new address, the smart contract will transfer the assets to the new address and complete the “mixing” of the assets. ”, so that the transaction cannot be traced back. This is why most hackers choose Tornado Cash.

About The Crypto Launchpad

The Crypto Launchpad is a one-stop solution for all new and Existing crypto projects. We help crypto projects from developing a token, Auditing, to its listing and marketing. TCL is a leading agency for helping its clients listing their coins/tokens in the world’s top exchanges at a rate lower than official. Our dedicated blockchain experts thoroughly analyze, brainstorm, ideate, and execute groundbreaking concepts for your crypto-related businesses.

The Crypto Launchpad provides you with a variety of services under one umbrella. You do not have to move from agencies to agencies to avail different kinds of services. Here in CL, we provide you services like the development of crypto coin/token, token audit, exchange listing, press releases, youtube reviews videos, the formation of telegram community, telegram community managers/moderators to handle the projects’ groups of different languages, private investors meet, AMA, and many more in an integrated package.

Website | Twitter | Telegram | Facebook | LinkedIn

About DeHacker

DeHacker is a team of auditors and white hat hackers who perform security audits and assessments. With decades of experience in security and distributed systems, our experts focus on the ins and outs of system security. Our services follow clear and prudent industry standards. Whether it’s reviewing the smallest modifications or a new platform, we’ll provide an in-depth security survey at every stage of your company’s project. We provide comprehensive vulnerability reports and identify structural inefficiencies in smart contract code, combining high-end security research with a real-world attacker mindset to reduce risk and harden code.

Website | Twitter | Blog | Telegram

--

--