zkLend Hacker Loses $5.4M in Phishing Attack While Using Tornado Cash

šŸ¤¦ā€ā™‚ļø Crypto Hacker Loses $5.4M in Phishing Scam šŸ¤‘

zkLend Hacker Loses $5.4M in Phishing Attack While Using Tornado Cash

Oh dear, it seems the universe has finally caught up with the universeā€™s most incompetent hacker. In a stunning display of incompetence, the scoundrel behind the February 2025 zkLend exploit has managed to lose a whopping $5.4 million worth of Ethereum (ETH) in a phishing scam. Because, you know, who needs a decent security system when you can just use Tornado Cash? šŸ¤£

According to onchain analytics firm Lookonchain, Karma (the universeā€™s way of saying ā€œyouā€™re a jerkā€) has decided to pay a visit to this hacker, who had previously stolen 2,930 ETH from zkLend. Itā€™s a bit like the universe is saying, ā€œHey, you thought you were clever, but really youā€™re just a big doofus.ā€ šŸ¤¦ā€ā™‚ļø

Itā€™s a bit of a Karma-filled cycle, really. Hacker steals 2,930 ETH from zkLendā€¦ then gets phished while using Tornado Cash. All 2,930 ETH gone ā€” to another thief. Karma hit fast.

ā€” Lookonchain (@lookonchain) April 1, 2025

The hacker, in a moment of sheer brilliance, managed to send an onchain message to the zkLend deployer address, apologizing for the whole debacle and blaming the phishing website. Itā€™s a bit like saying, ā€œIā€™m sorry I messed up, but itā€™s not my fault, I used a fake website!ā€ šŸ™„

As it turns out, the hacker had been using a fake Tornado Cash website, dubbed ā€œtornadoeth[.]cashā€, which had been operating undetected for over five years. Because, you know, who needs security when you can just use a dodgy website? šŸ˜

Tornado Cash, the very same service thatā€™s supposed to obscure transaction trails, has been the target of phishing schemes for years. Itā€™s a bit like the universe is saying, ā€œHey, Tornado Cash, youā€™re supposed to be secure, but really youā€™re just a big target for scammers.ā€ šŸ¤¦ā€ā™‚ļø

And to make matters worse, the incident reflects a troubling trend in rising crypto scams and security breaches. According to Immunefiā€™s Q1 2025 report, the first quarter of the year saw a record-breaking $1.64 billion stolen in various crypto-related attacks. Itā€™s a bit like the universe is saying, ā€œHey, crypto users, youā€™re all just sitting ducks waiting to be scammed.ā€ šŸ¤‘

For zkLend users and the broader crypto community, this incident serves as both a cautionary tale and a testament to the ever-evolving dangers lurking in the digital asset landscape. So, do take heed, folks. Donā€™t use Tornado Cash. Donā€™t use phishing websites. And for goodnessā€™ sake, donā€™t be a hacker. šŸ™

Read More

2025-04-02 22:13