500 Dormant Ethereum Wallets Drained in 24 Hours: AI Cracking or Old Leaks?

500 Dormant Ethereum Wallets Drained in 24 Hours: AI Cracking or Old Leaks?

N
News Editor 01
2026-07-24 02:30:18
Over 500 dormant Ethereum wallets (4–14 years untouched) were drained by a single address, losing ~$800K in ETH. Funds were bridged via ThorChain to BTC and Monero. Community debates AI brute-force, but analysts point to old seed phrase leaks (e.g., LastPass breach).

Crypto analyst WazzCrypto reported on X that over 500 dormant wallets on Ethereum mainnet — untouched for 4 to 14 years — were emptied by a single address within 24 hours, losing approximately 324.741 ETH (~$800,000). The stolen funds were bridged via ThorChain into wrapped assets, converted into 9.56 BTC, and partially moved into Monero for privacy. One linked address still holds about $32,000 in ETH.

Manual Operation vs. Automated Script

WazzCrypto noted that some wallets were not fully drained, with small leftover amounts still inside. “That doesn’t look like automation; it feels like someone manually operated this whole batch.” On-chain researcher @tayvano is also tracking the flow. Aragon team member @TheTakenUser confirmed his own wallet was drained under mysterious circumstances.

The attacker targeted only old wallets — the oldest had seen no transactions for 14 years. The community quickly floated the idea of AI brute-forcing private keys, but mathematically that’s unlikely. The attacker is exploiting already-leaked keys, not cracking new ones.

Old Seed Phrase Leaks Likely Responsible

Community analysis points to leaked seed phrases from 2017–2020, with the 2022 LastPass breach as a prime candidate. That hack exposed encrypted vault backups of ~30 million users. Weak master passwords are being cracked one by one. TRM Labs traced at least $35 million in stolen crypto to the breach, with funds flowing to Russian crime groups.

Other possible sources include compromised Electrum versions, npm supply-chain attacks, and trading bots that asked users to paste private keys.

Timing: ETH Surged Over 30% Before the Attack

The timing is telling. ETH rallied more than 30% from its April lows, making dormant assets suddenly worth cashing out. The attacker likely had the key list for months and waited for the price bump to maximize profits.

Related incidents previously reported: an Ethereum developer lost funds after installing a malicious AI plugin; a MediaTek chip vulnerability allowed seed phrase theft in 45 seconds on Android devices; and researchers are making progress using AI+GPU+algorithms to recover lost private keys.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.