BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

Phishing attack drains $25.6 million from crypto whale, second loss tied to same wallet

A crypto whale suffered a $25.6 million phishing attack on August 12, making it the second major breach affecting this particular address in less than a year. On-chain analyst Specter reporte

AnonymousCryptoCompass newsroom
August 13, 2026
4 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for altcoins coverage.

A crypto whale suffered a $25.6 million phishing attack on August 12, making it the second major breach affecting this particular address in less than a year. On-chain analyst Specter reported that the attacker exchanged the stolen assets for Dai (DAI) and Ethereum (ETH) shortly after seizing the funds.

Details of the Recent Attack

The unidentified victim’s wallet lost a range of tokens, including Wrapped Bitcoin (WBTC), Coinbase-wrapped Bitcoin (cbBTC), Lido DAO (LDO), StableUSD (USDS), and Curve DAO Token (CRV). The attacker swiftly swapped the holdings for 20 million DAI and 3,000 ETH, converting the assets to major cryptocurrencies to facilitate easier movement and potential laundering.

According to blockchain security firm PeckShield, the most significant individual loss involved aWBTC, valued at $6.3 million. Additional losses included $5.1 million in DAI and $4.7 million in Wrapped Bitcoin. In total, the attacker drained approximately $2.6 million in ETH along with several other tokens in smaller amounts.

PeckShield tracked the stolen assets to four new wallet addresses, which now hold the proceeds of the breach from the whale’s account.

No funds from this most recent attack have been returned. This outcome sharply contrasts with the previous incident tied to the same wallet, where the attacker restored a substantial portion of the stolen assets.

Review of the 2023 Breach

In September 2023, the same address fell victim to a phishing exploit facilitated by malicious token approvals, according to analyst Specter. That breach resulted in the loss of $24.2 million, including 4,851 Rocket Pool ETH and 9,579.2 Lido Staked ETH. After swapping these tokens, the attacker obtained approximately 13,785 ETH and 1.64 million DAI.

Unlike the current case, nearly 90% of those funds were ultimately returned to the whale’s wallet. However, with the August 2024 attack, none of the $25.6 million has been recovered. The amount lost in the most recent incident exceeds the previous one by almost $1.4 million, not accounting for the refunded assets in 2023.

Attack DateTotal StolenFunds ReturnedMain Assets AffectedSeptember 2023$24.2 million~$21.8 millionRPL, stETH, ETH, DAIAugust 2024$25.6 million$0aWBTC, DAI, WBTC, ETH

Broader Crypto Security Landscape in August

August witnessed heightened activity in crypto-related security incidents. Research platform DefiLlama recorded 13 security breaches throughout the month, resulting in reported losses exceeding $12 million. The single largest event prior to the whale’s breach involved payment services company Coinsbuy, which lost $7.9 million on August 9 after its wallets were compromised on the Ethereum and TRON networks.

The August $12 million figure from DefiLlama does not account for the whale’s $25.6 million loss, raising the month’s total significantly higher than initially reported. Other incidents during this period included losses by platforms and projects such as RRWallet ($2 million), MOKE ($907,000), LOOPSDAO ($696,000), and RISEx ($673,000). None of these individual amounts came close to the scale of the Coinsbuy or whale attacks.

IncidentAsset(s) LostReported Loss ($)Whale (August 2024)Multiple25,600,000CoinsbuyETH, TRON7,900,000RRWalletUnspecified2,000,000MOKEUnspecified907,000LOOPSDAOUnspecified696,000RISExUnspecified673,000

Coinsbuy, a digital payment provider, was particularly impacted as attackers moved quickly to launder the proceeds into privacy-focused cryptocurrencies. DefiLlama monitors and aggregates data on decentralized finance platforms, providing real-time updates on hacks and exploits in the sector.

Mini dictionary: Malicious token approval, a vulnerability where a victim unknowingly grants a third party unlimited spending access to their tokens, allowing attackers to drain assets once approval is obtained.

Security Precautions and Advice

Analysts have highlighted the importance of responding quickly if a wallet is suspected of compromise. Crypto Jargon advised users to revoke all malicious token approvals and transfer remaining assets to a new wallet to prevent further losses.

Repeated phishing attacks underscore an urgent need for users to revoke compromised token approvals and secure funds in new wallets as soon as possible, according to analysts.

The post Phishing attack drains $25.6 million from crypto whale, second loss tied to same wallet appeared first on COINTURK NEWS.