Cointime

Download App
iOS & Android

Who Will Be the Next Target After Tornado Cash Governance Attack?

Validated Project

On May 20, 2023, Tornado Cash fell victim to a governance attack, resulting in a loss of approximately $1 million. The attacker initiated the attack by submitting a malicious proposal with a misleading description, which was later approved by the voters. Once the malicious proposal was executed, the attacker gained control over the governance of Tornado Cash.

Let's analyze how this attack unfolded and examine the underlying reasons behind it.

By examining the transaction records, we can trace the details of the attack. The attacker used two addresses: Attacker A (https://etherscan.io/address/0x092123663804f8801b9b086b03b98d706f77bd59) and Attacker B (https://etherscan.io/address/0x592340957ebc9e4afb0e9af221d06fdddf789de9).

The transaction details can be found here: https://etherscan.io/tx/0x65fa5b475f34a954a10f88f2c84f316a048a0e67d273c7abb098717b1a4a46a3.

The code for the malicious proposal is stored at the following address: https://etherscan.io/address/0xc503893b3e3c0c6b909222b45f2a3a259a52752d#code.

The contract that was attacked is TornadoVault (https://etherscan.io/address/0x2f50508a8a3d323b91336fa3ea6ae50e55f32185#code).

The attack unfolded as follows:

1. Attacker B created the malicious proposal at address 0xc503893b3e3c0c6b909222b45f2a3a259a52752d

2. Attacker B submitted a deceptive proposal labeled as #20.

3. Attacker A manipulated multiple accounts to lock 0 TORN tokens.

4. Deceived users voted for proposal #20.

5. After reaching the required number of votes, the attacker launched the attack:

  • The old proposal was destroyed. Attacker B invoked the emergencyStop function, destroying the old proposal at address 0xC50389 (https://etherscan.io/tx/0xd3a570af795405e141988c48527a595434665089117473bc0389e83091391adb
  • The proposal contract was updated. Attacker B created a new proposal contract at the same address 0xC50389 (https://etherscan.io/tx/0xa7d20ccdbc2365578a106093e82cc9f6ec5d03043bb6a00114c0ad5d03620122
  • Proof of Concept: A test file (https://github.com/MetaTrustLabs/SmartContractAttackPoC/blob/main/test/TornadoCash) was created to simulate the attacker's steps, including the creation and destruction of malicious contracts and the creation of new contracts at the same address.

6. Token transfers

  • Attacker B transferred tokens to Tornado.Cash: Governance Staking.
  • Attacker A transferred tokens to the attacker-controlled account.

Eventually, Attacker A obtained tokens worth $1 million through this attack.

The root causes of this governance attack can be attributed to two factors: the approval of a malicious proposal and the destruction and recreation of the proposal contract by the attacker.

Firstly, the attacker lured voters into making a misjudgment by creating a malicious proposal, leading them to approve it without fully understanding its potential risks. This deceptive description may have concealed the true intentions of the attack and misled voters into believing that the proposal was beneficial or harmless.

Secondly, the attacker took measures to destroy the original proposal contract and recreate it at the same address. By invoking the emergencyStop function, the attacker successfully disrupted the logic of the original proposal, causing its execution results to deviate from expectations. This action provided the attacker with an opportunity to seize control of the governance and laid the foundation for subsequent attacks.

The combination of these two factors enabled the attacker to successfully carry out the governance attack and take control of Tornado Cash. The approval of the malicious proposal and the destruction and recreation of the proposal contract paved the way for the attacker to utilize the controlled governance for further operations.

This attack highlights the importance of security and risk management in decentralized governance processes. Developers and communities should strengthen the review of proposals to ensure accurate and transparent descriptions, as well as enhance the security audit of contracts to prevent attackers from exploiting vulnerabilities and engaging in malicious activities. Additionally, users and voters need to carefully evaluate proposal content and ensure they understand the potential risks and consequences.

For projects like Tornado Cash and similar ones, this governance attack should be considered a lesson to strengthen their governance processes and security mechanisms, thereby improving the overall system's security and resilience against risks. Only through continuous security audits, risk assessments, and increased community participation and awareness can we establish a safer and more reliable blockchain ecosystem.

About Us

At MetaTrust, our primary focus is on creating a secure infrastructure that caters to the needs of developers in the WEB 3.0 space. We offer an array of AI-Driven automation tools and security services to assist Web3 developers and project stakeholders in achieving a secure development environment.

Website | Twitter | Telegram | Try MetaScan for FREE

Comments

All Comments

Recommended for you

  • Circle minted 500 million USDC on the Solana network.

    according to Onchain Lens monitoring, Circle has minted 500 million USDC on the Solana network. Since October 11, Circle has issued a total of 18 billion USDC on the Solana network.

  • Sources familiar with the matter: JPMorgan Chase is considering offering cryptocurrency trading services to institutional clients.

    according to Bloomberg, as major global banks deepen their involvement in the cryptocurrency asset class, JPMorgan Chase is considering offering cryptocurrency trading services to its institutional clients. A knowledgeable source revealed that JPMorgan is evaluating what products and services its market division can offer to expand its business in the cryptocurrency field. The source stated that these products and services may include spot and derivatives trading.

  • Federal Reserve Governor Milan: We believe that the policy rate will eventually be lowered.

    Federal Reserve Board member Mylan stated that due to the US government shutdown, there were some anomalies in last week's inflation data; he believes that the US will not experience an economic recession in the near term, but if policies are not adjusted, the US will face an increasing risk of economic recession. We believe that policy interest rates will eventually be lowered.

  • BlackRock deposited 819.39 BTC, worth approximately $73.72 million, into Coinbase.

     according to Onchain Lens monitoring, BlackRock deposited 819.39 BTC into Coinbase, worth approximately 73.72 million USD.

  • Ghana passes law legalizing the use of cryptocurrency

    according to Bloomberg, the Ghanaian Parliament has approved a cryptocurrency legalization bill aimed at addressing the expanding use of cryptocurrencies in the country but the lack of regulation. According to Johnson Asiamah, Governor of the Bank of Ghana, the newly passed Virtual Asset Service Providers Act will facilitate the licensing of crypto platforms and the regulation of related activities.

  • CryptoQuant: Bitcoin network activity cools, market shows clear bearish signs.

    CryptoQuant published an analysis stating that the Bitcoin market continues to be in a bear market state, with multiple network indicators showing a significant cooling of activity. Data shows that the 30-day moving average of Bitcoin is below the 365-day moving average (-0.52%), and the bull-bear cycle indicator confirms the current bear market pattern. The number of network transactions has dropped from about 460,000 to about 438,000, fees have decreased from $233,000 to $230,000, and highly active addresses have reduced from 43.3K to 41.5K, all indicating reduced speculative activity and that the market is in a defensive phase.

  • ETH falls below $3,000

    the market shows that ETH has fallen below $3000, currently at $2999.5, with a 24-hour increase of 0.86%. The market is highly volatile, please manage your risks accordingly.

  • BTC breaks through $89,000

    market shows BTC breaking through $89,000, currently at $89,014.5, with a 24-hour increase of 0.85%. The market is highly volatile, please manage your risk accordingly.

  • F2Pool co-founder: Last year, 500 bitcoins were transferred in to confirm whether the private key had been leaked; hackers took 490 bitcoins.

    regarding the community's heated discussion about the 50 million USDT phishing attack, F2Pool co-founder Wang Chun tweeted, "Last year, I suspected that my private key was leaked. To confirm whether the address was really hacked, I transferred 500 bitcoins to that address. To my surprise, the hacker 'generously' only took 490 bitcoins, leaving me 10 bitcoins, enough for me to make a living."