logo

Malicious code in Tornado Cash governance proposal puts user funds at risk

ID: fd9e5e6b-b9bb-5ff3-af37-13b69f165c06

STIX ID: report--fd9e5e6b-b9bb-5ff3-af37-13b69f165c06

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-02-27

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Malicious JavaScript code hidden in Tornado Cash governance proposal #47 covertly encoded and leaked users' private deposit notes to a private server via IPFS-hosted deployments (ipfs.io, cf-ipfs.com, eth.link) starting January 1; a researcher (Gas404) discovered the issue and Tornado Cash developers confirmed the compromise and urged users to withdraw exposed notes and revoke the malicious proposal.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.