Skip to main content
AVOID.NET

Crypto Whale Repeat Phishing — $25.6M Drain August 2026

avoid.net/crypto-whale-repeat-phishing-25-6m-drain-august-2026→0/100·72% conf.
[AI-DRAFTED · AWAITING FACT-CHECK]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·5NpCZr…7XyZ
last updated 2026-08-25

Summary

On August 12, 2026, an unidentified Ethereum whale lost approximately $25.6 million in WBTC, cbBTC, aWBTC, DAI, ETH, LDO, USDS, and CRV to a phishing attack that induced the victim to authorize malicious token-approval transactions. The same wallet had previously lost $24.2 million in a nearly identical phishing scheme in September 2023, of which approximately 90% was returned; no funds from the 2026 attack had been recovered as of mid-August 2026. The combined gross exposure across both incidents is approximately $49.8 million, making this one of the most consequential repeat-targeting cases in Ethereum's history.

Connected Entities

8 entities · 60 linked investigations
Organizations
Protocols
Tokens
♦Coinsbuy♦Harmony Protocol (2026 ONE Token Exploit and L1 Shutdown)♦Bitcoin62♦Crypto Whale Repeat Phishing — $25.6M Drain August 2026
Relationships
  • Crypto Whale Repeat Phishing — $25.6M Drain August 2026→mentioned with→Ethereum(80%)
  • Crypto Whale Repeat Phishing — $25.6M Drain August 2026→mentioned with→FixedFloat(75%)
  • Crypto Whale Repeat Phishing — $25.6M Drain August 2026→mentioned with→Harmony Bridge(70%)
  • Crypto Whale Repeat Phishing — $25.6M Drain August 2026→mentioned with→Bitcoin(65%)
  • Crypto Whale Repeat Phishing — $25.6M Drain August 2026→mentioned with→Coinsbuy(60%)
  • Harmony Bridge→mentioned with→Bitcoin(75%)
  • Harmony Bridge→mentioned with→Ethereum(80%)
  • Ethereum→mentioned with→Bitcoin(60%)
  • Rocket Pool→mentioned with→Ethereum(80%)
  • Coinsbuy→mentioned with→Ethereum(70%)
  • + 8 more
Have evidence about Crypto Whale Repeat Phishing — $25.6M Drain August 2026?

Timeline(7 events)

6 September 2023

The same Ethereum wallet (partial ID: 0x13e38) lost approximately $24.2 million in rETH and stETH after the victim signed malicious increaseAllowance transactions. The 2023 attacker swapped assets into approximately 13,785 ETH and 1.64 million DAI.

CoinPaper / CryptoSlate

September 2023

The 2023 attacker voluntarily returned approximately 90% of stolen funds — approximately $21.8 million — to the victim's wallet. Partial proceeds were traced to FixedFloat exchange.

CryptoPotato / Crypto.news

12 August 2026

The same Ethereum whale wallet was drained of $25.6 million in a second phishing attack. Stolen assets included aWBTC ($6.3M), DAI ($5.1M), WBTC ($4.7M), ETH ($2.6M), and smaller amounts of cbBTC, USDS, LDO, and CRV. On-chain analyst Specter flagged the drain; attacker address partial ID reported as 0x8fEB...F95Ae.

Crypto Times / Tron Weekly / Coin Turk

12 August 2026

PeckShield confirmed the attacker converted all stolen assets into approximately 20 million DAI and 3,000 ETH, distributed across four separate attacker-controlled addresses.

Tron Weekly / Crypto Adventure

13 August 2026

CertiK independently confirmed approximately $25 million in outflows from the victim address. Multiple crypto news outlets published coverage of the incident.

Crypto Adventure

15 August 2026

No funds from the 2026 attack had been returned as of mid-week. Weekly crypto losses for August 9–15, 2026 confirmed to exceed $37 million across multiple incidents.

Crypto Times

16 August 2026

Crypto Times and AMBCrypto publish comprehensive weekly security roundups contextualizing the whale drain within broader 2026 losses exceeding $1.2 billion year-to-date.

AMBCrypto
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (4 events). 13 of 13 cited source URLs have an Internet Archive snapshot.

Fact-checked 2026-09-0727 claims checked2 corrections pending0 applied⛓ anchoredSee findings →

model: claude-sonnet-4-6

generated: 8/18/2026, 12:14:30 PM

last updated: 8/25/2026, 8:14:47 AM

5 views

avoid.net — verified advice for a post-truth world