Crypto Whale Repeat Phishing Drain — August 2026
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·4cxHWB…rokbSummary
On August 12, 2026, an unidentified Ethereum whale lost approximately $25.6 million in a malicious token approval phishing attack — the second major drain on the same wallet, which had previously lost $24.2 million in a comparable attack in September 2023. On-chain security firm PeckShield traced the stolen proceeds, consolidated into approximately 20 million DAI and 3,000 ETH, to four attacker-controlled addresses. Unlike the 2023 incident where the attacker voluntarily returned roughly 90% of funds, no restitution has occurred or been announced as of August 16, 2026.
Connected Entities
1 entities · 10 linked investigationsTimeline(4 events)
6 September 2023
The victim wallet (address prefix 0x13e382) lost approximately $24.23 million in rETH and stETH after signing malicious 'increaseAllowance' transactions granting the attacker token spending approval. Stolen assets were converted to approximately 13,785 ETH and 1.64 million DAI.
CryptoSlateSeptember 2023
The 2023 attacker voluntarily returned approximately 90% of the stolen funds — roughly $21.8 million — to the victim wallet.
BeInCrypto12 August 2026
The same wallet was drained of approximately $25.6 million in a second malicious token approval phishing attack. Stolen assets included aWBTC, WBTC, DAI, ETH, cbBTC, USDS, LDO, and CRV. The attacker consolidated proceeds into approximately 20 million DAI and 3,000 ETH across four addresses. On-chain investigator Specter identified attacker address 0x8fEB...F95Ae.
PeckShield / CryptoTimes16 August 2026
As of this date, no funds from the August 2026 attack have been returned. No law enforcement action has been announced. Total confirmed crypto losses for the week of August 9–15 exceeded $37 million across multiple incidents.
CryptoTimesDecision Log
- hash: 8vZrpwPzn7sdREePQ5FAh3BNRuqXXvRh4asqYwyCRHyr
- hash: BiHMgxKSMpwzSqkxRyib66p4aN1fkzPJAtHyR4B5zqwE
- hash: A5i5mzr9CwHuNikMLUgwP7TFeCPhHxgAR2fEF9PnK7E9
This investigation is cryptographically anchored to the Solana blockchain (3 events). 10 of 11 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/16/2026, 12:07:42 PM
last updated: 8/25/2026, 1:14:46 PM
5 viewsavoid.net — verified advice for a post-truth world