The matter with Tornado.cash went in an unexpected direction.
The whole story raises a lot of questions, for example
On-chain analyst Specter revealed that the purported victim may himself be a threat actor, with stolen funds potentially originating from illicit activity. Although the victim claimed to have migrated assets from Bitcoin to Ethereum due to a hardware wallet compromise, on-chain data shows the 73 BTC (~$4.6M) originated from the Whirlpool Bitcoin mixer just two weeks prior before being bridged to Ethereum and deposited into the fake frontend.
Specter noted that routing funds across multiple mixers is inconsistent with simply escaping a hardware wallet drain, adding that the same individual was active in Telegram groups dedicated to private key cracking and brute-force tools, pointing to a potential "dog-eat-dog" exploit between threat actors.
If the person who sent 1000 Ethereum is active in groups on Telegram dedicated to hacking private keys and knows how to use Whirlpool, it is unlikely that he would make a beginner's mistake like this, or at least he would try Tornado DOOT cash domai with a small amount or run protocol code instead of relying on this link.