Worked example · 2026-08
Repeat-victim whale — the same address that lost $24.2M to approval phishing in 2023 was drained again for $25.6M three years later, and this time nothing came back — unidentified individual (Ethereum) — 2026-08-12 (first drain 2023-09)
Summary
An unidentified individual's Ethereum address — a "whale" by the size of its holdings — was drained of $25.6M on 2026-08-12. On-chain analyst Specter flagged the outflows the same day; PeckShield published the asset breakdown: ~$6.3M in aWBTC, ~$5.1M in DAI, ~$4.7M in WBTC, ~$2.6M in ETH, alongside cbBTC, USDS, LDO and CRV. The attacker swapped the mixed portfolio into roughly 20M DAI and 3,000 ETH.
The address had been here before. In September 2023 it lost approximately $24.2M after signing malicious token approvals that let an attacker pull 4,851 rETH and 9,579.2 stETH, subsequently swapped into about 13,785 ETH and 1.64M DAI. In that incident the attacker returned roughly 90% of the proceeds. In 2026, no funds have been returned.
Between the two events, the address remained in use and rebuilt an eight-figure position, including aWBTC — an Aave interest-bearing receipt token, indicating the wallet was actively deployed in lending rather than sitting idle. The 2026 loss therefore hit a portfolio that had been actively managed for three years after a known compromise.
Public reporting characterises the 2026 event as phishing, without specifying what was signed. Whether the authority was an on-chain ERC-20 allowance, an off-chain permit-style signature, or a compromised key is not established, and the accounts differ on which they favour.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| 2023-09 | Victim signs malicious token approvals; attacker pulls 4,851 rETH and 9,579.2 stETH, ~$24.2M | T4.004 → T5.001 |
| 2023-09 (post-event) | Stolen assets swapped into ~13,785 ETH and 1.64M DAI | T7.007 |
| 2023-09 (post-event) | Attacker returns approximately 90% of the proceeds; net loss becomes survivable | (attacker-side return) |
| 2023-09 → 2026-08 | Address remains in active use and rebuilds an eight-figure portfolio, including aWBTC lending positions | (standing exposure) |
| 2026-08-12 | Second drain: $25.6M across aWBTC, DAI, WBTC, ETH, cbBTC, USDS, LDO and CRV | T4.004 / T4.001 (artefact undetermined) → T5.001 |
| 2026-08-12 | Attacker consolidates into ~20M DAI and ~3,000 ETH | T7.007 |
| 2026-08-12 | Specter flags the drain on X; PeckShield publishes the asset-level breakdown | (external detection) |
| 2026-08-12 onward | No return of funds; no public identification of the phishing vector | (open) |
What defenders observed
- Pre-event (a previously phished address is a marked address). Drained wallets are enumerable, and their owners are demonstrably reachable by whatever channel worked the first time. Re-victimisation is not bad luck; it is the predictable consequence of leaving the same address, the same signing habits, and the same person exposed. Retire the address (M22).
- Pre-event (allowance review as routine, not as cleanup). aWBTC as the largest line means live lending positions with live approvals attached. Standing per-spender allowance audit — with revocation of anything not currently needed — is the one control that bounds this class regardless of how the victim was contacted (M08).
- Pre-event (signing surface separation). A portfolio of this size interacting with the open web from the address that holds it is the underlying structural fault. Hardware or multisig custody for the balance, plus a disposable hot address for unfamiliar interactions, converts a successful phish into a small loss (M19).
- At-event (what the wallet showed the user is the whole battle). If the artefact was an off-chain permit-style signature, the victim saw a signing prompt whose displayed scope did not match its effect. Wallet-side EIP-712 decoding with explicit risk heuristics — what is being granted, to whom, over which token, for how long — is the mitigation aimed exactly at that gap (M31).
- Detection (an outside analyst was first, again). Specter's flag and PeckShield's breakdown are the public record. There is no indication the owner detected either drain independently, which for a self-custodied eight-figure portfolio argues for balance-change alerting as basic hygiene (M39).
- Response (do not budget for the attacker being generous). The 90% return in 2023 is the outlier that made the first incident survivable and, plausibly, made the second one possible by defusing the urgency to change anything. Plan against the 2026 outcome, which is the norm.
Public references
[cryptotimesweek0816]— The Crypto Times, "Crypto Whale Loses $25.6M Again as Weekly Hacks Cross $37M" (the 2026-08-12 date, the $25.6M figure, the repeat-victim framing against the 2023 $24.2M loss, the absence of any return this time, and the note that the vector is reported as phishing-or-key-compromise rather than established): https://www.cryptotimes.io/2026/08/16/crypto-whale-loses-25-6m-again-as-weekly-hacks-cross-37m/[tronweeklywhale2026]— TronWeekly, "Phishing Attack Drains Crypto Whale Wallet Of Another $25.6M" (PeckShield's asset breakdown — ~$6.3M aWBTC, ~$5.1M DAI, ~$4.7M WBTC, ~$2.6M ETH plus cbBTC, USDS, LDO and CRV — the consolidation into ~20M DAI and 3,000 ETH, Specter's 2026-08-12 report, and the 2023 detail: malicious token approvals, 4,851 rETH and 9,579.2 stETH, ~13,785 ETH and 1.64M DAI, ~90% returned): https://www.tronweekly.com/phishing-attack-drains-crypto-whale-wallet/[beincryptowhale2026]— BeInCrypto, "Crypto Whale Loses $25.6 Million 2 Years After $24 Million Phishing Attack" (independent account of the repeat victimisation and the combined ~$50M exposure across both events): https://beincrypto.com/crypto-whale-25-million-wallet-drain/[cointurkwhale2026]— CoinTurk, "Phishing attack drains $25.6 million from crypto whale, second loss tied to same wallet" (corroboration of the PeckShield figures and the second-loss framing): https://en.coin-turk.com/phishing-attack-drains-25-6-million-from-crypto-whale-second-loss-tied-to-same-wallet/[utodaywhale2026]— U.Today, "Crypto Hack Drains $25.6 Million From Unknown Victims" (the victim's unidentified status and the scale of the single-address loss): https://u.today/crypto-hack-drains-256-million-from-unknown-victims
Discussion
OAK usually declines single-victim phishing incidents; they are numerous, mechanically identical, and rarely teach anything that the Technique pages do not already say. This one is kept because the pair is the finding. Two drains, three years apart, one address, ~$50M combined, with the intervening period spent rebuilding an eight-figure position on the same keys. That sequence answers a question the individual cases cannot: what actually happens after a victim survives an approval-phishing drain? Here the answer is that the address kept signing, the balance came back, and the second attacker found a richer target than the first one did.
The 90% return in 2023 deserves to be recorded as a hazard, not as a happy ending. Returns happen for reasons specific to an operator — negotiation, exposure risk, a change of mind — and they are unpredictable and unenforceable. Their systemic effect is to soften the feedback signal that should have driven a custody change. Anyone reasoning about post-incident behaviour should assume the 2026 outcome: total loss, no counterparty, no recourse.
Finally, the entry is deliberately honest about the 2026 artefact being unknown. Allowance-drainer and permit-signature phishing produce nearly identical on-chain results and materially different defences — one is visible as a standing on-chain Allowance record that per-spender monitoring can catch before exercise, the other exists only as an off-chain signature until the moment it is used. A private-key compromise would imply a third defence set again. Reporting that says "phishing" without naming the artefact is not enough to choose, and OAK's convention is to carry both candidate Techniques with the ambiguity stated rather than to resolve it by preference. Contributors who locate the victim address and the exercising transaction can close this by inspection.