• bitcoinBitcoin (BTC) $ 59,968.00
  • ethereumEthereum (ETH) $ 1,572.79
  • tetherTether (USDT) $ 0.998614
  • bnbBNB (BNB) $ 556.90
  • usd-coinUSDC (USDC) $ 0.999773
  • xrpXRP (XRP) $ 1.05
  • solanaSolana (SOL) $ 70.52
  • tronTRON (TRX) $ 0.320731
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • hyperliquidHyperliquid (HYPE) $ 61.81
  • dogecoinDogecoin (DOGE) $ 0.074477
  • usdsUSDS (USDS) $ 0.999519
  • rainRain (RAIN) $ 0.015585
  • leo-tokenLEO Token (LEO) $ 9.41
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • zcashZcash (ZEC) $ 395.21
  • canton-networkCanton (CC) $ 0.152933
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • stellarStellar (XLM) $ 0.173883
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • moneroMonero (XMR) $ 312.63
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • whitebitWhiteBIT Coin (WBT) $ 47.93
  • chainlinkChainlink (LINK) $ 7.29
  • cardanoCardano (ADA) $ 0.145227
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • labLAB (LAB) $ 16.54
  • usd1-wlfiUSD1 (USD1) $ 0.999109
  • daiDai (DAI) $ 0.999654
  • susdssUSDS (SUSDS) $ 1.08
  • ethena-usdeEthena USDe (USDE) $ 0.998172
  • the-open-networkGram (prev. Toncoin) (GRAM) $ 1.56
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • bitcoin-cashBitcoin Cash (BCH) $ 195.68
  • litecoinLitecoin (LTC) $ 42.16
  • hedera-hashgraphHedera (HBAR) $ 0.071929
  • wethWETH (WETH) $ 2,268.37
  • hashnote-usycCircle USYC (USYC) $ 1.13
  • global-dollarGlobal Dollar (USDG) $ 0.999718
  • avalanche-2Avalanche (AVAX) $ 6.44
  • usdt0USDT0 (USDT0) $ 0.998824
  • suiSui (SUI) $ 0.685398
  • paypal-usdPayPal USD (PYUSD) $ 0.999887
  • crypto-com-chainCronos (CRO) $ 0.054641
  • tether-goldTether Gold (XAUT) $ 4,064.55
  • shiba-inuShiba Inu (SHIB) $ 0.000004
  • nearNEAR Protocol (NEAR) $ 1.88
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.14
  • bittensorBittensor (TAO) $ 209.47
  • pax-goldPAX Gold (PAXG) $ 4,068.55
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.057696
  • uniswapUniswap (UNI) $ 2.92
  • aster-2Aster (ASTER) $ 0.621620
  • okbOKB (OKB) $ 78.30
  • ripple-usdRipple USD (RLUSD) $ 0.999893
  • worldcoin-wldWorldcoin (WLD) $ 0.450702
  • ondo-financeOndo (ONDO) $ 0.311339
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • htx-daoHTX DAO (HTX) $ 0.000002
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • mantleMantle (MNT) $ 0.436639
  • aaveAave (AAVE) $ 94.34
  • falcon-financeFalcon USD (USDF) $ 0.994977
  • pi-networkPi Network (PI) $ 0.128854
  • usddUSDD (USDD) $ 0.998654
  • polkadotPolkadot (DOT) $ 0.815629
  • bfusdBFUSD (BFUSD) $ 0.998461
  • internet-computerInternet Computer (ICP) $ 2.14
  • skySky (SKY) $ 0.049297
  • bitget-tokenBitget Token (BGB) $ 1.64
  • morphoMorpho (MORPHO) $ 1.75
  • ethereum-classicEthereum Classic (ETC) $ 7.13
  • dexeDeXe (DEXE) $ 22.14
  • united-stablesUnited Stables (U) $ 0.999702
  • pepePepe (PEPE) $ 0.000002
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • memecoreMemeCore (M) $ 0.742608
  • blockchain-capitalBlockchain Capital (BCAP) $ 107.03
  • quant-networkQuant (QNT) $ 65.67
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.20
  • kucoin-sharesKuCoin (KCS) $ 6.76
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • stable-2​​Stable (STABLE) $ 0.037645
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.11
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • usdgoUSDGO (USDGO) $ 1.00
  • render-tokenRender (RENDER) $ 1.56
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • cosmosCosmos Hub (ATOM) $ 1.57
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • superstate-short-duration-us-government-securities-fund-ustbInvesco Short Duration US Government Securities Fund (USTB) $ 11.13
  • algorandAlgorand (ALGO) $ 0.085884
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • kaspaKaspa (KAS) $ 0.027801
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.070646
  • wbnbWrapped BNB (WBNB) $ 759.61
  • usdtbUSDtb (USDTB) $ 0.999571
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • justJUST (JST) $ 0.085683
  • jupiter-exchange-solanaJupiter (JUP) $ 0.219064
  • audieraAudiera (BEAT) $ 2.54
  • nexoNEXO (NEXO) $ 0.721110
  • ethenaEthena (ENA) $ 0.077095
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.701569
  • gatechain-tokenGate (GT) $ 6.57
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.04
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • velvetVelvet (VELVET) $ 1.59
  • beldexBeldex (BDX) $ 0.083800
  • venice-tokenVenice Token (VVV) $ 13.55
  • adi-tokenADI (ADI) $ 4.92
  • spiko-amundi-overnight-swap-fund-eurSpiko Amundi Overnight Swap Fund (EUR) (EURSAFO) $ 1.15
  • ghoGHO (GHO) $ 0.997660
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • filecoinFilecoin (FIL) $ 0.728248
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • flare-networksFlare (FLR) $ 0.006659
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • yldsYLDS (YLDS) $ 0.999988
  • pump-funPump.fun (PUMP) $ 0.001369
  • xdce-crowd-saleXDC Network (XDC) $ 0.027825
  • clbtcclBTC (CLBTC) $ 76,920.00
  • usual-usdUsual USD (USD0) $ 0.998783
  • hash-2Provenance Blockchain (HASH) $ 0.009367
  • midnight-3Midnight (NIGHT) $ 0.030756
  • usxUSX (USX) $ 0.999802
  • true-usdTrueUSD (TUSD) $ 0.997700
  • aptosAptos (APT) $ 0.580121
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • a7a5A7A5 (A7A5) $ 0.012264
  • arbitrumArbitrum (ARB) $ 0.073402
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • injective-protocolInjective (INJ) $ 4.63
  • tbtctBTC (TBTC) $ 70,942.00
  • aerodrome-financeAerodrome Finance (AERO) $ 0.461396
  • lighterLighter (LIT) $ 1.73
  • euro-coinEURC (EURC) $ 1.14
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.32
  • dashDash (DASH) $ 33.09
  • ousgOndo Short-Term U.S. Government Bond Fund (OUSG) $ 115.70
  • hastra-primePRIME (PRIME) $ 1.04
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • jito-governance-tokenJito (JTO) $ 0.814042
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • official-trumpOfficial Trump (TRUMP) $ 1.65
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.172949
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • vechainVeChain (VET) $ 0.004519
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006178
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • bonkBonk (BONK) $ 0.000004
  • celestiaCelestia (TIA) $ 0.373860
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.532536
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997057
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • sei-networkSei (SEI) $ 0.050414
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000061
  • ether-fiEther.fi (ETHFI) $ 0.347181
  • the9bitThe9bit (9BIT) $ 0.042627
  • spx6900SPX6900 (SPX) $ 0.343554
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • sun-tokenSun Token (SUN) $ 0.016599
  • kite-2Kite (KITE) $ 0.136149
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • blockstackStacks (STX) $ 0.167907
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • grassGrass (GRASS) $ 0.491985
  • kinesis-goldKinesis Gold (KAU) $ 125.46
  • curve-dao-tokenCurve DAO (CRV) $ 0.191773
  • apxusdapxUSD (APXUSD) $ 0.740359
  • gnosisGnosis (GNO) $ 103.95
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • ethgas-2ETHGas (GWEI) $ 0.130419
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • plasmaPlasma (XPL) $ 0.101435
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • pyth-networkPyth Network (PYTH) $ 0.033507
  • apenftAINFT (NFT) $ 0.00000026
  • noonNoon (NOON) $ 0.751949
  • royal-dollarRoyal Dollar (RUSD) $ 0.998700
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • bittorrentBitTorrent (BTT) $ 0.00000026
  • skyaiSkyAI (SKYAI) $ 0.249903
  • bitcoin-svBitcoin SV (BSV) $ 12.41
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • fraxLegacy Frax Dollar (FRAX) $ 0.988256
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • olympusOlympus (OHM) $ 15.83
  • tezosTezos (XTZ) $ 0.212443
  • megausdMegaUSD (USDM) $ 1.00
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • zebec-networkZebec Network (ZBCN) $ 0.002338

Tornado Cash DAO faces ‘malicious’ governance attack, researchers warn

0 0


Researchers at L2BEAT have flagged a suspicious governance proposal submitted to the Tornado Cash DAO.

It raised eyebrows for pointing to an unverified contract, something “very unusual for Tornado Cash DAO proposals… [and] a clear indication that the proposal should be treated as malicious.”

Adding to suspicions, the address of the proposer was funded by Railgun (a competing crypto privacy protocol) just four days ago.

Sergey Shemyakov, a ZK researcher, took to X to “summon” others to examine the proposal, which “shows pretty convoluted logic.”

1/ A suspicious DAO proposal on Tornado Cash was created ~8hrs ago. Summoning @pcaversaccio (and everyone else curious) for an independent opinion!

Details in the thread below👇 pic.twitter.com/akCpfW4f6P

— sergeyshemyakov, PhD 💗 (@sergeyshemyakov) June 25, 2026

The proposal purports to define a new fee structure and “establish a brand-new dynamic deflationary economic model.”

However, Security Alliance researcher Pascal Caversaccio alleged the “malicious” intentions behind the proposal, stating that the real intention is to switch key addresses with spoofed lookalikes.

The current DAO governance address, which holds $23 million of TORN tokens, would be replaced by an attacker-controlled address which shares the same initial 15 characters.

A similar switch would be made on the staking governance proxy contract.

Caversaccio also notes that the spoofed governance address would be able to “zero out any relayer’s balance at will.” He called the proposal a “governance attack on Tornado Cash” and urged TORN holders to reject it.

All TORN up

Today’s governance attack is the latest in a long series of governance, legal and security troubles for Tornado Cash.

Tornado Cash last faced a governance attack in 2023 when a malicious proposal passed, granting an attacker a majority share of votes.

On 2023/05/20 at 07:25:11 UTC, Tornado Cash governance effectively ceased to exist. Through a malicious proposal, an attacker granted themselves 1,200,000 votes. As this is more than the ~700,000 legitimate votes, they now have full control. pic.twitter.com/h9qjc3xRqz

— samczsun (@samczsun) May 20, 2023

After selling around $800,000 of TORN tokens for ETH, the attacker created a new proposal to set its voting power back to zero. Not before washing the proceeds through none other than Tornado Cash itself, though.

The following year, multiple Tornado Cash IPFS front ends were injected with malicious javascript to leak sensitive deposit information to an attacker-controlled server. Even a hacker allegedly fell victim to the trap.

In the legal sphere, Tornado Cash was sanctioned by the US Treasury in 2022, though the decision was eventually reversed last year.

Despite no longer being banned, Tornado Cash developer Roman Storm was prosecuted for conspiracy to operate an unlicensed money-transmitting business last year, following a rocky trial.

Storm’s fate continues to hang in the balance. In April, a motion for acquittal was left unresolved and prosecutors are keen to retry two counts on which the jury remained deadlocked at the end of his trial.





Source link

Leave A Reply

Your email address will not be published.