A DeFi whale lost about $25 million to $26 million after several wallets were drained within 15 minutes early on Aug. 13, according to Scam Sniffer and on-chain analysis cited by Foresight News. The stolen assets included DAI, WBTC, aUSDC, LDO, sUSDe, and native ETH. The victim had also been hit in September 2023, when another attack led to losses of about $24.23 million.
On-chain analyst Ember said three wallets were affected in the latest incident. One of them, address 0x8f3...914, had no token approval history at all and was still emptied. That detail points away from a simple approval-phishing case and suggests the attacker may have gained direct control of the private key.
Assets were moved out in 15 minutes, with part of the funds later sent to Hyperliquid
On-chain data shows that at around 5:05 on Aug. 13, the victim’s main address and a related address, 0xcb3de9c898b59ff239edd6bf30cc44058e24eb47, transferred out all assets almost at the same time. The receiving address was a newly created wallet for that day: 0x8fEB0c6eF08B20bA19C04F951d4408bB5A1F95Ae.
Within an hour, the stolen funds had already gone through an initial laundering cycle. Tokens including WBTC, cbBTC, LDO, USDS, CRV, and sUSDe were swapped into DAI and ETH.
Among the transfers, 20 million DAI was sent to downstream address 0x61cE24326d713641583e6a337a69bef7458fcf76. Arkham labeled that wallet as a separate entity. As of publication, those funds had not moved again.
By the time of publication, the ETH held by the aggregation address had already started moving out. The wallet split ETH into batches of 70, 60, and 50 ETH, sending them to different addresses. Those funds then moved into separate smart contract addresses, were swapped for USDC on Uniswap, and were sent to Circle’s Token Minter contract.
The USDC was then bridged to Arbitrum through CCTP and deposited into Hyperliquid. The path from aggregation to swaps, cross-chain transfer, and exchange deposit showed a well-practiced process.
Data cited in the report came from Arkham.
Additional data came from Arbiscan.
The same victim lost about $24.23 million in September 2023
In the earlier case, the victim signed a malicious increaseAllowance approval transaction. That led to the theft of 4,851 rETH and 9,579 stETH, worth about $24.23 million at the time. Foresight News described it as one of the largest phishing cases then on record.
The stolen funds in that 2023 incident were sent to two addresses: 0x4c10a462CD1e639Da8A062aE8a33a23401120ab1 and 0x693B725a375f599F0b6EfA0d910E749E1Bec1555. Both have been labeled "Fake_Phishing" on Etherscan, based on reports confirmed by Scam Sniffer.
Ember said the attacker in that case eventually returned about 90% of the stolen assets. On-chain records also show that the address ending in ec1555 did not go dormant right after receiving the funds. Instead, it remained active for nearly a year and a half, using protocols such as Uniswap Permit2 and MetaMask swap routing to dispose of assets in stages, before activity faded in the second half of 2024.
The wallet had mainly interacted with major DeFi protocols over the past five years
A review of the victim’s main address over more than five years showed concentrated activity in major DeFi protocols. The counterparties included MakerDAO (Sky) for DAI, Aave for lending and borrowing, Curve liquidity pools, Lido staking, and lending positions on Spark Lend. The report said there was no sign of meme token launches, airdrop farming, or suspicious contract deployments.
Foresight News said the victim appeared to be a long-term DeFi participant rather than a trader chasing speculative yields. The wallet had maintained positions at the level of tens of millions of dollars. At the same time, a large portfolio and frequent protocol interaction meant a much higher volume of approvals than an average user, leaving more room for a single mistake to have outsized consequences.
The aggregation wallet was later flooded with zero-value transfers
After the theft, the aggregation address was hit by another form of on-chain nuisance. A large number of addresses sent repeated zero-value transfers, including 0x61cE7f...09cF76 and 0x61cEa4...13Cf76. The report described this as a common trick used to imitate a real address by matching its first and last characters, hoping someone will copy and paste the wrong destination later.
Foresight News wrote that after a phishing incident, what needs to change may not be limited to user vigilance. The broader signing environment may also need review, including hardware wallets, seed phrase storage, approval management habits, and whether any device has been infected with malware. For users holding large sums, the report suggested at least a 2/3 multisig setup, physical separation between hot and cold wallets, and regular cleanup of stale approvals.
Fund flows, timestamps, and counterparties all leave an on-chain trail. In this case, the route from wallet drain to swaps, cross-chain movement, and deposit into Hyperliquid could be tracked step by step.

