An unknown crypto whale has suffered a $25.6 million loss after an attacker gained control of the wallet and drained multiple digital assets on August 12, 2026. Blockchain analyst Specter reported the incident, while security firm PeckShield tracked the movement of the stolen funds.
The latest phishing attack involved several major crypto assets, including Wrapped Bitcoin (WBTC), Coinbase Wrapped Bitcoin (cbBTC), Lido DAO (LDO), USDS and Curve DAO (CRV). The attacker subsequently converted the assets into Dai (DAI) and Ethereum (ETH), apparently consolidating the stolen funds to make them easier to manage across the blockchain.
“An unknown victim was just drained of $25.6M in assets,” Specter, on-chain analyst.
Specter also noted that the attacker “swapped all the assets” into DAI and ETH, highlighting the speed with which the stolen portfolio was consolidated.
PeckShield later identified the largest assets taken from the wallet. About $6.3 million worth of aWBTC was drained, while DAI accounted for approximately $5.1 million. Another $4.7 million was held directly in WBTC before being removed.
Approximately $2.6 million in ETH was also taken, alongside smaller balances of cbBTC, USDS, LDO and CRV.

The attacker ultimately converted the stolen holdings into roughly 20 million DAI and 3,000 ETH. PeckShield said the funds are currently distributed across four separate addresses.
The wallet had already suffered a phishing attack
The latest incident is particularly notable because the same wallet had already been hit by a major phishing attack in September 2023.
According to PeckShield, the victim lost approximately $24.24 million during that earlier incident. The stolen assets included about 4,851 rETH and 9,579.2 stETH.
The attacker behind the 2023 phishing attack subsequently exchanged those assets for roughly 13,785 ETH and 1.64 million DAI. However, the incident took an unusual turn when approximately 90% of the stolen funds were eventually returned to the victim.
The history makes the latest phishing attack significantly more costly for the wallet owner. Combined losses from the two incidents now approach $50 million, although the final amount recovered from the newest theft remains uncertain.
The repeated targeting of the same address also underscores the risks faced by large crypto holders. Wallets containing substantial digital assets can remain attractive targets long after an earlier security incident, particularly when they continue to hold significant balances.
A second phishing attack leaves nearly $50 million exposed
The latest phishing attack comes as crypto security incidents continue to affect users and businesses across the industry.
Data from DeFiLlama cited in the original report recorded 13 hacks in August, with tracked losses exceeding $12 million at the time of reporting. Those figures exclude the separate $25.6 million wallet theft described in this incident.
Payment processor Coinsbuy accounted for a significant portion of the reported August losses after suffering a $7.9 million attack on August 9.
The comparison illustrates how losses in the sector can arise from different forms of compromise. While the current case involved a whale wallet, other attacks have targeted companies and infrastructure providers with potentially large pools of digital assets.
For the victim, however, the central question is now whether the latest attacker will follow the pattern established by the 2023 phishing attack and return some or all of the stolen assets.
What happens to the stolen crypto next?
The movement of the funds into DAI and ETH could make monitoring easier because both assets are widely used across decentralized finance markets, but it does not necessarily mean recovery will be straightforward.
Blockchain transactions remain publicly visible, allowing security researchers and analytics firms to follow movements between addresses. However, tracking funds does not automatically translate into recovering them.
The four addresses currently holding the stolen funds will therefore remain important to investigators and blockchain security researchers. Any subsequent transfers, swaps or attempts to move the assets through other services could provide additional information about the attacker’s strategy.
The incident also demonstrates why a phishing attack can remain financially devastating even for experienced crypto holders. A wallet that survived a previous phishing attack with most of its funds eventually returned has now suffered another major compromise.
For the crypto industry, the case reinforces the importance of wallet security, transaction verification and careful management of token approvals. For the affected whale, the outcome of this latest phishing attack may depend largely on whether the stolen assets can be traced and whether the attacker ultimately chooses to return any portion of the funds.
The latest phishing attack has therefore turned a wallet already associated with a major 2023 theft into the center of another investigation, with total exposure from the two incidents nearing $50 million.