Repeat Whale Phishing Drain
An anonymous crypto whale lost about $25.6 million to a phishing drain on Ethereum — the same wallet that had already been phished for roughly $24 million in 2023.
- Date
- Victim
- Anonymous whale
- Chain(s)
- Status
- Funds Stolen
On August 12, 2026, an anonymous crypto whale lost approximately $25.6 million to a phishing attack on Ethereum, after signing malicious transactions that handed control of a large multi-asset position to the attacker. On-chain analyst Specter first flagged the drain, and blockchain security firm PeckShield traced the stolen assets to four freshly created wallets. In a striking twist, the same wallet had already been phished for roughly $24 million in September 2023 — making its owner a rare repeat victim of near-identical social-engineering attacks.
What happened
The attacker made off with a spread of blue-chip holdings — including WBTC, cbBTC, LDO, USDS and CRV — with the largest single lines reported as about $6.3M in aWBTC, $5.1M in DAI, $4.7M in wrapped Bitcoin and $2.6M in ETH. As is typical of drainer operations, the proceeds were rapidly consolidated and swapped into liquid, hard-to-freeze assets — roughly 20 million DAI and about 3,000 ETH — to complicate tracing and set up laundering. No smart contract was broken: the loss flowed entirely from the victim approving or signing transactions presented by a malicious front-end or approval prompt, a pattern that has industrialised into "wallet drainer" scam-as-a-service kits.
Aftermath
Unlike the 2023 incident on this same wallet — where the phisher ultimately returned about 90% of the funds — none of the August 2026 proceeds had been recovered as of reporting, and the status remains stolen. The theft landed during an especially busy stretch: security trackers tallied more than $37 million in losses across the week, alongside the Harmony unauthorized-mint exploit and other incidents. PeckShield and independent investigators continued to monitor the four attacker-controlled addresses for movement toward mixers or exchanges.
Why it matters
This drain underlines that the single largest attack surface for high-net-worth holders is their own signature, not a protocol bug. It echoes the Whale Hunter's Payday case of 2024, in which an anonymous whale lost $55M in DAI to an Inferno Drainer phishing page. That the very same wallet was successfully phished twice, two years apart, is a hard lesson in operational security: a large, transparent on-chain position is a permanent target, and the defences are well known but unevenly adopted — hardware-wallet calldata verification, bookmark-only access to dApps, transaction simulation, and strict separation between storage and interaction wallets. Absent those habits, a whale's balance is effectively a public billboard for drainer crews.
Sources & on-chain evidence
- [01]en.coin-turk.comhttps://en.coin-turk.com/phishing-attack-drains-25-6-million-from-crypto-whale-second-loss-tied-to-same-wallet/
- [02]cryptotimes.iohttps://www.cryptotimes.io/2026/08/16/crypto-whale-loses-25-6m-again-as-weekly-hacks-cross-37m/
- [03]tronweekly.comhttps://www.tronweekly.com/phishing-attack-drains-crypto-whale-wallet/