We didn’t see it coming. Not the first time, not the second. But the on-chain data never lies. A single crypto whale, hit by a phishing attack in September 2023 for $24.2 million, just got drained again. Same wallet. Same attacker. $25.6 million gone. That’s $49.2 million in total, and the market barely blinked. But I’m not here to count losses. I’m here to show you the structural rot that allowed this to happen—and why it’s a mirror for every DeFi user who thinks ‘I’ll be careful this time.’

Let me take you back to Manila, 2023. I was at a meetup in BGC, nursing a beer and listening to a kid explain how he’d just lost his entire yield-farming stack to a fake approval popup. We laughed nervously. ‘Not me,’ I thought. But the data says otherwise. The same exploit vector that took him down—a malicious token approval—just took down one of the deepest whales in DeFi. And the really scary part? It happened again, three years later, to the exact same wallet.
Hook: The $25.6M Wake-Up Call
On August 12, 2026, a wallet that had already been stripped of 4,851 rETH and 9,579.2 stETH in 2023 saw its assets vanish again. This time the haul: 630 aWBTC ($6.3M), 5.1M DAI, 470 WBTC, 260 ETH, smaller slices of cbBTC, USDS, LDO, and CRV. Total: $25.6 million. The attacker converted everything to 20M DAI and 3,000 ETH, spread across four addresses. Classic pivot. But the story isn’t the numbers—it’s the pattern.
We didn’t expect to see the same wallet hit twice. That’s not how these things work. Usually, after a breach, you wipe the wallet, move to cold storage, call it a lesson. But this whale? They stayed. They kept farming yields, kept interacting with Aave, Lido, Curve—kept signing approvals. And the attacker, whoever they are, kept watching. The second attack wasn’t a surprise. It was a patient, data-driven re-exploitation of a known vulnerability.
Context: The Global Liquidity Map Meets a Single Point of Failure
Let’s zoom out. The macro picture is central to understanding why this matters. In 2024, the spot Bitcoin ETF unlocked institutional liquidity. $10 billion flowed in. The narrative shifted from ‘crypto is a casino’ to ‘crypto is a macro asset.’ But that liquidity, once it enters the DeFi ecosystem, funnels through wallets that are only as secure as the approval screens they sign. The whale in question wasn’t just a whale—they were a node in the global liquidity map. Their holdings in aWBTC, stETH, and CRV represented capital that was actively deployed in the machine. When that node broke, the liquidity didn’t disappear—it got hijacked, converted to DAI and ETH, and sent into the abyss.
We didn’t design DeFi to handle this kind of structural failure. The Aave aToken system, the Lido staking contracts, the Curve pools—they all rely on a permission model that assumes users are rational, attentive, and immune to social engineering. The reality is that every approval request is a potential exploit, and the UX hasn’t evolved fast enough to protect high-value users. This whale, like many others, was a victim of the ‘DeFi summer’ mindset: move fast, sign things, trust the community. That mindset worked in 2020. In 2026, it’s a liability.
Core: The Technical Anatomy of the Second Strike
Let’s dig into the chain data. The first attack in 2023 was a classic phishing approval: the whale signed a malicious token approval transaction, granting the attacker permission to spend their rETH and stETH. The attacker drained 4,851 rETH and 9,579.2 stETH—about $24.2 million at the time. Remarkably, the attacker later returned 90% of the funds. That’s an anomaly. Most phishing attacks don’t give back. But the 10% that wasn’t returned? That was the cost of complacency.
Fast forward to 2026. The same wallet had accumulated a new portfolio: aWBTC (Aave’s interest-bearing wrapped Bitcoin), DAI, WBTC, cbBTC, ETH, USDS, LDO, CRV. The attacker, likely the same entity or a copycat, executed a near-identical attack. The vector: a malicious token approval. The difference this time was the asset mix. aWBTC was the biggest single loss at $6.3 million. That’s important because aWBTC is not a simple token—it’s an Aave aToken, which means it carries accrued interest and is deeply integrated into the lending protocol. Draining it required the attacker to have approval over the Aave’s pool logic, not just the token itself.
We didn’t see this coming, but we should have. The attacker’s behavior after the theft is a textbook case: convert everything to DAI and ETH, then disperse across four addresses. DAI because it’s censorship-resistant—no central issuer to freeze. ETH because it’s the base layer asset with the deepest liquidity. The attacker didn’t touch USDC or USDT. That’s a deliberate signal. They’re preparing for a privacy mix (Tornado Cash or similar) or an OTC desk that doesn’t ask questions.
The hidden truth here is that the whale’s wallet was not a cold storage vault. It was a hot wallet with active DeFi interactions. The attacker didn’t steal the private key—they only had spending approval on specific tokens. That’s why ETH (the gas token) wasn’t fully drained, and why some assets remained. The approval model in DeFi is granular: you can approve only a specific token, or a specific amount. The attacker exploited the gaps in that granularity.
Contrarian: The Decoupling Thesis—Why This Isn’t a Systemic Risk
Everyone wants to scream ‘DeFi is broken.’ I’m not buying it. This attack is a failure of user security, not protocol security. The protocols themselves—Aave, Lido, Curve—functioned exactly as designed. The vulnerability is in the approval UX, which is a user-side problem. That’s contrarian because most security narratives blame the protocols. But let’s look at the data: DefiLlama recorded 13 other attacks in August 2026, totaling over $12 million in losses. The Coinsbuy incident alone was $7.9 million. The cumulative loss is significant, but it’s a drop in the ocean of DeFi’s $100+ billion total value locked. The market’s reaction? A shrug. The price of ETH, WBTC, LDO, CRV barely moved. The decoupling is real: individual security events no longer move the macro needle the way they did in 2022.
What’s more contrarian is that the attacker’s decision to return 90% in 2023 might actually create a moral hazard. The whale never moved to cold storage because they believed the attacker would return the funds again. That’s a dangerous narrative. If the attacker this time doesn’t return, the whale’s trust model collapses. But the market doesn’t care about one whale’s trust model—it cares about liquidity flows. And the $25.6 million, while painful, is not going to crash the market.
We didn’t learn from the first attack. The industry’s response to the 2023 incident was to recommend Revoke.cash and other approval checkers. But adoption remains low. The user experience of checking and revoking approvals is cumbersome. High-value whales are the least likely to adopt new tools because they’re the most confident in their own security. That’s the blind spot. The real risk isn’t the attack itself—it’s the repeated failure to change behavior.
Takeaway: Cycle Positioning and the Next Phase of Security
If you’re a macro watcher, you’re already thinking about the next cycle. The 2026 bull market is in full swing, and security incidents are a feature, not a bug. The liquidity flowing in from ETFs and institutions is creating a massive target surface. The whales of the future won’t be individuals—they’ll be funds, treasuries, and DeFi-native protocols. The attack on this wallet is a preview of the scalability of phishing. The tools exist to prevent it: hardware wallets for long-term storage, dedicated approval management, and multi-signature setups. But adoption is lagging.
My takeaway is simple: the next cycle will be defined by who can secure their capital, not just who can deploy it. The whale in this story is a cautionary tale, but also an opportunity. Every time an attack like this happens, the market learns. The value of security infrastructure—revocation tools, monitoring services, insurance—increases. The protocols that integrate seamless approval management into their UX will win the next wave of institutional capital. The ones that don’t will see their whales get drained.

We didn’t see the second attack coming. But we can see the third. The question is: will you be ready?