Crypto Whale Drained Of $25.6M In Second Major Phishing Attack
An Ethereum whale has lost approximately $25.6 million in a phishing attack, marking the second major drain from the same wallet in less than three years.
The victim lost WBTC, cbBTC, LDO, USDS and CRV before the stolen assets were converted into DAI and ETH. Onchain investigator Specter traced the theft to attacker address 0x8fEB...F95Ae.
The same whale was drained of roughly $24.2 million in September 2023 after signing a malicious token approval, although about 90% of those funds were later returned.
Attacker Converts Stolen Assets Into DAI And ETH
The drain removed assets spread across several major Ethereum tokens rather than a single position. WBTC and cbBTC provided Bitcoin exposure, while the wallet also held LDO, USDS and CRV.
The stolen tokens were subsequently swapped into DAI and ETH, consolidating the position after the theft. No public indication of a return agreement or recovery has emerged from the latest attack.
CertiK independently traced approximately $25 million leaving the same victim address, identifying it as the wallet’s second large drain since 2023.
The latest theft lands during another difficult period for wallet security. Thirty major crypto hacks generated $210.3 million in losses during July, while wallet-specific compromises have remained a major source of losses alongside protocol and bridge exploits.
Same Wallet Lost $24.2M In 2023
The victim was previously hit on September 7, 2023 after signing a malicious increaseAllowance transaction that granted an attacker permission to move its tokens.
That attack removed 9,579 stETH and 4,850 rETH, valued at roughly $24.2 million at the time. Scam Sniffer later listed the address among the largest phishing victims of 2023, with the theft tied specifically to an Increase Allowance signature.
Around 90% of those assets were eventually returned by the 2023 attacker.
The two attacks have therefore removed roughly $49.8 million in gross value from the same wallet across separate incidents, although that figure should not be treated as the wallet’s permanent net loss because most of the first theft was recovered.
Reusing Compromised Wallet Leaves Long-Term Exposure
The second drain differs from recent hardware-wallet failures such as the Coldcard attacks involving vulnerable seed generation. The 2023 loss involved a malicious onchain permission rather than predictable private keys.
A separate Ledger user lost more than $1 million after entering a recovery phrase into a phishing site, demonstrating another route attackers use to bypass wallet protections.
The latest $25.6 million drain has not produced a disclosed recovery agreement. The attacker had converted the stolen WBTC, cbBTC, LDO, USDS and CRV into DAI and ETH at the latest confirmed update.




Post Comment
You must be logged in to post a comment.