Crypto Incidents

Crypto Whale Drained of $25.6M Three Years After Previous $24M Attack

✶ The Main Takeaways
  • A crypto holder lost $25.6 million in a suspected private key compromise, highlighting the importance of securing private keys.
  • The same victim previously suffered a $24 million phishing attack, emphasizing the need for ongoing vigilance against security threats.
  • Users should regularly review and revoke permissions on their wallets to mitigate risks from approval phishing attacks.

An unidentified crypto holder lost roughly $25.6 million after two wallets were emptied within about 15 minutes, nearly three years after the same victim suffered a $24 million phishing attack.

Blockchain security service Scam Sniffer said the latest drain appeared to be a suspected private-key compromise. DAI, WBTC, aUSDC, LDO, sUSDe and native ETH were transferred from the victim’s wallets to a newly created address before the assets were consolidated. The cause has not been formally confirmed.

On-chain analyst Specter separately placed the loss at $25.6 million and identified the victim as the same holder hit in September 2023. PeckShield later traced the stolen assets and said the attacker had converted the haul into approximately 20 million DAI and 3,000 ETH, with the funds spread across four addresses.

A different failure mode from 2023

The earlier attack involved malicious token permissions rather than an apparent loss of signing control. In September 2023, the victim lost about 9,579 stETH and 4,851 rETH, worth $24.23 million at the time, after signing increaseAllowancetransactions that authorized an attacker to spend the tokens.

The stolen staking assets were subsequently exchanged for roughly 13,785 ETH and 1.64 million DAI. Scam Sniffer had identified the incident as an approval-phishing attack, while the malicious address had already been associated with phishing infrastructure.

That distinction is important in the latest case. Revoking malicious allowances can remove permissions granted during approval phishing, but it cannot secure a wallet if an attacker possesses the private key itself; assets instead need to be moved under a new key.

Researchers have not established how the suspected key exposure occurred, whether both affected wallets shared the same compromised credentials, or whether the attacker has any connection to the 2023 phisher. The on-chain evidence currently links the two incidents through the victim, not the culprit.

Mandy Williams
Written by

Mandy Williams

Mandy Williams is a full-time cryptocurrency reporter. Having entered the blockchain space in early 2017, she leverages a diverse background in multi-niche writing and content strategy to cover the evolving digital asset market. Mandy is dedicated to breaking down complex Web3 concepts and spreading mainstream awareness of blockchain technology.