The wallet was already bleeding in 2023. Now it is hemorrhaging again.
On August 12, 2026, a crypto whale saw $25.6 million drained from the same address that lost $24.2 million three years ago. The attacker used the same vector—malicious token approvals—and the victim apparently never fully revoked the permissions, or simply fell for another phishing signature.
Context: The Ghost of 2023
Back in September 2023, this whale lost 4,851 rETH and 9,579.2 stETH, worth roughly $24.2 million at the time. Remarkably, the attacker returned 90% of the funds after the incident. The whale likely thought the nightmare was over. But the underlying security posture never changed. The wallet remained active in DeFi, holding a complex portfolio of aWBTC, DAI, WBTC, ETH, cbBTC, USDS, LDO, and CRV. The same bad habits—frequent approvals, multi-protocol exposure—persisted.
Core: The Anatomy of a Repeat Attack
This time, the attacker stripped 630 aWBTC (Aave’s interest-bearing wrapped Bitcoin), 5.1 million DAI, 470 WBTC, 260 ETH, plus smaller amounts of cbBTC, USDS, LDO, and CRV. Total haul: $25.6 million, per PeckShield and on-chain analyst Specter.
Chasing the alpha while the market sleeps, the whale was deep in DeFi—yield farming, staking, governance. Aave’s aToken architecture, while elegant, exposes users to layered approval risks. The attacker likely exploited a single approve() transaction that covered multiple assets, or a permit() signature that granted sweeping access. Once authorized, the attacker swept everything into 20 million DAI and 3,000 ETH, then spread the funds across four wallets.
I’ve seen this pattern before. During the 2020 Curve Wars, I traced anomalous liquidity withdrawals that turned out to be a whale’s over-approved position. The mechanics are always the same: the user signs once, the attacker moves forever.
Reading the room in the order book silence, the attacker’s choice to convert to DAI and ETH is a textbook money-laundering step. DAI is censorship-resistant; ETH is the deepest liquidity pool. No USDC, no USDT—avoiding Circle or Tether freeze risk. This is the work of a professional, not a script kiddie.
Contrarian: The Real Vulnerability Isn’t Code—It’s Cognition
Every security report will blame phishing, but the deeper issue is structural. Three years after the first attack, the industry still hasn’t solved the approval blindness problem. Tools like Revoke.cash exist, but adoption among high-value users is abysmal. The whale’s wallet was still holding aWBTC and stETH—assets that require frequent approvals for yield strategies. The attacker knew exactly what to target.
Speed over precision when the chart breaks—but here, the chart didn’t break. The whale simply didn’t learn. And the industry’s response has been fragmented: protocol-level safeguards (like Aave’s approval limits) are optional, and wallet interfaces still bury approval details in nested menus.
This isn’t a zero-day exploit. It’s a zero-day human. The same wallet, the same flaw, the same outcome. The 2023 attacker returned 90% of funds—maybe this one will too. But that’s not a security strategy; it’s a lottery ticket.
Takeaway: The Next Target Is Already Being Studied
DefiLlama reports 13 other attacks in August 2026 alone, costing over $12 million. Combined with this $25.6 million hit, the month’s tally tops $37 million. That’s a wake-up call, but for whom? The whale’s remaining assets are still sitting in the same wallet—likely still approved. If you’re a high-net-worth DeFi user, stop reading and revoke every token approval you’ve ever made. Because the attacker is probably already tracing your next signature.