Tornado Cash governance Proposal 21 completed voting on May 26, 2023, with roughly 517,000 TORN-weighted votes in favor and none against. The proposal was designed to reverse the governance changes used in a hostile takeover six days earlier and reduce the attacker’s artificially created voting balances to zero.
The result was an important but limited recovery step. Passing the vote did not itself execute the proposal, identify the attacker or recover tokens already removed from governance. Because the attacker still controlled enough voting power to determine the result and participated in approving the reversal, the unanimous tally could not be treated as evidence of broad, independent community consensus.
How governance was captured
On May 20, 2023, an unidentified address used a malicious proposal to seize control of Tornado Cash’s token-governed decentralized autonomous organization. Contemporaneous technical accounts said the proposal appeared to reproduce logic from an earlier, accepted governance action. Its implementation could subsequently be replaced with different code at the same address, allowing the attacker to assign itself 1.2 million governance votes.
That voting balance exceeded the legitimate voting power participating in Tornado Cash governance and gave the address effective control over subsequent proposals. A protocol-community test repository created before the restoration vote documented 1.2 million attacker-created TORN voting units and identified 483,000 TORN as having been withdrawn from the Governance Vault, leaving an accounting imbalance that Proposal 21 was intended to repair.
Those figures describe governance-contract state, not the balances of Tornado Cash’s separate mixing pools. The surviving records do not establish that Proposal 21 recovered the withdrawn tokens, and this reconstruction does not assign them a dollar value because crypto prices vary by venue and measurement time.
What Proposal 21 could—and could not—repair
Proposal 21 sought to restore the pre-attack governance state by nullifying the attacker’s fabricated voting balances and replenishing the Governance Vault from tokens held by the governance contract. Community testing examined whether the vault’s token balance and its internal accounting would again match after execution.
The May 26 vote mattered because token governance was the mechanism for changing Tornado Cash’s auxiliary protocol administration. Until the malicious voting power was removed, the attacker retained the practical ability to dictate outcomes. The episode also exposed a broader weakness in decentralized governance: voters may approve a proposal’s stated purpose without independently verifying every behavior permitted by its executable code.
Still, the vote was an authorization, not the final state transition. Execution remained subject to the governance contract’s delay and an on-chain transaction after the vote. On May 26, it therefore remained possible that the attacker could decline to execute the proposal, modify its behavior if the underlying deployment mechanism permitted it, or take other actions while retaining control.
An unusually constrained protocol
The incident carried added institutional significance because the U.S. Treasury’s Office of Foreign Assets Control had redesignated Tornado Cash on November 8, 2022. That sanctions status was part of the known environment on May 26, 2023; it did not resolve the technical distinction between governance contracts and the protocol’s other smart contracts.
The attacker’s identity and motive remained unverified. Interpretations that the reversal represented remorse, market manipulation or an attempted bounty arrangement were speculation, not established facts.
What remained to verify
The next decisive record was the execution transaction: whether Proposal 21 actually ran, whether the attacker-created voting balances became zero and whether the Governance Vault’s token accounting was restored as tested. Separate tracing would be required to determine the disposition of withdrawn TORN or exchanged assets. The May 26 result established only that the restoration proposal passed its vote and became eligible for the next governance step.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

