Crypto's Repeat Victims: Why the Same Wallets Keep Getting Drained for Millions
Crypto security faces a troubling pattern: the same high-value targets are being drained multiple times, with one unidentified whale losing nearly $50 million across two separate incidents three years apart. The week of August 9 to August 15 saw over $37 million in confirmed losses across the crypto ecosystem, but the most striking case reveals a vulnerability that goes beyond code flaws.
Why Are the Same Wallets Being Targeted Repeatedly?
On August 12, an attacker drained approximately $25.6 million from a crypto whale's wallet in what security researchers flagged as a phishing attack. The incident mirrored a previous compromise of the same address in September 2023, when the wallet lost roughly $24.2 million. Combined, the two attacks have cost the same address close to $50 million.
The 2023 incident resulted in the attacker returning about 90 percent of the stolen funds, leaving the victim with a manageable loss. This time, the outcome has been starkly different. On-chain analyst Specter noted that the attacker swapped a diverse basket of assets, including wrapped Bitcoin (WBTC), Aave-wrapped Bitcoin (aWBTC), Lido Staked ETH (stETH), and various stablecoins, into DAI and ETH within minutes. Security firm PeckShield tracked the largest components of the loss, identifying roughly $6.3 million in aWBTC, $5.1 million in DAI, $4.7 million in WBTC, and about $2.6 million in ETH.
As of mid-week, the stolen assets had been consolidated into approximately 20 million DAI and 3,000 ETH sitting across four attacker-controlled addresses, with no signs of a return offer. PeckShield reported no indication that the victim would recover any portion of the funds.
How Are Attackers Targeting High-Value Wallets?
Security researchers have not confirmed whether the latest breach came from a fresh signature-phishing prompt or a direct private-key compromise, but both routes remain active theories. The pattern reflects what Scam Sniffer has described as an industry-wide shift toward "whale hunting," where attackers focus on large-holder wallets rather than mass-market targets. A similar case earlier in 2026 saw a crypto user lose $999,999 in USDT to a single malicious token approval.
The shift in attack patterns reveals a critical gap in how high-net-worth crypto holders protect their assets. Unlike smart contract exploits, which affect entire protocols, phishing and wallet compromises target individual users and require either social engineering or credential theft. This personalized approach has proven more lucrative for attackers than waiting for protocol-level vulnerabilities.
Steps to Reduce Your Risk of Wallet Compromise
- Use Hardware Wallets: Store the majority of your assets in a hardware wallet that keeps private keys offline and requires physical confirmation for transactions, making remote phishing attacks significantly harder to execute.
- Verify Approval Requests Carefully: Before signing any token approval, check the contract address and the amount being approved; malicious approvals are a primary vector for phishing attacks targeting large holders.
- Separate Hot and Cold Storage: Keep only the assets you actively trade in a hot wallet connected to the internet, and move the rest to cold storage that is not exposed to phishing campaigns or malware.
- Monitor Wallet Activity: Use on-chain monitoring tools to track unusual outflows or approvals from your address, and set up alerts for large transfers so you can respond quickly if a compromise occurs.
What Do the Latest Crypto Hack Statistics Reveal?
The August 9 to August 15 week was not an isolated incident. According to CertiK's H1 2026 report, Web3 lost more than $1.31 billion across 344 incidents in the first half of the year, with wallet compromises and infrastructure breaches now representing the costliest attack surface. This marks a significant shift from earlier years, when smart contract bugs dominated the loss categories.
Beyond the whale phishing case, the week included several other major breaches. Coinsbuy, a B2B crypto payment processor, lost $7.9 million on August 9 in a coordinated drain across Ethereum and TRON networks. The attacker siphoned 6.04 million USDT from eight TRON wallets and 1.89 million USDT plus 77 ETH from three Ethereum wallets, then quickly converted the stolen funds into Monero (XMR) using instant-exchange services to break the on-chain trail.
The simultaneous activity on two separate blockchains pointed investigators toward a hot-wallet private key compromise or an elevated administrative privilege breach rather than a smart contract flaw. Coinsbuy temporarily paused deposits and withdrawals after the incident, then refilled the drained wallets to within 0.05 percent of their pre-attack balances within 24 hours, stating that the incident had been "contained" and that "all affected amounts have been covered in full by the company from its own reserves".
Layer-1 blockchain Harmony also suffered a major exploit between August 11 and 12, when an attacker suspected of minting roughly 4 billion ONE tokens, equal to about 26 percent of the network's circulating supply. On-chain analyst Juiceberg flagged the unauthorized mint via empty blocks, with 2.8 billion of those tokens moved to centralized exchanges as the price collapsed. SlowMist logged the realized loss from the incident at approximately $3.2 million based on the value the attacker was able to extract through on-chain sales before liquidity dried up.
Why Wallet Compromises Now Outpace Smart Contract Bugs
The shift from smart contract exploits to wallet compromises and infrastructure breaches reflects a maturing threat landscape. Audits and security reviews have become more sophisticated at catching conventional code flaws, but they cannot protect against phishing, credential theft, or social engineering. High-value targets like the whale in this case are attractive precisely because they hold significant assets and may be less cautious about approval requests or may reuse credentials across multiple platforms.
The repeat targeting of the same wallet also suggests that attackers maintain lists of known high-value addresses and periodically attempt new compromise vectors. The three-year gap between the 2023 and 2026 attacks on the same address indicates that attackers may be patient and willing to wait for security practices to slip or for new attack surfaces to emerge.
For the broader crypto ecosystem, these incidents underscore a hard truth: decentralized finance and blockchain technology have solved many problems around censorship and custody, but they have not eliminated the human vulnerabilities that attackers exploit. Until wallet security practices improve and users become more resistant to phishing, high-value targets will remain attractive prey.
" }