🚨🌪💵 I would like to share a brief analysis of the Tornado Cash Attack that occurred recently.
A few days ago, a rather unusual attack took place on the popular Tornado Cash, an Ethereum protocol that functions as a blender. Essentially, it allows users to deposit tokens, mix them, and receive them in different addresses, ensuring their anonymity.
Due to its functionality, many criminal organizations have utilized Tornado Cash to conceal or redirect their funds to other wallets. According to Yahoo Finance, Tornado Cash was used to hide over USD 10 billion in cryptocurrencies. As a result of its association with such activities, TORN was sanctioned by the US government.
Tornado Cash operates as a decentralized autonomous organization (DAO). But what does this mean? In simple terms, DAOs are governed by their members, who make decisions through proposals and voting. Any user can propose something, and then others vote on it (in this case, users must have more than 1000 $TORN locked to make a proposal). If a proposal is accepted via successful voting, it can be executed through smart contracts.
Now, let's discuss the hacking incident:
On May 21st, at 11:52:11 AM +UTC, a hacker created a proposal that appeared attractive to Tornado Cash members, and it was accepted. However, the hacker later destroyed that proposal and deployed a malicious proposal using the same address as the previous one. The malicious proposal was executed, granting the hacker control over the entire organization. By self-awarding the majority of votes, the hacker exploited a vulnerability within the system. This incident serves as a crucial lesson for decentralized organizations to exercise caution and consider the consequences of their voting decisions, as it ultimately cost them their organization.
Days later, the hacker began defunding the DAO. They transferred and sold 38,302 $TRON, which is equivalent to approximately $150,000 USD at today's value. Additionally, they utilized the Tornado Cash system to mix 460 ETH (around $870,000 USD), which belonged to the DAO, in order to make them untraceable.
I have included a link to a 100 ETH mixing transaction for you to examine on the blockchain: lnkd.in/dXqXX5Yk
I just voted "Option 1 (Only Front)" on "What is the Linea SWAG that you would like to see at upcoming events? " snapshot.org/#/linea-build.eth/proposal/0xda4f201a37ea08cf1892418e7b9e88f5687a68dbdc96c3ab22abaa1c7244648e #Snapshot
TORNADO CASH EXPLOIT: 🚨⚠️
THE ATTACKER IS MOVING FUNDS
TRANSFERRED
#tornadocash #exploit
Tornado situation only improves the ecosystem by making people and DAOS aware that this can happen.
Fool me once shame on you fool me twice shame on me.
Hey everyone! im sharing the Pitch Deck for Meleora DAO.
www.figma.com/proto/IOUAU2SndvBOa8cGj9WIqC/Meleora?node-id=1%3A2
Meleora
Hello community!
Yesterday we launched MeleoraDAO. The digital and physical city of the future. We aim to provide the members the tools and opportunity to achieve their own professional, social and economic objectives. If anyone is interested to join let me know. Not everybody can enter. You will need to be onboarded. Only like-minded individuals with the energy and the want to progress are able to join.
Meleora empowers its members to collaborate and pool their resources to fund and launch new projects and initiatives. Whether you're an entrepreneur with a groundbreaking idea or a professional looking to join a dynamic and supportive community, Meleora offers a unique and exciting opportunity to be part of a new model for success and fulfillment.
meleoracity.com
I just voted "Yes" on "Real Estate Developmenet. " demo.snapshot.org/#/meletest2.eth/proposal/0x1502fc74e8f539d16b131149e3fb677b8219c2b0cbda489a8d34230af46f5ef9 #snapshotlabs