← Crypto Whale Repeat Phishing Drain — August 20261 decision on this page
Audit log
Every state-changing event for Crypto Whale Repeat Phishing Drain — August 2026: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-16 12:07:49ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
A5i5mzr9CwHu…F9PnK7E9sha256 → base58
verifying row…canonical bytes (15593 B) ▸
{"actor":"system:backfill","investigation_id":"fa0a4874-e9e8-4965-92ec-c07fd1912d5d","kind":"publish","page_slug":"crypto-whale-repeat-phishing-drain-august-2026","published_at":"2026-08-16T12:07:49.263Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Crypto Whale Repeat Phishing Drain — August 2026","sections":[{"content":"On August 12, 2026, an unidentified cryptocurrency whale suffered a phishing-induced token approval drain that resulted in the loss of approximately $25.6 million in mixed assets. According to reporting by PeckShield and on-chain investigator Specter, the victim wallet was compromised through a malicious token approval — a mechanism in which the victim is induced to sign a transaction granting an attacker unlimited spending access over specified token balances. The stolen assets included aWBTC ($6.3 million), WBTC ($4.7 million), DAI ($5.1 million), ETH ($2.6 million), and smaller positions in cbBTC, USDS, LDO (Lido DAO), and CRV (Curve DAO). The attacker rapidly swapped all holdings into approximately 20 million DAI and 3,000 ETH, then distributed those proceeds across four newly created wallet addresses to hinder tracing and recovery. Specter identified the primary attacker-linked address as 0x8fEB...F95Ae. CertiK independently confirmed approximately $25 million leaving the victim address. As of August 16, 2026, no funds have been returned and no recovery pathway has been publicly identified.","heading":"The August 2026 Attack","severity":"critical","sources":[{"credibility":2,"name":"Phishing Attack Drains Crypto Whale Wallet Of Another $25.6M — Tron Weekly","type":"news_article","url":"https://www.tronweekly.com/phishing-attack-drains-crypto-whale-wallet/"},{"credibility":2,"name":"Crypto Whale Drained Of $25.6M In Second Major Phishing Attack — CryptoAdventure","type":"news_article","url":"https://cryptoadventure.com/crypto-whale-drained-of-25-6m-in-second-major-phishing-attack/"},{"credibility":2,"name":"PeckShield reports $25.6 million crypto theft, 2026 losses hit $1.65 billion — CoinTurk","type":"news_article","url":"https://en.coin-turk.com/peckshield-reports-25-6-million-crypto-theft-2026-losses-hit-1-65-billion/"},{"credibility":2,"name":"Crypto Whale Loses $25.6 Million 2 Years After $24 Million Phishing Attack — BeInCrypto","type":"news_article","url":"https://beincrypto.com/crypto-whale-25-million-wallet-drain/"}]},{"content":"The same wallet, partially identified as beginning with 0x13e382, was the victim of a prior phishing attack on or around September 6, 2023, in which approximately $24.23 million in liquid-staked Ethereum was stolen. That attack involved 4,851 rETH (valued at approximately $8.58 million) and 9,579 stETH (valued at approximately $15.63 million). According to security researchers including Scam Sniffer, the victim had unknowingly signed 'increaseAllowance' transactions, granting the attacker permission to transfer assets. The attacker converted the stolen assets into approximately 13,785 ETH and 1.64 million DAI, with funds moving to addresses 0x693b72 and 0x4c10a4, and some assets routed through the FixedFloat exchange. Notably, the 2023 attacker subsequently returned approximately 90% of the stolen funds — roughly $21.8 million — in what was described by security researchers as one of the largest individual phishing losses in crypto history at the time. The 2026 attacker has made no comparable offer as of August 16, 2026.","heading":"Prior Incident: September 2023 Drain on the Same Wallet","severity":"high","sources":[{"credibility":2,"name":"Crypto whale loses over $24M staked Ethereum to phishing — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/crypto-whale-loses-over-24m-staked-ethereum-to-phishing-as-verified-x-scams-surge/"},{"credibility":2,"name":"Phishing scammer steals over $24 million from a crypto whale — CoinPaper","type":"news_article","url":"https://coinpaper.com/2264/crypto-whale-loses-over-24-million-in-a-phishing-scam"},{"credibility":2,"name":"High-Profile Whale Loses Over $24M in Crypto Phishing Attack — CryptoPotato","type":"news_article","url":"https://cryptopotato.com/high-profile-whale-loses-over-24m-in-crypto-phishing-attack-report/"}]},{"content":"Both the 2023 and 2026 incidents reportedly involved the same class of attack: malicious token approval phishing. In this technique, an attacker deceives a victim into signing a blockchain transaction — typically an ERC-20 'approve' or 'increaseAllowance' call — that grants the attacker's address unlimited or high-ceiling spending rights over the victim's token balances. Once the approval is in place, the attacker can drain the relevant tokens at any time without any further interaction from the victim. This vulnerability does not require the attacker to compromise the victim's private key; it only requires the victim to sign a deceptive transaction, often through a malicious link, a spoofed interface, or a social engineering lure. The recurrence of this mechanism on the same wallet across two separate incidents suggests that the victim did not revoke outstanding approvals or implement preventive measures following the 2023 event. Security researchers broadly recommend auditing and revoking unnecessary token approvals using tools such as Revoke.cash or Etherscan's token approval viewer as a standard defensive measure.","heading":"Attack Mechanism: Malicious Token Approval Phishing","severity":"high","sources":[{"credibility":2,"name":"Phishing attack drains $25.6 million from crypto whale, second loss tied to same wallet — CoinTurk","type":"news_article","url":"https://en.coin-turk.com/phishing-attack-drains-25-6-million-from-crypto-whale-second-loss-tied-to-same-wallet/"},{"credibility":2,"name":"Crypto whale loses over $24M staked Ethereum to phishing — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/crypto-whale-loses-over-24m-staked-ethereum-to-phishing-as-verified-x-scams-surge/"}]},{"content":"Following the August 12, 2026 attack, on-chain security firm PeckShield tracked the stolen proceeds — approximately 20 million DAI and 3,000 ETH — to four newly created attacker-controlled addresses. The rapid conversion of a mixed token basket into two liquid, easily transferable assets (DAI and ETH) is a standard laundering step designed to simplify further movement across bridges, exchanges, or privacy tools. As of August 16, 2026, no funds have been returned, no on-chain message to the victim has been identified, and no bounty or negotiation has been publicly reported. This stands in contrast to the 2023 incident, in which the attacker voluntarily returned approximately $21.8 million after the theft. The identities of both the victim and the 2026 attacker remain unknown. No law enforcement action has been announced in connection with the August 2026 incident.","heading":"Fund Movement and Recovery Prospects","severity":"critical","sources":[{"credibility":2,"name":"Crypto Whale Loses $25.6M Again as Weekly Hacks Cross $37M — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/16/crypto-whale-loses-25-6m-again-as-weekly-hacks-cross-37m/"},{"credibility":2,"name":"Crypto whale drained $25.6M as physical attacks spread: 2026 losses top $1.2B — AMBCrypto","type":"news_article","url":"https://ambcrypto.com/crypto-whale-drained-25-6m-as-physical-attacks-spread-2026-losses-top-1-2b/"}]},{"content":"The whale phishing incident was the largest single-entity loss in the week of August 9–15, 2026, which saw total confirmed crypto losses exceeding $37 million across multiple incidents. Other notable events in the same week included the Coinsbuy exchange breach ($7.9 million lost across Ethereum and TRON, with some funds frozen by ChangeNOW), an unauthorized mint on Harmony Protocol involving approximately 4 billion ONE tokens (resulting in $3.2 million in realized on-chain losses and a 38% price decline), a drain of the Coreum-XRPL bridge for approximately 199,916 XRP (~$200,000), and the USM Protocol flash loan exploit (~$136,000). Security firm PeckShield's year-to-date tracking placed total 2026 crypto losses at approximately $1.65 billion through July 2026, with the August incidents adding to that figure. Separately, AMBCrypto reported that on-chain exploit losses in 2026 had exceeded $1.2 billion, alongside more than $107 million attributed to violent 'wrench attack' robberies targeting known crypto holders.","heading":"Broader Context: August 9–15, 2026 Hack Week","severity":"medium","sources":[{"credibility":2,"name":"Crypto Whale Loses $25.6M Again as Weekly Hacks Cross $37M — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/16/crypto-whale-loses-25-6m-again-as-weekly-hacks-cross-37m/"},{"credibility":2,"name":"PeckShield reports $25.6 million crypto theft, 2026 losses hit $1.65 billion — CoinTurk","type":"news_article","url":"https://en.coin-turk.com/peckshield-reports-25-6-million-crypto-theft-2026-losses-hit-1-65-billion/"},{"credibility":2,"name":"Crypto whale drained $25.6M as physical attacks spread: 2026 losses top $1.2B — AMBCrypto","type":"news_article","url":"https://ambcrypto.com/crypto-whale-drained-25-6m-as-physical-attacks-spread-2026-losses-top-1-2b/"}]},{"content":"As of August 16, 2026, neither the victim nor the attacker has been publicly identified. The victim is described only as an unidentified Ethereum whale. The victim's wallet was partially identified by the address prefix 0x13e382 in 2023 reporting; 2026 coverage did not confirm or deny that this address matches the one involved in the August 2026 incident. Attacker address 0x8fEB...F95Ae was identified by on-chain investigator Specter as the primary recipient address in the 2026 attack; four downstream addresses were traced by PeckShield. No additional identifying information is available. No law enforcement agency has announced an investigation. No decentralized or centralized exchange has publicly reported flagging or freezing the attacker's funds in connection with this incident. Claims and figures in this page are sourced from Tier 2 crypto news outlets reporting on PeckShield and Specter on-chain data; no Tier 1 regulatory or court-record corroboration is available as of the investigation date.","heading":"Unknown Parties and Investigation Limits","severity":"medium","sources":[{"credibility":2,"name":"Phishing Attack Drains Crypto Whale Wallet Of Another $25.6M — Tron Weekly","type":"news_article","url":"https://www.tronweekly.com/phishing-attack-drains-crypto-whale-wallet/"},{"credibility":2,"name":"Crypto Whale Loses $25.6 Million in Second Phishing Attack on Same Wallet — BigGo Finance","type":"news_article","url":"https://finance.biggo.com/news/51a47b35-732c-42cc-8422-0fc7bfcecfaa"}]}],"sources_used":[{"credibility":2,"name":"Crypto Whale Loses $25.6M Again as Weekly Hacks Cross $37M — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/16/crypto-whale-loses-25-6m-again-as-weekly-hacks-cross-37m/"},{"credibility":2,"name":"Phishing Attack Drains Crypto Whale Wallet Of Another $25.6M — Tron Weekly","type":"news_article","url":"https://www.tronweekly.com/phishing-attack-drains-crypto-whale-wallet/"},{"credibility":2,"name":"Crypto Whale Loses $25.6 Million 2 Years After $24 Million Phishing Attack — BeInCrypto","type":"news_article","url":"https://beincrypto.com/crypto-whale-25-million-wallet-drain/"},{"credibility":2,"name":"Crypto whale drained $25.6M as physical attacks spread: 2026 losses top $1.2B — AMBCrypto","type":"news_article","url":"https://ambcrypto.com/crypto-whale-drained-25-6m-as-physical-attacks-spread-2026-losses-top-1-2b/"},{"credibility":2,"name":"Phishing attack drains $25.6 million from crypto whale, second loss tied to same wallet — CoinTurk","type":"news_article","url":"https://en.coin-turk.com/phishing-attack-drains-25-6-million-from-crypto-whale-second-loss-tied-to-same-wallet/"},{"credibility":2,"name":"PeckShield reports $25.6 million crypto theft, 2026 losses hit $1.65 billion — CoinTurk","type":"news_article","url":"https://en.coin-turk.com/peckshield-reports-25-6-million-crypto-theft-2026-losses-hit-1-65-billion/"},{"credibility":2,"name":"Crypto Whale Drained Of $25.6M In Second Major Phishing Attack — CryptoAdventure","type":"news_article","url":"https://cryptoadventure.com/crypto-whale-drained-of-25-6m-in-second-major-phishing-attack/"},{"credibility":2,"name":"Crypto Whale Loses $25.6 Million in Second Phishing Attack on Same Wallet — BigGo Finance","type":"news_article","url":"https://finance.biggo.com/news/51a47b35-732c-42cc-8422-0fc7bfcecfaa"},{"credibility":2,"name":"Crypto whale loses over $24M staked Ethereum to phishing — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/crypto-whale-loses-over-24m-staked-ethereum-to-phishing-as-verified-x-scams-surge/"},{"credibility":2,"name":"High-Profile Whale Loses Over $24M in Crypto Phishing Attack — CryptoPotato","type":"news_article","url":"https://cryptopotato.com/high-profile-whale-loses-over-24m-in-crypto-phishing-attack-report/"},{"credibility":2,"name":"Phishing scammer steals over $24 million from a crypto whale — CoinPaper","type":"news_article","url":"https://coinpaper.com/2264/crypto-whale-loses-over-24-million-in-a-phishing-scam"}],"summary":"On August 12, 2026, an unidentified Ethereum whale lost approximately $25.6 million in a malicious token approval phishing attack — the second major drain on the same wallet, which had previously lost $24.2 million in a comparable attack in September 2023. On-chain security firm PeckShield traced the stolen proceeds, consolidated into approximately 20 million DAI and 3,000 ETH, to four attacker-controlled addresses. Unlike the 2023 incident where the attacker voluntarily returned roughly 90% of funds, no restitution has occurred or been announced as of August 16, 2026.","timeline":[{"date":"2023-09-06","event":"The victim wallet (address prefix 0x13e382) lost approximately $24.23 million in rETH and stETH after signing malicious 'increaseAllowance' transactions granting the attacker token spending approval. Stolen assets were converted to approximately 13,785 ETH and 1.64 million DAI.","source":"CryptoSlate","source_url":"https://cryptoslate.com/crypto-whale-loses-over-24m-staked-ethereum-to-phishing-as-verified-x-scams-surge/"},{"date":"2023-09","event":"The 2023 attacker voluntarily returned approximately 90% of the stolen funds — roughly $21.8 million — to the victim wallet.","source":"BeInCrypto","source_url":"https://beincrypto.com/crypto-whale-25-million-wallet-drain/"},{"date":"2026-08-12","event":"The same wallet was drained of approximately $25.6 million in a second malicious token approval phishing attack. Stolen assets included aWBTC, WBTC, DAI, ETH, cbBTC, USDS, LDO, and CRV. The attacker consolidated proceeds into approximately 20 million DAI and 3,000 ETH across four addresses. On-chain investigator Specter identified attacker address 0x8fEB...F95Ae.","source":"PeckShield / CryptoTimes","source_url":"https://www.cryptotimes.io/2026/08/16/crypto-whale-loses-25-6m-again-as-weekly-hacks-cross-37m/"},{"date":"2026-08-16","event":"As of this date, no funds from the August 2026 attack have been returned. No law enforcement action has been announced. Total confirmed crypto losses for the week of August 9–15 exceeded $37 million across multiple incidents.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/08/16/crypto-whale-loses-25-6m-again-as-weekly-hacks-cross-37m/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 60f4b9cc-bac7-420d-a109-918d7cfddead
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.