Ethereum and Cross-Chain Platforms Face $37M in Weekly Losses as Wallet Hacks Surge
Ethereum-connected wallets and cross-chain infrastructure suffered over $37 million in confirmed losses during the week of August 9 to 15, marking an escalation in what security researchers describe as a shift toward targeting high-value accounts and protocol-level vulnerabilities. The incidents included a $25.6 million phishing drain on a single whale address, a $7.9 million coordinated breach at payment processor Coinsbuy that hit both Ethereum and TRON simultaneously, and protocol-level exploits across multiple blockchain networks.
The week's losses extend a troubling trend documented in the first half of 2026. According to CertiK's H1 2026 security report, Web3 lost more than $1.31 billion across 344 incidents, with wallet compromises and infrastructure breaches now representing the costliest attack surface in the ecosystem. This shift reflects a change in attacker strategy, moving away from smart contract exploits toward targeting the human and operational layers where security is harder to automate.
What Happened to the Ethereum Whale's $25.6 Million?
On August 12, an unidentified crypto whale suffered a wallet compromise that drained approximately $25.6 million in a single transaction. On-chain analyst Specter flagged the drain, noting that the attacker swapped a diverse basket of assets into DAI and ETH within minutes of gaining access. The stolen portfolio included roughly $6.3 million in aWBTC (Aave-wrapped Bitcoin), $5.1 million in DAI, $4.7 million in WBTC, and about $2.6 million in ETH, along with smaller holdings of cbBTC, USDS, LDO, and CRV.
What makes this incident particularly notable is that the same wallet had been targeted before. In September 2023, the address lost approximately $24.2 million after signing malicious token approvals. In that earlier case, the attacker returned roughly 90 percent of the stolen funds, leaving the victim with a manageable loss. The August 2026 incident has followed a different trajectory. Security researchers have not confirmed whether the latest breach came from a phishing prompt or a direct private key compromise, though both routes remain active theories. As of mid-week, no portion of the stolen assets had been returned, and PeckShield tracked the consolidated proceeds into approximately 20 million DAI and 3,000 ETH sitting across four attacker-controlled addresses.
How Are Attackers Targeting Cross-Chain Infrastructure?
Two days before the whale incident, Coinsbuy, a B2B crypto payment processor serving enterprise and merchant clients since 2019, lost $7.9 million in a coordinated attack that hit both Ethereum and TRON networks simultaneously around 13:00 UTC on August 9. The attacker's activity was traced to two Ethereum addresses and one TRON address, with the two chains linked through the cross-chain swap service Bridgers. This coordination suggests the attacker had elevated access rather than exploiting a single smart contract vulnerability.
The attacker began with a 5 USDT probing transaction before siphoning 6.04 million USDT from eight TRON wallets within an hour. On Ethereum, three wallets were simultaneously emptied of 1.89 million USDT and 77 ETH. The attacker then moved quickly to convert the stolen assets into Monero (XMR) using instant-exchange services such as ChangeNOW, FixedFloat, and BingX in an attempt to break the on-chain trail before freezes could take effect. ChangeNOW cooperated with investigators and froze a six-figure sum linked to the stolen funds mid-transfer, though most of the $7.9 million had already been converted by the time freezes activated.
Coinsbuy temporarily paused deposits and withdrawals after the incident, then refilled the drained wallets to within 0.05 percent of their pre-attack balances within 24 hours. The company stated that the incident had been "contained" and that "all affected amounts have been covered in full by the company from its own reserves." Coinsbuy subsequently announced a $100,000 bounty for information identifying the attacker.
Steps to Understand the Broader Security Landscape
- Wallet Compromise Trends: Security researchers have documented an industry-wide shift toward "whale hunting," where attackers specifically target high-value accounts through phishing and signature-manipulation attacks rather than attempting broad protocol exploits.
- Cross-Chain Vulnerability: The simultaneous draining of wallets across Ethereum and TRON in the Coinsbuy incident highlights how bridges and cross-chain infrastructure create new attack surfaces that require separate security monitoring on each connected network.
- Asset Laundering Speed: Attackers are increasingly converting stolen assets into privacy coins like Monero within minutes, making recovery difficult even when exchanges cooperate with investigators and freeze accounts.
The week's incidents also included protocol-level failures that exposed unchecked minting paths and deposit-verification gaps. Layer-1 blockchain Harmony was exploited between August 11 and 12, with an attacker suspected of minting roughly 4 billion ONE tokens, equal to about 26 percent of the network's circulating supply. Harmony confirmed the exploit and stated it was working with exchanges to freeze the funds and develop a patch and rollback options.
These incidents collectively underscore a critical vulnerability in the Web3 ecosystem: while smart contract auditing has matured significantly, the operational and human layers remain exposed. The concentration of losses in wallet compromises and infrastructure breaches, rather than code-level exploits, suggests that security improvements must now focus on key management, access controls, and cross-chain coordination rather than solely on smart contract verification.