Crypto Wallet Attack Drains Over $4.3 Million Across Ethereum, Tron, and Bitcoin
Key Takeaways
- •An unidentified holder lost more than $4.3 million in cryptocurrency through an apparent private key compromise affecting Ethereum, EVM-compatible chains, Tron, and Bitcoin.
- •On-chain analyst Specter identified more than 145 drained Ethereum addresses, many of which held USDC that the attacker converted into ETH.
- •Bitcoin was stolen from at least five additional addresses, and the cross-chain movement of the funds makes tracking more difficult.
- •The attacker was still moving stolen funds as of Sept. 22, so the total loss could increase as further transactions occur.
- •Industry data shows infrastructure attacks, including private key and seed phrase compromises, accounted for a large share of cryptocurrency theft losses in 2025.

An unidentified cryptocurrency holder has lost more than $4.3 million in what appears to be a private key compromise that exposed funds across multiple blockchain networks. The attack affected Ethereum and other EVM-compatible chains, Tron, and Bitcoin, and the attacker was still moving stolen funds as of Sept. 22.
The incident highlights the risks surrounding key security, as attackers increasingly target wallet access itself rather than exploiting vulnerabilities in smart-contract code. A private key is the fundamental control mechanism for a self-custody wallet, and whoever obtains it can authorize outgoing transactions without any further approval step. Recent industry research has identified compromised private keys and wallet infrastructure as a major source of cryptocurrency theft.
More Than 145 Ethereum Addresses Drained
On-chain analyst Specter identified activity involving more than 145 Ethereum addresses. Many of the affected wallets held USDC, a dollar-pegged stablecoin commonly used to store value on-chain, which the attacker converted into ETH before moving the assets across chains.
The attacker then consolidated those proceeds with Bitcoin taken from at least five additional addresses. This cross-chain movement makes the theft harder to track, since the funds do not remain on a single blockchain.
The reported losses include:
- More than $4.3 million in cryptocurrency
- Over 145 Ethereum addresses affected
- USDC among the assets held by many targeted wallets
- Bitcoin stolen from at least five addresses
- Funds converted to ETH and moved across networks
The attacker remains active, meaning the reported loss could increase as additional transactions occur.
Private Key Security Under Scrutiny
The incident also underscores the consequences of losing control of a private key. Unlike many smart-contract exploits, a compromised key can allow an attacker to authorize transactions directly from a wallet. Because public blockchains treat transfers signed with a valid key as legitimate, there is no protocol-level mechanism to reverse confirmed transactions.
Industry data shows that infrastructure attacks, including private key and seed phrase compromises, accounted for a large share of cryptocurrency theft losses in 2025. That trend has increased attention on wallet security, access controls, and custody practices.
For affected users, investigators will likely continue tracing the stolen assets across chains and monitoring the destinations where the attacker consolidates funds. The final value of the theft may remain uncertain until the activity stops and on-chain analysis is complete.
Source: CryptoMeter News