A crypto whale suffered a $25.6 million phishing attack on August 12, making it the second major breach affecting this particular address in less than a year. On-chain analyst Specter reported that the attacker exchanged the stolen assets for Dai (DAI) and Ethereum (ETH) shortly after seizing the funds.
Details of the Recent Attack
The unidentified victim’s wallet lost a range of tokens, including Wrapped Bitcoin (WBTC), Coinbase-wrapped Bitcoin (cbBTC), Lido DAO (LDO), StableUSD (USDS), and Curve DAO Token (CRV). The attacker swiftly swapped the holdings for 20 million DAI and 3,000 ETH, converting the assets to major cryptocurrencies to facilitate easier movement and potential laundering.
According to blockchain security firm PeckShield, the most significant individual loss involved aWBTC, valued at $6.3 million. Additional losses included $5.1 million in DAI and $4.7 million in Wrapped Bitcoin. In total, the attacker drained approximately $2.6 million in ETH along with several other tokens in smaller amounts.
PeckShield tracked the stolen assets to four new wallet addresses, which now hold the proceeds of the breach from the whale’s account.
No funds from this most recent attack have been returned. This outcome sharply contrasts with the previous incident tied to the same wallet, where the attacker restored a substantial portion of the stolen assets.
Review of the 2023 Breach
In September 2023, the same address fell victim to a phishing exploit facilitated by malicious token approvals, according to analyst Specter. That breach resulted in the loss of $24.2 million, including 4,851 Rocket Pool ETH and 9,579.2 Lido Staked ETH. After swapping these tokens, the attacker obtained approximately 13,785 ETH and 1.64 million DAI.
Unlike the current case, nearly 90% of those funds were ultimately returned to the whale’s wallet. However, with the August 2024 attack, none of the $25.6 million has been recovered. The amount lost in the most recent incident exceeds the previous one by almost $1.4 million, not accounting for the refunded assets in 2023.
| Attack Date | Total Stolen | Funds Returned | Main Assets Affected |
|---|---|---|---|
| September 2023 | $24.2 million | ~$21.8 million | RPL, stETH, ETH, DAI |
| August 2024 | $25.6 million | $0 | aWBTC, DAI, WBTC, ETH |
Broader Crypto Security Landscape in August
August witnessed heightened activity in crypto-related security incidents. Research platform DefiLlama recorded 13 security breaches throughout the month, resulting in reported losses exceeding $12 million. The single largest event prior to the whale’s breach involved payment services company Coinsbuy, which lost $7.9 million on August 9 after its wallets were compromised on the Ethereum and TRON networks.
The August $12 million figure from DefiLlama does not account for the whale’s $25.6 million loss, raising the month’s total significantly higher than initially reported. Other incidents during this period included losses by platforms and projects such as RRWallet ($2 million), MOKE ($907,000), LOOPSDAO ($696,000), and RISEx ($673,000). None of these individual amounts came close to the scale of the Coinsbuy or whale attacks.
| Incident | Asset(s) Lost | Reported Loss ($) |
|---|---|---|
| Whale (August 2024) | Multiple | 25,600,000 |
| Coinsbuy | ETH, TRON | 7,900,000 |
| RRWallet | Unspecified | 2,000,000 |
| MOKE | Unspecified | 907,000 |
| LOOPSDAO | Unspecified | 696,000 |
| RISEx | Unspecified | 673,000 |
Coinsbuy, a digital payment provider, was particularly impacted as attackers moved quickly to launder the proceeds into privacy-focused cryptocurrencies. DefiLlama monitors and aggregates data on decentralized finance platforms, providing real-time updates on hacks and exploits in the sector.
Mini dictionary: Malicious token approval, a vulnerability where a victim unknowingly grants a third party unlimited spending access to their tokens, allowing attackers to drain assets once approval is obtained.
Security Precautions and Advice
Analysts have highlighted the importance of responding quickly if a wallet is suspected of compromise. Crypto Jargon advised users to revoke all malicious token approvals and transfer remaining assets to a new wallet to prevent further losses.
Repeated phishing attacks underscore an urgent need for users to revoke compromised token approvals and secure funds in new wallets as soon as possible, according to analysts.





USDT
AAPL
