Blockchain security researcher Sergey Shemyakov issued an urgent warning on X on June 25, flagging a highly suspicious governance proposal submitted to Tornado Cash DAO about eight hours earlier. The proposal's contract code is unverified, the proposer funded the address through the privacy protocol Railgun to obfuscate the source, and the target contract uses a delegatecall mechanism—if executed, an attacker could gain control over the DAO treasury's roughly $23 million worth of TORN tokens.
Four Red Flags: Unverified Code and a Delegatecall Trap
Shemyakov detailed four dangerous characteristics of the proposal. First, the contract code is unverified—a rare occurrence in Tornado Cash DAO history, which the researcher considers a clear sign of malicious intent. Second, the proposer's address was funded via Railgun four days ago, obscuring the source and making the behavior highly suspicious. Third, the proposal's description appears designed to mislead voters into overlooking the real risk. The fourth and most critical anomaly: once passed and executed, the governance contract would call a function on the target contract via delegatecall. This mechanism grants the attacker extensive privileges, including control over treasury withdrawals.
Mixing Pool Safe; Only DAO Treasury Targeted
The researcher stressed that Tornado Cash's mixing pool contracts remain unaffected by this proposal; user funds are secure. The attack's sole target is the DAO governance layer—if the proposal passes, the attacker could directly drain the DAO treasury's $23 million in TORN, without affecting the mixing service itself.
A Repeat of the 2023 Attack?
Tornado Cash DAO has faced similar threats before. In May 2023, an attacker used a malicious governance proposal to gain 1.2 million fraudulent voting rights, seized protocol control, and stole 10,000 TORN, triggering a 50% price drop. OpenZeppelin classified that incident as a "metamorphic attack," exposing the inherent vulnerabilities of DAO governance. Shemyakov urged all TORN holders to remain vigilant before the proposal enters the voting phase, to independently verify the proposal's content, and not to vote blindly.

