An unknown crypto whale lost $25.6 million in a phishing attack on August 12, 2026, according to on-chain analyst Specter. The attacker swapped stolen assets into Dai and Ethereum. Blockchain security firm PeckShield traced the funds, identifying aWBTC as the most expensive lost asset at $6.3 million. The same wallet had suffered a separate $24.2 million phishing attack in September 2023, but 90% of those funds were later returned. No funds from the latest attack have been returned yet. The two incidents total nearly $50 million in theft from the address.
A phishing attack drained $25.6 million from an unidentified crypto whale on Aug. 12, marking the second major breach linked to the same wallet. On-chain analyst Specter reported that the attacker exchanged the stolen tokens for Dai and Ethereum.
Blockchain security firm PeckShield rated aWBTC as the most expensive lost asset at $6.3 million. The address also lost $5.1 million in DAI and $4.7 million in Wrapped Bitcoin. The attacker removed about $2.6 million in ETH, along with smaller holdings of cbBTC, USDS, Lido DAO, and Curve DAO tokens.
The total value of assets stolen was converted into 20 million DAI and 3,000 ETH. PeckShield traced the proceeds to four separate addresses. Interestingly, the same wallet was drained of $24.23 million in September 2023 due to malicious token approvals, as Specter noted. In that earlier incident, the attacker stole about 4,851 Rocket Pool ETH and 9,579.2 Lido Staked ETH, later swapping them for roughly 13,785 ETH and 1.64 million DAI. However, 90% of those funds were returned to the victim.
The whale’s latest loss occurred in a particularly busy month for crypto security. DefiLlama reported 13 incidents in August worth more than $12 million. Payment processor Coinsbuy accounted for most of the tracked losses after losing $7.9 million on Aug. 9. DefiLlama’s August total does not include the whale’s $25.6 million loss. Among other listed losses were $2 million in RRWallet, $907,000 in MOKE, $696,000 in LOOPSDAO, and $673,000 in RISEx.
Analyst Crypto Jargon claimed that repeated phishing attacks proved the need for a comprehensive reaction to wallet compromise, advising the revocation of all malicious approvals and moving remaining funds to a new wallet.
