Skip to content
Est. MMXXVIVol. VI · № 321RSS
Blockchain Breaches

An archive of cryptocurrency security incidents — hacks, exploits, bridge failures and rug pulls, documented with on-chain evidence.

Dossier № 320Phishing / Social Engineering

Repeat Whale Phishing Drain

An anonymous crypto whale lost about $25.6 million to a phishing drain on Ethereum — the same wallet that had already been phished for roughly $24 million in 2023.

Date
Chain(s)
Status
Funds Stolen

On August 12, 2026, an anonymous crypto whale lost approximately $25.6 million to a phishing attack on Ethereum, after signing malicious transactions that handed control of a large multi-asset position to the attacker. On-chain analyst Specter first flagged the drain, and blockchain security firm PeckShield traced the stolen assets to four freshly created wallets. In a striking twist, the same wallet had already been phished for roughly $24 million in September 2023 — making its owner a rare repeat victim of near-identical social-engineering attacks.

What happened

The attacker made off with a spread of blue-chip holdings — including WBTC, cbBTC, LDO, USDS and CRV — with the largest single lines reported as about $6.3M in aWBTC, $5.1M in DAI, $4.7M in wrapped Bitcoin and $2.6M in ETH. As is typical of drainer operations, the proceeds were rapidly consolidated and swapped into liquid, hard-to-freeze assets — roughly 20 million DAI and about 3,000 ETH — to complicate tracing and set up laundering. No smart contract was broken: the loss flowed entirely from the victim approving or signing transactions presented by a malicious front-end or approval prompt, a pattern that has industrialised into "wallet drainer" scam-as-a-service kits.

Aftermath

Unlike the 2023 incident on this same wallet — where the phisher ultimately returned about 90% of the funds — none of the August 2026 proceeds had been recovered as of reporting, and the status remains stolen. The theft landed during an especially busy stretch: security trackers tallied more than $37 million in losses across the week, alongside the Harmony unauthorized-mint exploit and other incidents. PeckShield and independent investigators continued to monitor the four attacker-controlled addresses for movement toward mixers or exchanges.

Why it matters

This drain underlines that the single largest attack surface for high-net-worth holders is their own signature, not a protocol bug. It echoes the Whale Hunter's Payday case of 2024, in which an anonymous whale lost $55M in DAI to an Inferno Drainer phishing page. That the very same wallet was successfully phished twice, two years apart, is a hard lesson in operational security: a large, transparent on-chain position is a permanent target, and the defences are well known but unevenly adopted — hardware-wallet calldata verification, bookmark-only access to dApps, transaction simulation, and strict separation between storage and interaction wallets. Absent those habits, a whale's balance is effectively a public billboard for drainer crews.

Sources & on-chain evidence

  1. [01]en.coin-turk.comhttps://en.coin-turk.com/phishing-attack-drains-25-6-million-from-crypto-whale-second-loss-tied-to-same-wallet/
  2. [02]cryptotimes.iohttps://www.cryptotimes.io/2026/08/16/crypto-whale-loses-25-6m-again-as-weekly-hacks-cross-37m/
  3. [03]tronweekly.comhttps://www.tronweekly.com/phishing-attack-drains-crypto-whale-wallet/

Related filings