An Ethereum address associated with the takeover of Tornado Cash governance deployed a new proposal contract on May 21, 2023, offering a possible route to reverse key changes imposed during the attack one day earlier. The deployment was recorded at 11:52:11 UTC, and Tornado Cash community participants identified the contract as Proposal 21.
The development did not restore governance on May 21. It placed code on-chain that appeared designed to do so if executed. That distinction was critical because the same attacker still possessed the artificial voting power needed to determine the proposal’s outcome.
What appeared on-chain
The verified Ethereum record identifies the proposal contract as `0x1FAd009aD35689B5a9B91486148F2F32AFE31e23`. Its bytecode included operations consistent with resetting storage entries associated with the attacker’s fabricated voting balances and transferring 483,000 TORN to the separate governance vault.
A contemporaneous Tornado Cash forum analysis said the attacker had assigned 10,000 TORN-equivalent locked balances to 102 addresses during the takeover. The author’s initial May 21 assessment was appropriately cautious: the new proposal seemed intended to reset those entries, but its full effects still required verification.
That uncertainty matters. A deployed contract is an observable fact; its purpose is an interpretation of code; successful execution is a separate event. On May 21, the record supported the first two propositions but not the third.
The takeover behind the proposal
The reversal attempt followed a governance attack executed at 07:25:11 UTC on May 20, 2023. Security researcher Samczsun reported that a malicious proposal granted its author 1.2 million votes, exceeding roughly 700,000 legitimate votes then participating in Tornado Cash governance.
The attacker had presented the original proposal as resembling an earlier governance action. The implementation, however, used contract-replacement behavior to introduce different logic after voters had approved it. A contemporaneous technical analysis by SharkTeam described the sequence as involving `CREATE2`, contract destruction and redeployment at the same address, followed by execution through the governance contract.
The resulting authority covered Tornado Cash governance, including locked voting balances and governance-controlled assets. Contemporaneous reporting distinguished that compromise from the protocol’s core privacy pools: the takeover did not, by itself, rewrite the immutable pool contracts or directly establish that deposited mixer funds had been drained.
Why the proposal mattered
Proposal 21 exposed a difficult property of token governance. The community’s most direct recovery path depended on the party that had compromised the voting system. Token holders could inspect and discuss the new code, but the attacker’s fabricated majority meant ordinary voting no longer provided an independent check.
The episode also demonstrated that proposal descriptions and familiar contract addresses were insufficient security controls. Reviewers had to verify executable bytecode, deployment mechanics and whether code could change between approval and execution.
There was a visible market consequence, although its measurement was limited. CoinDesk reported on May 21 that the TORN/U.S.-dollar price had fallen by as much as 40% over the preceding 24 hours, citing CoinGecko data. TORN traded continuously across multiple venues, CoinGecko aggregated those markets, and the report did not define a single official closing price. The decline therefore documented market stress but did not prove that every part of the move was caused by the governance attack.
What remained unresolved on May 21
The proposal’s deployment was not evidence of benevolent intent, recovered funds or restored control. Community participants explicitly considered the possibility that the attacker might decline to execute it or use the proposal for further manipulation.
The questions outstanding at the end of May 21 were concrete: whether Proposal 21’s storage changes had been completely audited, whether the attacker would carry it through the voting and execution process, whether the governance vault would be made whole, and what safeguards could prevent another metamorphic-proposal attack. Those answers belonged to subsequent dates and should not be projected backward into this record.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

