Skip to main content
Sign in

Unidentified Crypto Whale — $25.6M Repeated Phishing Drain

avoid.net/unidentified-crypto-whale-25-6m-repeated-phishing-drain0/100·72% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Summary

On August 12, 2026, an unidentified crypto whale (victim wallet partially identified as beginning 0x13e382) lost approximately $25.6 million in a phishing or private key compromise attack — the second major drain from the same wallet, which had previously lost $24.23 million in September 2023. Unlike the 2023 incident, in which the attacker returned approximately 90% of stolen funds, no funds have been returned from the August 2026 drain as of the date of this investigation. The attacker, whose address was partially identified as 0x8fEB...F95Ae by on-chain investigator Specter, converted stolen assets into approximately 20 million DAI and 3,000 ETH distributed across four addresses.

Have evidence about Unidentified Crypto Whale — $25.6M Repeated Phishing Drain?

Timeline(8 events)

2023-05-21

Attacker wallet 0x4c10a4 — later linked to the September 2023 phishing theft — became active and was associated with multiple phishing websites.

CryptoSlate

2023-09-06

$24.23M drained from victim wallet (partially identified as 0x13e382) via malicious 'increaseAllowance' token approval transactions. Stolen assets: 4,851 rETH ($8.58M) and 9,579 stETH ($15.63M). Scam Sniffer and CryptoSlate reported the incident.

CryptoSlate / CryptoRank

2024-07-06

The 2023 attacker began returning stolen funds, approximately 10 months after the original theft, transferring approximately $9.3 million in DAI to the victim in two initial transactions.

CryptoRank

2024-07-15

More than $10 million had been returned to the 2023 victim by this date, ultimately totaling approximately 90% (~$21.8M) of the stolen amount.

CryptoRank

2026-08-01

Blockaid published report finding $1.1 billion stolen across 212 crypto incidents in H1 2026; private key misuse accounted for approximately $790 million.

AMBCrypto

2026-08-12

Approximately $25.6M drained from the same whale wallet in a second major attack. Stolen assets — WBTC, cbBTC, LDO, USDS, CRV (including aWBTC) — converted by attacker into approximately 20 million DAI and 3,000 ETH across four addresses. Attacker address partially identified as 0x8fEB...F95Ae.

BeInCrypto / PeckShield / Specter (on-chain)

2026-08-13

Incident publicly reported by multiple crypto news outlets. PeckShield confirmed asset tracking. CertiK independently verified approximately $25M leaving the victim address. No funds returned; no law enforcement action announced.

Tron Weekly / Crypto Economy / AMBCrypto

2026-08-14

As of this date, no funds from the August 2026 drain have been publicly reported as returned. No regulatory action or law enforcement referral has been announced.

AVOID.NET investigation (current status)
Provenance & Audit Trail

Decision Log

  • #1publish⛓ pending8/14/2026, 5:09:15 PM
    hash: 4m5whA5to3VZFXxGmCPzN2K49nzxL77nWGgNC4pKS2C3

0 of 12 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/14/2026, 5:09:06 PM

last updated: 8/14/2026, 5:09:15 PM

avoid.net — verified advice for a post-truth world