← Unidentified Crypto Whale — $25.6M Repeated Phishing Drain1 decision on this page
Audit log
Every state-changing event for Unidentified Crypto Whale — $25.6M Repeated Phishing Drain: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-14 17:09:15ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
4m5whA5to3VZ…C4pKS2C3sha256 → base58
verifying row…canonical bytes (17888 B) ▸
{"actor":"system:backfill","investigation_id":"fee02041-4d9a-4f8c-873d-070c0eb8c403","kind":"publish","page_slug":"unidentified-crypto-whale-25-6m-repeated-phishing-drain","published_at":"2026-08-14T17:09:14.933Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Unidentified Crypto Whale — $25.6M Repeated Phishing Drain","sections":[{"content":"On August 12, 2026, an unidentified crypto whale suffered an apparent phishing attack or private key compromise that drained approximately $25.6 million from their wallet. Blockchain security firm PeckShield and on-chain analyst Specter both tracked the theft in real time. This was reported as the largest single phishing incident of August 2026 at the time of discovery, and contributed to year-to-date 2026 crypto losses surpassing $1.2 billion according to AMBCrypto, which cited a Blockaid report estimating $1.1 billion lost across 212 incidents in the first half of 2026 alone. The victim's wallet is described by multiple sources as belonging to an experienced liquidity provider active since 2017, maintaining positions including WBTC/USDT liquidity on Uniswap V3.","heading":"Incident Overview","severity":"critical","sources":[{"credibility":2,"name":"Phishing Attack Drains Crypto Whale Wallet Of Another $25.6M — Tron Weekly","type":"news_article","url":"https://www.tronweekly.com/phishing-attack-drains-crypto-whale-wallet/"},{"credibility":2,"name":"Crypto whale drained $25.6M as physical attacks spread: 2026 losses top $1.2B — AMBCrypto","type":"news_article","url":"https://ambcrypto.com/crypto-whale-drained-25-6m-as-physical-attacks-spread-2026-losses-top-1-2b/"},{"credibility":2,"name":"Crypto Whale Loses $25.6 Million 2 Years After $24 Million Phishing Attack — BeInCrypto","type":"news_article","url":"https://beincrypto.com/crypto-whale-25-million-wallet-drain/"}]},{"content":"According to PeckShield and on-chain investigator Specter, the attacker drained assets across multiple categories from the victim's wallet. PeckShield identified the following breakdown: approximately $6.3 million in aWBTC (Aave-wrapped Bitcoin), $5.1 million in DAI, $4.7 million in Wrapped Bitcoin (WBTC), and roughly $2.6 million in Ethereum (ETH). Additional assets stolen include cbBTC (Coinbase Wrapped BTC), LDO (Lido DAO governance token), USDS, and CRV (Curve DAO token). Following the theft, the attacker rapidly swapped all stolen holdings into approximately 20 million DAI and 3,000 ETH — a conversion strategy consistent with laundering intent. The consolidated proceeds were then distributed across four separate attacker-controlled wallet addresses. The attacker address was partially identified by Specter as 0x8fEB...F95Ae. CertiK independently confirmed approximately $25 million leaving the victim address, providing additional corroboration of the loss magnitude.","heading":"Stolen Assets and Fund Movement","severity":"critical","sources":[{"credibility":2,"name":"Crypto Whale Loses $25.6 Million 2 Years After $24 Million Phishing Attack — BeInCrypto","type":"news_article","url":"https://beincrypto.com/crypto-whale-25-million-wallet-drain/"},{"credibility":2,"name":"Phishing attack drains $25.6 million from crypto whale, second loss tied to same wallet — Coin Turk","type":"news_article","url":"https://en.coin-turk.com/phishing-attack-drains-25-6-million-from-crypto-whale-second-loss-tied-to-same-wallet/"},{"credibility":2,"name":"Two Crypto Hacks Drain Over $51M Through Key Compromises — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/two-crypto-hacks-drain-over-51m-through-key-compromises/"},{"credibility":2,"name":"Crypto Whale Drained Of $25.6M In Second Major Phishing Attack — CryptoAdventure","type":"news_article","url":"https://cryptoadventure.com/crypto-whale-drained-of-25-6m-in-second-major-phishing-attack/"}]},{"content":"The precise attack vector has not been definitively confirmed by a primary source as of the date of this investigation. Multiple outlets describe this as a phishing attack, while others — including CryptoPotato and Crypto Economy — characterize it as an apparent private key compromise. In the 2023 incident involving the same wallet, the mechanism was confirmed as a malicious token approval attack: the victim signed 'increaseAllowance' transactions that granted the attacker unlimited spending access to their staked ETH holdings, as documented by Web3 security firm Scam Sniffer and CryptoSlate. Whether the 2026 drain used a similar approval exploit, a fully compromised private key, or another social engineering method remains unconfirmed in available public reporting. The repeat targeting of the same wallet — approximately three years after the original compromise — suggests the attacker may have retained surveillance capability or persistent access credentials from the 2023 incident, though this remains an inference from the pattern of events rather than a confirmed finding.","heading":"Attack Vector: Phishing or Private Key Compromise","severity":"high","sources":[{"credibility":2,"name":"Crypto Whale Loses $26M After Apparent Private Key Compromise — CryptoPotato","type":"news_article","url":"https://cryptopotato.com/crypto-whale-loses-26m-after-apparent-private-key-compromise/"},{"credibility":2,"name":"Crypto whale loses over $24M staked Ethereum to phishing — CryptoSlate (2023 incident)","type":"news_article","url":"https://cryptoslate.com/crypto-whale-loses-over-24m-staked-ethereum-to-phishing-as-verified-x-scams-surge/"},{"credibility":2,"name":"Two Crypto Hacks Drain Over $51M Through Key Compromises — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/two-crypto-hacks-drain-over-51m-through-key-compromises/"}]},{"content":"The same victim wallet (partially identified as 0x13e382) was previously compromised on September 6, 2023, in an attack that drained $24.23 million worth of liquid staked Ethereum: 4,851 rETH (Rocket Pool staked ETH, valued at approximately $8.58 million) and 9,579 stETH (Lido staked ETH, valued at approximately $15.63 million). The attack was executed via malicious 'increaseAllowance' token approval transactions that granted the attacker unrestricted access to move the victim's staked ETH. The stolen assets were swapped for approximately 13,785 ETH and 1.64 million DAI. Two attacker wallets were identified in 2023: 0x693b72 and 0x4c10a4; the latter was flagged as associated with numerous phishing websites and had been active since May 21, 2023. In a notable development, the 2023 attacker began returning funds approximately 10 months later (July 2024), ultimately returning approximately 90% of the stolen amount — roughly $21.8 million. The reason for the return was never publicly explained. Web3 security firm Scam Sniffer characterized the 2023 theft as likely the largest amount ever stolen from a single individual at the time.","heading":"Prior Incident: September 2023 Phishing Attack","severity":"high","sources":[{"credibility":2,"name":"Crypto whale loses over $24M staked Ethereum to phishing — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/crypto-whale-loses-over-24m-staked-ethereum-to-phishing-as-verified-x-scams-surge/"},{"credibility":2,"name":"Crypto whale loses $24.23 million in major Ethereum phishing scam — CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/7766e-crypto-whale-loses-24-23-million-in-major-ethereum-phishing-scam"},{"credibility":2,"name":"Phishing scammer returns $10 million to victim 10 months after $24 million Ethereum heist — CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/232df-phishing-scammer-returns-10-million-to-victim-10-months-after-24-million-ethereum-heist"},{"credibility":2,"name":"Crypto Whale Nightmare: $24M Lost in Massive Phishing Scam — DailyCoin","type":"news_article","url":"https://dailycoin.com/crypto-whale-nightmare-24m-scam/"}]},{"content":"As of the date of this investigation (August 14, 2026), no funds from the August 2026 drain have been returned. This contrasts sharply with the 2023 incident in which approximately 90% of funds were eventually recovered. The repeat victimization of the same wallet raises significant questions about operational security practices. If the 2026 attack was enabled by residual access from the 2023 compromise — such as a retained private key, a persistent malicious approval, or surveillance infrastructure established by the original attacker — it would represent a case of a long-dormant threat actor re-engaging after a partial return of funds. This pattern is documented in security literature as 'persistent threat actor' behavior. However, it is also possible that the 2026 attack was conducted by an entirely different party exploiting a separate vulnerability. No law enforcement action, blockchain forensics firm attribution, or official statement has publicly confirmed the identity of either the 2023 or 2026 attacker, nor whether they are the same individual or group. The combined gross losses across both incidents total approximately $49.8 million, with net losses (accounting for the 2023 partial recovery) of approximately $28 million.","heading":"Recovery Status and Persistent Threat Pattern","severity":"critical","sources":[{"credibility":2,"name":"Crypto Whale Loses $25.6 Million 2 Years After $24 Million Phishing Attack — BeInCrypto","type":"news_article","url":"https://beincrypto.com/crypto-whale-25-million-wallet-drain/"},{"credibility":2,"name":"Phishing Attack Drains Crypto Whale Wallet Of Another $25.6M — Tron Weekly","type":"news_article","url":"https://www.tronweekly.com/phishing-attack-drains-crypto-whale-wallet/"},{"credibility":2,"name":"Crypto Whale Loses $25.6 Million In Targeted Wallet Hack — Bitcoin World","type":"news_article","url":"https://bitcoinworld.co.in/crypto-whale-loses-25-6-million-hack/"}]},{"content":"This incident occurred against a backdrop of sharply elevated crypto theft activity in 2026. A Blockaid report dated August 1, 2026, found that $1.1 billion was stolen across 212 incidents in the first half of 2026 alone, with private key misuse accounting for approximately $790 million — close to 75% of all theft by value. AMBCrypto reported that year-to-date 2026 losses had surpassed $1.2 billion by the time of this incident's reporting, including $107 million attributed to physical 'wrench attacks' targeting crypto holders, though the success rate of such physical attacks had declined to approximately 26%. The $25.6 million whale drain was the largest individual phishing loss reported in August 2026 at the time of disclosure. No regulatory action, law enforcement referral, or exchange-level asset freeze has been publicly reported in connection with this incident as of August 14, 2026.","heading":"Broader 2026 Crypto Loss Context","severity":"medium","sources":[{"credibility":2,"name":"Crypto whale drained $25.6M as physical attacks spread: 2026 losses top $1.2B — AMBCrypto","type":"news_article","url":"https://ambcrypto.com/crypto-whale-drained-25-6m-as-physical-attacks-spread-2026-losses-top-1-2b/"},{"credibility":2,"name":"Two Crypto Hacks Drain Over $51M Through Key Compromises — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/two-crypto-hacks-drain-over-51m-through-key-compromises/"}]}],"sources_used":[{"credibility":2,"name":"Crypto Whale Loses $25.6 Million 2 Years After $24 Million Phishing Attack — BeInCrypto","type":"news_article","url":"https://beincrypto.com/crypto-whale-25-million-wallet-drain/"},{"credibility":2,"name":"Phishing Attack Drains Crypto Whale Wallet Of Another $25.6M — Tron Weekly","type":"news_article","url":"https://www.tronweekly.com/phishing-attack-drains-crypto-whale-wallet/"},{"credibility":2,"name":"Two Crypto Hacks Drain Over $51M Through Key Compromises — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/two-crypto-hacks-drain-over-51m-through-key-compromises/"},{"credibility":2,"name":"Crypto whale drained $25.6M as physical attacks spread: 2026 losses top $1.2B — AMBCrypto","type":"news_article","url":"https://ambcrypto.com/crypto-whale-drained-25-6m-as-physical-attacks-spread-2026-losses-top-1-2b/"},{"credibility":2,"name":"Phishing attack drains $25.6 million from crypto whale, second loss tied to same wallet — Coin Turk","type":"news_article","url":"https://en.coin-turk.com/phishing-attack-drains-25-6-million-from-crypto-whale-second-loss-tied-to-same-wallet/"},{"credibility":2,"name":"Crypto Whale Drained Of $25.6M In Second Major Phishing Attack — CryptoAdventure","type":"news_article","url":"https://cryptoadventure.com/crypto-whale-drained-of-25-6m-in-second-major-phishing-attack/"},{"credibility":2,"name":"Crypto Whale Loses $26M After Apparent Private Key Compromise — CryptoPotato","type":"news_article","url":"https://cryptopotato.com/crypto-whale-loses-26m-after-apparent-private-key-compromise/"},{"credibility":2,"name":"Crypto whale loses over $24M staked Ethereum to phishing — CryptoSlate (2023 incident)","type":"news_article","url":"https://cryptoslate.com/crypto-whale-loses-over-24m-staked-ethereum-to-phishing-as-verified-x-scams-surge/"},{"credibility":2,"name":"Crypto whale loses $24.23 million in major Ethereum phishing scam — CryptoRank (2023 incident)","type":"news_article","url":"https://cryptorank.io/news/feed/7766e-crypto-whale-loses-24-23-million-in-major-ethereum-phishing-scam"},{"credibility":2,"name":"Phishing scammer returns $10 million to victim 10 months after $24 million Ethereum heist — CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/232df-phishing-scammer-returns-10-million-to-victim-10-months-after-24-million-ethereum-heist"},{"credibility":2,"name":"Crypto Whale Nightmare: $24M Lost in Massive Phishing Scam — DailyCoin (2023 incident)","type":"news_article","url":"https://dailycoin.com/crypto-whale-nightmare-24m-scam/"},{"credibility":2,"name":"Crypto Whale Loses $25.6 Million In Targeted Wallet Hack — Bitcoin World","type":"news_article","url":"https://bitcoinworld.co.in/crypto-whale-loses-25-6-million-hack/"}],"summary":"On August 12, 2026, an unidentified crypto whale (victim wallet partially identified as beginning 0x13e382) lost approximately $25.6 million in a phishing or private key compromise attack — the second major drain from the same wallet, which had previously lost $24.23 million in September 2023. Unlike the 2023 incident, in which the attacker returned approximately 90% of stolen funds, no funds have been returned from the August 2026 drain as of the date of this investigation. The attacker, whose address was partially identified as 0x8fEB...F95Ae by on-chain investigator Specter, converted stolen assets into approximately 20 million DAI and 3,000 ETH distributed across four addresses.","timeline":[{"date":"2023-05-21","event":"Attacker wallet 0x4c10a4 — later linked to the September 2023 phishing theft — became active and was associated with multiple phishing websites.","source":"CryptoSlate","source_url":"https://cryptoslate.com/crypto-whale-loses-over-24m-staked-ethereum-to-phishing-as-verified-x-scams-surge/"},{"date":"2023-09-06","event":"$24.23M drained from victim wallet (partially identified as 0x13e382) via malicious 'increaseAllowance' token approval transactions. Stolen assets: 4,851 rETH ($8.58M) and 9,579 stETH ($15.63M). Scam Sniffer and CryptoSlate reported the incident.","source":"CryptoSlate / CryptoRank","source_url":"https://cryptoslate.com/crypto-whale-loses-over-24m-staked-ethereum-to-phishing-as-verified-x-scams-surge/"},{"date":"2024-07-06","event":"The 2023 attacker began returning stolen funds, approximately 10 months after the original theft, transferring approximately $9.3 million in DAI to the victim in two initial transactions.","source":"CryptoRank","source_url":"https://cryptorank.io/news/feed/232df-phishing-scammer-returns-10-million-to-victim-10-months-after-24-million-ethereum-heist"},{"date":"2024-07-15","event":"More than $10 million had been returned to the 2023 victim by this date, ultimately totaling approximately 90% (~$21.8M) of the stolen amount.","source":"CryptoRank","source_url":"https://cryptorank.io/news/feed/232df-phishing-scammer-returns-10-million-to-victim-10-months-after-24-million-ethereum-heist"},{"date":"2026-08-01","event":"Blockaid published report finding $1.1 billion stolen across 212 crypto incidents in H1 2026; private key misuse accounted for approximately $790 million.","source":"AMBCrypto","source_url":"https://ambcrypto.com/crypto-whale-drained-25-6m-as-physical-attacks-spread-2026-losses-top-1-2b/"},{"date":"2026-08-12","event":"Approximately $25.6M drained from the same whale wallet in a second major attack. Stolen assets — WBTC, cbBTC, LDO, USDS, CRV (including aWBTC) — converted by attacker into approximately 20 million DAI and 3,000 ETH across four addresses. Attacker address partially identified as 0x8fEB...F95Ae.","source":"BeInCrypto / PeckShield / Specter (on-chain)","source_url":"https://beincrypto.com/crypto-whale-25-million-wallet-drain/"},{"date":"2026-08-13","event":"Incident publicly reported by multiple crypto news outlets. PeckShield confirmed asset tracking. CertiK independently verified approximately $25M leaving the victim address. No funds returned; no law enforcement action announced.","source":"Tron Weekly / Crypto Economy / AMBCrypto","source_url":"https://www.tronweekly.com/phishing-attack-drains-crypto-whale-wallet/"},{"date":"2026-08-14","event":"As of this date, no funds from the August 2026 drain have been publicly reported as returned. No regulatory action or law enforcement referral has been announced.","source":"AVOID.NET investigation (current status)","source_url":"https://ambcrypto.com/crypto-whale-drained-25-6m-as-physical-attacks-spread-2026-losses-top-1-2b/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 8ed3223c-3ff7-4d4b-bb18-3da3dea18c89
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.