BitcoinWorld Suspicious governance proposal puts $23M in Tornado Cash tokens at risk A governance proposal submitted to the Tornado Cash (TORN) protocol is suspectedBitcoinWorld Suspicious governance proposal puts $23M in Tornado Cash tokens at risk A governance proposal submitted to the Tornado Cash (TORN) protocol is suspected

Suspicious governance proposal puts $23M in Tornado Cash tokens at risk

2026/06/26 09:55
Okuma süresi: 3 dk
Bu içerikle ilgili geri bildirim veya endişeleriniz için lütfen crypto.news@mexc.com üzerinden bizimle iletişime geçin.

BitcoinWorld

Suspicious governance proposal puts $23M in Tornado Cash tokens at risk

A governance proposal submitted to the Tornado Cash (TORN) protocol is suspected of containing malicious code, potentially putting $23 million worth of the token at risk of theft. Blockchain security researcher Sergey Shemyakov reported the finding via X, urging the community to exercise caution before voting.

Unverified code and privacy tool funding raise red flags

Shemyakov noted that the proposal’s contract code remains unverified, a significant departure from standard practice in decentralized autonomous organization (DAO) governance. Typically, proposal code is publicly auditable to ensure transparency. Additionally, the proposer received initial funding through Railgun, a privacy-focused tool that obscures transaction histories, making it difficult to trace the source of funds.

The researcher explained that the proposal is structured in a way that could allow the proposer to seize control of the DAO’s governance mechanisms. While the Tornado Cash mixing pool itself remains safe, the attack appears to be aimed directly at the protocol’s governance layer, potentially enabling the theft of TORN tokens held in the DAO treasury.

Implications for DAO security and user funds

This incident highlights a growing vulnerability in decentralized governance systems. Malicious actors can exploit the often-complex proposal process to insert hidden code that, if approved, grants them administrative control. For Tornado Cash, which has already faced significant regulatory and technical challenges, this represents another threat to its operational integrity.

What users should know

The immediate risk is limited to the DAO treasury, not the mixing pools or user funds. However, if the proposal were to pass, the attacker could drain the treasury of its TORN tokens. The community is advised to reject the proposal and for the DAO to implement more rigorous code verification processes before any vote.

Conclusion

The discovery of a potentially malicious governance proposal underscores the importance of security diligence in decentralized finance. As DAOs become more common, so do targeted attacks on their governance structures. The Tornado Cash community must act swiftly to neutralize this threat and reinforce its security protocols to prevent future incidents.

FAQs

Q1: Is my Tornado Cash mixing pool safe?
Yes, the mixing pool itself is not affected. The risk is limited to the DAO treasury and governance tokens.

Q2: How can the community stop this attack?
By voting against the malicious proposal and implementing stricter code verification before any future votes.

Q3: What makes this proposal suspicious?
The contract code is unverified, and the proposer funded their address through a privacy tool, making it difficult to identify them.

This post Suspicious governance proposal puts $23M in Tornado Cash tokens at risk first appeared on BitcoinWorld.

Piyasa Fırsatı
TornadoCash Logosu
TornadoCash Fiyatı(TORN)
$4.842
$4.842$4.842
-3.83%
USD
TornadoCash (TORN) Canlı Fiyat Grafiği

CHZ +28%! Will History Repeat?

CHZ +28%! Will History Repeat?CHZ +28%! Will History Repeat?

0-fee opening long & short. Be ready for any move!

Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen crypto.news@mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

World Cup Combo: Aim for 200x

World Cup Combo: Aim for 200xWorld Cup Combo: Aim for 200x

Combine up to 20 World Cup matches in one order