More than 500 long-dormant Ethereum wallets were drained in a coordinated incident, with total losses nearing $800,000. The case was first flagged by analyst WazzCrypto. Many of the affected addresses had shown no activity for years, and a large share had reportedly remained untouched for four to eight years.
On-chain activity cited in the report shows that attackers moved over 260 ETH, valued there at about $600,000, into a single address labeled Fake_Phishing2831105 on Etherscan. The funds were then routed onward. One transfer of 324.741 ETH went to THORChain Router v4.1.1, a pattern that points to efforts to redistribute or obscure the assets.
Inactive addresses, but not inactive risk
What sets this case apart is the type of wallets involved. These were not recently used addresses, and they were not described as typical fresh phishing victims. They had been sitting idle for years, yet they were emptied in the same incident, suggesting the weakness may have existed long before the funds were actually moved.
That makes the episode different from the usual DeFi exploit, where investigators can often point to a flaw in a smart contract. Here, the issue appears tied to wallet access itself. WazzCrypto said the fact that these were not active wallets makes the incident much more troubling for long-term holders.
Focus shifts to old key handling and seed phrase exposure
The exact cause has not been confirmed. Still, the report lists several possible explanations: stolen seed phrases, weak private key generation in older wallet tools, exposure through outdated wallet software, leaked credentials from password managers, and unsafe storage of recovery phrases.
Some users also pointed to earlier storage habits. In past years, seed phrases were sometimes kept in insecure locations, which may have made them easier to access later. Because the suspected compromise sits at the wallet-access layer rather than the smart-contract layer, tracing the root cause is harder.
Another hit during a heavy month for crypto security
The wallet drain landed during an already severe stretch for crypto security incidents. According to DeFiLlama-linked data cited in the article, April recorded about 28 to 30 major incidents, with aggregate losses above $635 million.
Recent exploits involving admin keys, bridge verification failures, and signer workflows point to the same problem from different angles: some of the most damaging weaknesses sit outside the visible contract code, in key management, access control, and operational procedures.
Why old-wallet holders are paying attention
The incident is a clear reminder that inactivity does not protect assets if the keys behind a wallet have already been exposed. A wallet can sit untouched for years and still be emptied quickly once someone gains valid access.
The source article says users with older wallets should consider moving funds into newer, more secure setups and avoid entering seed phrases into unknown tools or services. Community reaction was mixed, with a smaller group suggesting the transfers could have been a self-managed consolidation by the original owner. Most responses dismissed that view, citing the later laundering-style fund flows.

