Unidentified Crypto Whale — $25.6M Repeated Phishing Drain
Summary
On August 12, 2026, an unidentified crypto whale (victim wallet partially identified as beginning 0x13e382) lost approximately $25.6 million in a phishing or private key compromise attack — the second major drain from the same wallet, which had previously lost $24.23 million in September 2023. Unlike the 2023 incident, in which the attacker returned approximately 90% of stolen funds, no funds have been returned from the August 2026 drain as of the date of this investigation. The attacker, whose address was partially identified as 0x8fEB...F95Ae by on-chain investigator Specter, converted stolen assets into approximately 20 million DAI and 3,000 ETH distributed across four addresses.
Connected Entities
1 entities · 10 linked investigationsTimeline(8 events)
2023-05-21
Attacker wallet 0x4c10a4 — later linked to the September 2023 phishing theft — became active and was associated with multiple phishing websites.
CryptoSlate2023-09-06
$24.23M drained from victim wallet (partially identified as 0x13e382) via malicious 'increaseAllowance' token approval transactions. Stolen assets: 4,851 rETH ($8.58M) and 9,579 stETH ($15.63M). Scam Sniffer and CryptoSlate reported the incident.
CryptoSlate / CryptoRank2024-07-06
The 2023 attacker began returning stolen funds, approximately 10 months after the original theft, transferring approximately $9.3 million in DAI to the victim in two initial transactions.
CryptoRank2024-07-15
More than $10 million had been returned to the 2023 victim by this date, ultimately totaling approximately 90% (~$21.8M) of the stolen amount.
CryptoRank2026-08-01
Blockaid published report finding $1.1 billion stolen across 212 crypto incidents in H1 2026; private key misuse accounted for approximately $790 million.
AMBCrypto2026-08-12
Approximately $25.6M drained from the same whale wallet in a second major attack. Stolen assets — WBTC, cbBTC, LDO, USDS, CRV (including aWBTC) — converted by attacker into approximately 20 million DAI and 3,000 ETH across four addresses. Attacker address partially identified as 0x8fEB...F95Ae.
BeInCrypto / PeckShield / Specter (on-chain)2026-08-13
Incident publicly reported by multiple crypto news outlets. PeckShield confirmed asset tracking. CertiK independently verified approximately $25M leaving the victim address. No funds returned; no law enforcement action announced.
Tron Weekly / Crypto Economy / AMBCrypto2026-08-14
As of this date, no funds from the August 2026 drain have been publicly reported as returned. No regulatory action or law enforcement referral has been announced.
AVOID.NET investigation (current status)Decision Log
- #1publish⛓ pending8/14/2026, 5:09:15 PMhash: 4m5whA5to3VZFXxGmCPzN2K49nzxL77nWGgNC4pKS2C3
0 of 12 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/14/2026, 5:09:06 PM
last updated: 8/14/2026, 5:09:15 PM
avoid.net — verified advice for a post-truth world