Unidentified Crypto Whale — $25.6M Repeated Phishing Drain
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·2CKFa6…VkX3Summary
On August 12, 2026, an unidentified crypto whale (victim wallet partially identified as beginning 0x13e382) lost approximately $25.6 million in a phishing or private key compromise attack — the second major drain from the same wallet, which had previously lost $24.23 million in September 2023. Unlike the 2023 incident, in which the attacker returned approximately 90% of stolen funds, no funds have been returned from the August 2026 drain as of the date of this investigation. The attacker, whose address was partially identified as 0x8fEB...F95Ae by on-chain investigator Specter, converted stolen assets into approximately 20 million DAI and 3,000 ETH distributed across four addresses.
Connected Entities
8 entities · 60 linked investigations- USDS→mentioned with→Ethereum(70%)
- USDS→mentioned with→Coinbase(65%)
- Ethereum→mentioned with→Coinbase(60%)
- Ethereum→mentioned with→Bitcoin(60%)
- DPRK Crypto Theft H1 2026 (TRM Labs / Blockaid Report)→mentioned with→Bitcoin(70%)
- DPRK Crypto Theft H1 2026 (TRM Labs / Blockaid Report)→mentioned with→Ethereum(70%)
- Rocket Pool→mentioned with→Ethereum(80%)
- Uniswap→mentioned with→Bitcoin(60%)
- Uniswap→mentioned with→Ethereum(80%)
- Coinbase→mentioned with→Bitcoin(65%)
- + 7 more
Timeline(8 events)
21 May 2023
Attacker wallet 0x4c10a4 — later linked to the September 2023 phishing theft — became active and was associated with multiple phishing websites.
CryptoSlate6 September 2023
$24.23M drained from victim wallet (partially identified as 0x13e382) via malicious 'increaseAllowance' token approval transactions. Stolen assets: 4,851 rETH ($8.58M) and 9,579 stETH ($15.63M). Scam Sniffer and CryptoSlate reported the incident.
CryptoSlate / CryptoRank6 July 2024
The 2023 attacker began returning stolen funds, approximately 10 months after the original theft, transferring approximately $9.3 million in DAI to the victim in two initial transactions.
CryptoRank15 July 2024
More than $10 million had been returned to the 2023 victim by this date, ultimately totaling approximately 90% (~$21.8M) of the stolen amount.
CryptoRankAugust 2026
Blockaid published report finding $1.1 billion stolen across 212 crypto incidents in H1 2026; private key misuse accounted for approximately $790 million.
AMBCrypto12 August 2026
Approximately $25.6M drained from the same whale wallet in a second major attack. Stolen assets — WBTC, cbBTC, LDO, USDS, CRV (including aWBTC) — converted by attacker into approximately 20 million DAI and 3,000 ETH across four addresses. Attacker address partially identified as 0x8fEB...F95Ae.
BeInCrypto / PeckShield / Specter (on-chain)13 August 2026
Incident publicly reported by multiple crypto news outlets. PeckShield confirmed asset tracking. CertiK independently verified approximately $25M leaving the victim address. No funds returned; no law enforcement action announced.
Tron Weekly / Crypto Economy / AMBCrypto14 August 2026
As of this date, no funds from the August 2026 drain have been publicly reported as returned. No regulatory action or law enforcement referral has been announced.
AVOID.NET investigation (current status)Decision Log
- hash: 6w2oXEgS3foDh5YLSQszQUwZZp6H4LSqeqfQVVtBdsWp
- hash: BcnpzPaYatX2zZCg4pMbPcNdykSpMNH6kxLGhB8NuWHS
- hash: 4m5whA5to3VZFXxGmCPzN2K49nzxL77nWGgNC4pKS2C3
This investigation is cryptographically anchored to the Solana blockchain (3 events). 11 of 12 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/14/2026, 5:09:06 PM
last updated: 8/25/2026, 1:59:41 PM
5 viewsavoid.net — verified advice for a post-truth world