Crypto Whale Repeat Phishing Drain — August 2026
Summary
On August 12, 2026, an unidentified Ethereum whale lost approximately $25.6 million in a malicious token approval phishing attack — the second major drain on the same wallet, which had previously lost $24.2 million in a comparable attack in September 2023. On-chain security firm PeckShield traced the stolen proceeds, consolidated into approximately 20 million DAI and 3,000 ETH, to four attacker-controlled addresses. Unlike the 2023 incident where the attacker voluntarily returned roughly 90% of funds, no restitution has occurred or been announced as of August 16, 2026.
Connected Entities
1 entities · 10 linked investigationsTimeline(4 events)
2023-09-06
The victim wallet (address prefix 0x13e382) lost approximately $24.23 million in rETH and stETH after signing malicious 'increaseAllowance' transactions granting the attacker token spending approval. Stolen assets were converted to approximately 13,785 ETH and 1.64 million DAI.
CryptoSlate2023-09
The 2023 attacker voluntarily returned approximately 90% of the stolen funds — roughly $21.8 million — to the victim wallet.
BeInCrypto2026-08-12
The same wallet was drained of approximately $25.6 million in a second malicious token approval phishing attack. Stolen assets included aWBTC, WBTC, DAI, ETH, cbBTC, USDS, LDO, and CRV. The attacker consolidated proceeds into approximately 20 million DAI and 3,000 ETH across four addresses. On-chain investigator Specter identified attacker address 0x8fEB...F95Ae.
PeckShield / CryptoTimes2026-08-16
As of this date, no funds from the August 2026 attack have been returned. No law enforcement action has been announced. Total confirmed crypto losses for the week of August 9–15 exceeded $37 million across multiple incidents.
CryptoTimesDecision Log
- #1publish⛓ pending8/16/2026, 12:07:49 PMhash: A5i5mzr9CwHuNikMLUgwP7TFeCPhHxgAR2fEF9PnK7E9
8 of 11 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/16/2026, 12:07:42 PM
last updated: 8/16/2026, 5:50:13 PM
avoid.net — verified advice for a post-truth world