NewsCryptoEthereum Whale Loses $25.6M in Second Major Phishing Attack

Ethereum Whale Loses $25.6M in Second Major Phishing Attack

Author: Crypto Adventure·

Key Takeaways

  • Onchain investigator Specter traced the latest theft to attacker address 0x8fEB...F95Ae.
  • The victim lost WBTC, cbBTC, LDO, USDS and CRV, and the attacker later converted them into DAI and ETH.
  • The same wallet was previously drained in September 2023 after a malicious increaseAllowance approval, with about $24.2 million taken.
  • Roughly 90% of the 2023 stolen assets were eventually returned.
  • CertiK said about $25 million left the same victim address, and no public recovery agreement has been disclosed for the latest attack.
Ethereum Whale Loses $25.6M in Second Major Phishing Attack

An Ethereum whale has lost approximately $25.6 million in a phishing attack, marking the second major drain from the same wallet in less than three years.

The victim lost WBTC, cbBTC, LDO, USDS and CRV before the stolen assets were converted into DAI and ETH. Onchain investigator Specter traced the theft to attacker address 0x8fEB...F95Ae .

The same whale was drained of roughly $24.2 million in September 2023 after signing a malicious token approval , although about 90% of those funds were later returned.

Attacker Converts Stolen Assets Into DAI And ETH

The drain removed assets spread across several major Ethereum tokens rather than a single position. WBTC and cbBTC provided Bitcoin exposure, while the wallet also held LDO, USDS and CRV.

The stolen tokens were subsequently swapped into DAI and ETH, consolidating the position after the theft. Converting diverse holdings into liquid base assets like ETH and stablecoins is a common post-exploitation step that simplifies movement of funds and complicates onchain tracing. No public indication of a return agreement or recovery has emerged from the latest attack.

CertiK independently traced approximately $25 million leaving the same victim address , identifying it as the wallet's second large drain since 2023.

The latest theft comes during another difficult period for wallet security. Thirty major crypto hacks generated $210.3 million in losses during July , while wallet-specific compromises have remained a major source of losses alongside protocol and bridge exploits.

Same Wallet Lost $24.2M In 2023

The victim was previously hit on September 7, 2023 after signing a malicious increaseAllowance transaction that granted an attacker permission to move its tokens. Token approval exploits are particularly dangerous because they delegate ongoing spending authority to an attacker address rather than executing a single transfer, meaning victims may not realize their wallet is compromised until assets are already moving.

That attack removed 9,579 stETH and 4,850 rETH, valued at roughly $24.2 million at the time. Scam Sniffer later listed the address among the largest phishing victims of 2023 , with the theft tied specifically to an Increase Allowance signature.

Around 90% of those assets were eventually returned by the 2023 attacker.

The two attacks have therefore removed roughly $49.8 million in gross value from the same wallet across separate incidents, although that figure should not be treated as the wallet's permanent net loss because most of the first theft was recovered.

Reusing A Compromised Wallet Can Leave Long-Term Exposure

The second drain differs from recent hardware-wallet failures such as the Coldcard attacks involving vulnerable seed generation . The 2023 loss involved a malicious onchain permission rather than predictable private keys.

A separate Ledger user lost more than $1 million after entering a recovery phrase into a phishing site , demonstrating another route attackers use to bypass wallet protections.

Wallets that have previously signed malicious approvals can retain hidden spending permissions unless those grants are actively revoked, which may explain how a wallet with a documented 2023 compromise remained a viable target. Approval-revocation tools such as Etherscan's token approval checker and third-party dashboards have become standard defensive measures as phishing campaigns continue targeting large holders across Ethereum and EVM-compatible chains.

The latest $25.6 million drain has not produced a disclosed recovery agreement. At the latest confirmed update, the attacker had converted the stolen WBTC, cbBTC, LDO, USDS and CRV into DAI and ETH.