A coordinated attack hit more than 500 long-dormant Ethereum wallets on July 24, 2026, siphoning off roughly $800,000 in ETH. On-chain data shows about 260 ETH was first transferred to an address tagged as Fake_Phishing2831105 on Etherscan, then funneled through THORChain Router v4.1.1. A single transaction of 324.741 ETH was sent to the bridge contract. Investigators are still tracing the final destinations.
Old Keys, Weak Storage Habits Under Scrutiny
The wallets had been inactive for four to eight years. Security researchers say the scale and coordination point to a common vulnerability rather than isolated breaches. Suspected causes include compromised legacy wallet generators, exposed private keys, or leaked seed phrases from early users who stored them in browser extensions or unencrypted text files. The phishing-labeled address has received hundreds of transactions over time, suggesting long-term consolidation by the attacker.
Cross-Chain Movement Complicates Tracing
Routing stolen ETH through THORChain makes fund tracking significantly harder. Cross-chain bridges swap assets across different networks, making it difficult for explorers to link source and destination addresses. Analysts say such patterns are sometimes used to obfuscate fund origins. No vulnerability in THORChain itself has been confirmed, and multiple blockchain explorers are working in parallel to map the flow.
Broader DeFi Security Context
April 2026 saw 28 security incidents with over $635 million in total losses, per DefiLlama data. Notable cases include the Wasabi Protocol admin key exploit, Drift signer anomaly, and KelpDAO bridge verification failure. Security experts note that these events highlight a recurring theme: legacy infrastructure decisions continue to expose current systems to risk.
Market reaction to the wallet drain has been muted, with no significant ETH price swing. Trader focus shifted to long-term self-custody hygiene rather than short-term volatility. Community discussions urge periodic wallet audits and migration of old funds to hardware-based storage to guard against delayed, silent attacks.
As of press time, the attacker's identity and exact entry method remain unknown. Investigations are ongoing.

