A crypto whale has lost roughly $25 million in 15 minutes, three years after the same wallet was drained of about $24 million in a separate phishing attack.
- A crypto whale has lost roughly $25 million in 15 minutes, three years after the same wallet was drained of about $24 million in a separate phishing attack.
- PeckShield, revealed the largest holdings taken included about $6.3 million in aWBTC, $5.1 million in DAI, $4.7 million in WBTC and about $2.6 million in ETH, along with smaller amounts of other tokens.
- The Blockchain Trail Is Still Visible The stolen funds remain traceable through public blockchain transactions.
Two wallets belonging to the same victim were emptied on Aug. 12, with DAI, WBTC, aUSDC, LDO, sUSDe, ETH and other assets transferred to a fresh address in a rapid series of transactions, according to Scam Sniffer and on-chain analysts. Lookonchain put the latest loss at about $25 million, while BeInCrypto reported $25.6 million.
The latest drain is suspected to have involved a private-key compromise rather than the malicious approval used in the earlier attack. Combined, the two incidents have cost the same wallet owner nearly $50 million.
Two Wallets Were Emptied In 15 Minutes
Scam Sniffer said the attacker drained two wallets belonging to the same victim and moved the assets to a newly created address.
“Someone lost ~$25M in a suspected private key compromise,” the security firm said. “2 wallets were emptied in 15 minutes.”
Have a development worth tracking?
Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.
→ Submit a Press ReleaseThe stolen assets included DAI, WBTC, aUSDC, LDO, sUSDe and native ETH, according to Scam Sniffer and subsequent blockchain analysis.
The attacker then consolidated the holdings into a smaller number of assets.
About 20 million DAI and 3,000 ETH were created through the swaps, with the DAI later moved to another address while the ETH remained at the consolidation wallet, Lookonchain reported.
PeckShield, revealed the largest holdings taken included about $6.3 million in aWBTC, $5.1 million in DAI, $4.7 million in WBTC and about $2.6 million in ETH, along with smaller amounts of other tokens.
The Same Victim Lost $24M In 2023
The wallet had already appeared in crypto-security records after a much earlier theft.
In September 2023, the same wallet lost about $24.2 million in 4,851 rETH and 9,579.2 stETH after signing a malicious increaseAllowance transaction, according to historical on-chain reporting.
That attack worked through a phishing-linked token approval. The attacker later returned roughly 90% of the stolen funds. The current incident has a different suspected entry point.
Security researchers have described it as a possible private-key leak or compromise, although no public investigation has established exactly how the attacker obtained control of the wallets.
Second Attack Took A Different Route
The contrast between the two incidents is important because neither appears to have followed the same mechanism.
In 2023, the victim approved a malicious transaction that gave an attacker permission to move assets.
This time, the wallets were emptied rapidly without any publicly reported indication that the victim was tricked into approving each transfer.
A private-key compromise can occur through several routes, including malware, exposed credentials, compromised devices or leaked wallet secrets. There is currently no public evidence showing which of those possibilities applies here.
The suspected method should therefore not be treated as confirmed.
What is established on-chain is the result: two wallets belonging to the same victim were drained and the assets were consolidated within a short period.
Nearly $50M Lost Across Two Attacks
The two incidents now represent nearly $50 million in reported losses connected to the same wallet owner.
The 2023 phishing theft was estimated at about $24.2 million, while the latest drain was estimated at about $25 million to $25.6 million depending on the valuation used.
The repeat loss is unusual not simply because of the amount involved, but because the victim had already survived one major wallet theft.
Most of the first loss was eventually returned, leaving a rare recovery story behind the earlier incident.
Three years later, another attacker appears to have found a different path into the same victim’s wallet holdings.
The Blockchain Trail Is Still Visible
The stolen funds remain traceable through public blockchain transactions.
Lookonchain reported that about 20 million DAI was moved to another address, while roughly 3,000 ETH remained at the consolidation address at the time of its report.
The stolen assets had been distributed across four addresses after the initial drain.
That does not mean the victim will recover the funds.
Blockchain visibility allows analysts to monitor where assets move, but recovery depends on whether the funds can be frozen, intercepted or returned before they are converted or moved into harder-to-trace channels.
The earlier attacker voluntarily returned most of the 2023 proceeds.
There is no indication yet that the latest attacker intends to do the same.
Activate Terminal Layer
Structural analysis of the systems, pressures, and stakeholders behind this story.





