Skip to main content
AVOID.NET

Fact-check findings

What an automated fact-checker found when it re-read Crypto Whale — $25.6M Repeat Phishing Drain (August 2026) against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed 3partially supported 3confirmed 193 corrections pending · 0 applied

disputed

3 claims

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #16[disputed][awaiting moderator]in section: Prior Incident — September 2023 Attack and Partial Recovery
    “representing roughly 90% partial restitution — an unusual outcome in phishing cases.”
    reviewerThe July 2024 return of ~$9.3 million in DAI represented roughly 90% partial restitution of the 2023 loss.The page's own cited 2026 sources say ~90%, but the original contemporaneous reporting on the return (Cointelegraph, July 2024) calculated the $9.3M return as approximately 38% of the theft's value using the theft-day valuation. 9.3/24.23 = ~38.4%, matching Cointelegraph's math, not the 90% figure repeated in later secondary articles.
    Proposed correction (not yet applied)
    representing roughly 38% partial restitution — an unusual outcome in phishing cases.
  2. #17[disputed][awaiting moderator]in the timeline
    “representing roughly 90% restitution of the 2023 loss.”
    reviewerThe July 2024 DAI return represented roughly 90% restitution of the 2023 loss (timeline entry).Same underlying error as the Prior Incident section; grouped under the same defect.
    Proposed correction (not yet applied)
    representing roughly 38% restitution of the 2023 loss.
  3. #18[disputed][awaiting moderator]in the timeline
    “2024-07-01”
    reviewerThe 2024 DAI return occurred on 2024-07-01.The stored date_original field asserts a specific day (July 1) that does not correspond to either of the two documented transfer dates (July 8 and July 13); July 8 is the date of the first transfer.
    Proposed correction (not yet applied)
    2024-07-08

partially supported

3 claims

The cited evidence supports part of the claim but not all of it.

  1. #13[partially supported][awaiting moderator]in section: Prior Incident — September 2023 Attack and Partial Recovery
    “The attacker distributed stolen funds between two addresses (0x693b72 and 0x4c10a4) and moved a portion through the FixedFloat exchange.”
    reviewerThe 2023 attacker distributed funds between two addresses and moved a portion through FixedFloat.The FixedFloat detail is accurate but incomplete; the cited reporting names two additional laundering channels the page does not mention.
  2. #14[partially supported][awaiting moderator]in the timeline
    “Funds moved to attacker addresses 0x693b72 and 0x4c10a4, with a portion routed through FixedFloat.”
    reviewerFunds moved to attacker addresses 0x693b72/0x4c10a4 with a portion routed through FixedFloat (timeline entry).Same underlying incomplete-routing issue as the Prior Incident section; grouped together.
  3. #15[partially supported][awaiting moderator]in section: Fund Disposition and On-Chain Tracing
    “the attacker moved a portion of stolen funds through FixedFloat exchange”
    reviewerIn the 2023 incident, the attacker moved a portion of stolen funds through FixedFloat exchange (Fund Disposition section).Third occurrence of the same incomplete laundering-route description.

confirmed

19 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in section: Incident Overview — August 12, 2026
    “On August 12, 2026, on-chain security firm PeckShield reported that an unidentified crypto whale lost approximately $25.6 million in a phishing attack on an Ethereum wallet.”
    reviewerOn August 12, 2026, PeckShield reported an unidentified crypto whale lost approximately $25.6 million in a phishing attack on an Ethereum wallet.Directly corroborated by the cited article and consistent with other outlets covering the same event.
  2. #2[confirmed][no action needed]in section: Incident Overview — August 12, 2026
    “The stolen assets comprised wrapped Bitcoin (aWBTC, approximately $6.3 million; WBTC direct holdings, approximately $4.7 million), cbBTC, Lido DAO (LDO), USDS stablecoin, and Curve DAO Token (CRV).”
    reviewerThe stolen assets comprised aWBTC (~$6.3M), WBTC (~$4.7M), cbBTC, LDO, USDS, and CRV.Figures match the source exactly.
  3. #3[confirmed][no action needed]in section: Incident Overview — August 12, 2026
    “Following the theft, the attacker consolidated the proceeds by swapping all seized tokens into approximately 20 million DAI and 3,000 ETH.”
    reviewerThe attacker consolidated proceeds into approximately 20 million DAI and 3,000 ETH.Confirmed.
  4. #4[confirmed][no action needed]in section: Incident Overview — August 12, 2026
    “PeckShield traced these proceeds to four separate wallet addresses.”
    reviewerPeckShield traced the proceeds to four separate wallet addresses.Confirmed verbatim by cited source.
  5. #5[confirmed][no action needed]in section: Incident Overview — August 12, 2026
    “On-chain investigator Specter identified an attacker address abbreviated as 0x8fEB...F95Ae as responsible for the 2026 theft.”
    reviewerOn-chain investigator Specter identified attacker address abbreviated as 0x8fEB...F95Ae.Confirmed.
  6. #6[confirmed][no action needed]in section: Incident Overview — August 12, 2026
    “No funds from this incident had been returned as of reporting.”
    reviewerNo funds from the 2026 incident had been returned as of reporting.Confirmed.
  7. #7[confirmed][no action needed]in section: Incident Overview — August 12, 2026
    “The attack occurred during a week (August 9–15, 2026) in which confirmed crypto losses across multiple separate incidents exceeded $37 million in total.”
    reviewerThe attack occurred during a week (Aug 9-15, 2026) with over $37 million in confirmed crypto losses.Confirmed; arithmetic checks out against the individual incidents listed.
  8. #8[confirmed][no action needed]in section: Phishing Methodology
    “The 2023 attack on the same wallet was executed via malicious token approval phishing, specifically exploiting the ERC-20 increaseAllowance function.”
    reviewerThe 2023 attack exploited the ERC-20 increaseAllowance function (approval phishing).Confirmed via secondary retrieval since direct fetch was blocked; content matches page's description.
  9. #9[confirmed][no action needed]in section: Phishing Methodology
    “The malicious address involved in 2023 had previously been flagged and was associated with multiple crypto phishing websites.”
    reviewerThe malicious address from 2023 had previously been flagged and was associated with multiple phishing websites.Confirmed.
  10. #10[confirmed][no action needed]in section: Phishing Methodology
    “Scam Sniffer attributed the 2023 theft to the phishing kit it tracks as MS Drainer.”
    reviewerScam Sniffer attributed the 2023 theft to the phishing kit it tracks as MS Drainer.Confirmed via independent search corroboration.
  11. #11[confirmed][no action needed]in section: Prior Incident — September 2023 Attack and Partial Recovery
    “On September 6, 2023, the same Ethereum wallet (partially identified in reporting as address beginning with 0x13e382) lost approximately $24.23 million to a phishing attack.”
    reviewerOn September 6, 2023, the same wallet (0x13e382...) lost approximately $24.23 million.Confirmed by multiple independent outlets.
  12. #12[confirmed][no action needed]in section: Prior Incident — September 2023 Attack and Partial Recovery
    “The stolen assets at that time consisted of approximately 4,851 Rocket Pool ETH (rETH) and 9,579.2 Lido Staked ETH (stETH), which the attacker swapped for approximately 13,785 ETH and 1.64 million DAI.”
    reviewerThe stolen assets were ~4,851 rETH and ~9,579.2 stETH, swapped for ~13,785 ETH and 1.64 million DAI.Confirmed.
  13. #19[confirmed][no action needed]in section: Prior Incident — September 2023 Attack and Partial Recovery
    “The victim's on-chain profile at the time of the 2023 attack included significant DeFi activity: WBTC/USDT liquidity provision on Uniswap V3 exceeding $1.6 million, and engagement with Aave, 1inch, Curve, and other protocols.”
    reviewerThe victim's on-chain profile included Uniswap V3 WBTC/USDT LP >$1.6M and engagement with Aave, 1inch, Curve.Confirmed; page's list is a subset of the source's fuller list (OMG and EOS omitted), which is a reasonable abbreviation rather than a mischaracterization.
  14. #20[confirmed][no action needed]in section: Repeat-Targeting Pattern
    “Combined losses across both incidents total approximately $49.8 million.”
    reviewerCombined losses across both incidents total approximately $49.8 million.Confirmed and arithmetically consistent.
  15. #21[confirmed][no action needed]in section: Repeat-Targeting Pattern
    “Reporting from CryptoAdventure cites on-chain investigator Specter as having identified the repeat pattern.”
    reviewerReporting from CryptoAdventure cites on-chain investigator Specter as having identified the repeat pattern.Confirmed.
  16. #22[confirmed][no action needed]in section: Repeat-Targeting Pattern
    “No law enforcement action or asset freeze has been reported in connection with either incident.”
    reviewerNo law enforcement action or asset freeze has been reported in connection with either incident.A negative claim; confirmed only in the sense that no consulted source contradicts it.
  17. #23[confirmed][no action needed]in section: Broader 2026 Threat Context
    “That same week included a $7.9 million breach of the Coinsbuy exchange (August 9), a $3.2 million unauthorized mint on Harmony Protocol (August 11–12), a $200,000 Coreum-XRPL bridge drain (August 9), and a $136,000 flash loan exploit on the USM Protocol (August 10).”
    reviewerThat week included a $7.9M Coinsbuy breach (Aug 9), $3.2M Harmony Protocol mint (Aug 11-12), $200K Coreum-XRPL drain (Aug 9), and $136K USM Protocol exploit (Aug 10).First three sub-incidents independently corroborated; the USM Protocol $136K figure could only be traced back to the page's own primary cited source (Crypto Times) and was not independently found in other outlets, but nothing contradicts it.
  18. #24[confirmed][no action needed]in section: Broader 2026 Threat Context
    “CertiK's report for H1 2026 noted that Web3 losses reached $1.31 billion across 344 incidents in the first half of the year, with wallet compromises and infrastructure breaches identified as the primary attack surface.”
    reviewerCertiK's H1 2026 report found Web3 losses reached $1.31 billion across 344 incidents.Confirmed against CertiK's own published Hack3D H1 2026 figures.
  19. #25[confirmed][no action needed]in section: Broader 2026 Threat Context
    “AMBCrypto reported that 2026 cumulative on-chain exploit losses had exceeded $1.2 billion as of mid-August, including approximately $107 million linked to physical coercion attacks, though the whale phishing incident is distinct from that category.”
    reviewerAMBCrypto reported 2026 cumulative on-chain exploit losses exceeded $1.2 billion, including ~$107 million from physical coercion attacks, distinct from the whale phishing incident.Confirmed verbatim against the cited article.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.