A Crypto Whale Lost $25.6 Million To The Same Phishing Trick Twice

A confirmed $24 million whale phishing case from 2023 still carries the lesson crypto users keep refusing to learn: a bad signature can be as damaging as a stolen password.

The biggest danger in crypto is not always a broken protocol or a hacked exchange. Sometimes it is one wallet owner clicking through a malicious approval and handing an attacker the right to drain assets that were supposed to be safely held on-chain.

That is what happened in September 2023, when an anonymous Ethereum user lost about $24 million in liquid staking tokens. The Block reported at the time that the wallet was drained of 4,851 Rocket Pool ETH, worth about $8.5 million, and 9,579 Lido Staked ETH, worth about $15.6 million. It was one of the largest individual phishing losses crypto had seen.

The attack did not require the victim to publish a seed phrase on the open internet. It ran through approvals. According to The Block, security firms said the user appeared to have authorized malicious transactions after interacting with a phishing link, giving the attacker permission to move the tokens through Ethereum's transferFrom function.

That is the part you should pay attention to.

The signature was the trap

Crypto users talk a lot about self-custody as if holding your own keys settles the security question. It doesn't. If you sign the wrong transaction, the chain will usually treat that signature as valid. The wallet interface may look routine, the site may look familiar, and the approval may seem like just another step before a swap or claim. Then the assets are gone.

In the 2023 case, crypto.news reported that PeckShield called it a phishing attack and said the stolen rETH and stETH were swapped for roughly 13,785 ETH and 1.64 million DAI. The attacker then began moving funds through exchanges and a mixer, including FixedFloat, OKX and Tornado Cash, according to that report.

There was one unusual turn. A scammer later returned nearly $9.3 million in DAI to the victim, according to Cointelegraph reporting carried by TradingView News. The transfers came in July 2024, about 10 months after the theft, with one return of $5.23 million and another of $4.04 million.

Do not mistake that for comfort. Most victims do not get a refund. Most attackers do not have a sudden change of heart. Once funds leave a wallet, recovery depends on tracing, exchange freezes, law enforcement pressure, and luck. That is a thin safety net for anyone holding serious money.

Whales are targets for a reason

The simple explanation is still the right one: attackers go where the money is. A whale wallet gives a phisher a better return than thousands of small accounts, so the social engineering gets sharper. Fake wallet prompts, poisoned search ads, copied front ends, malicious token approvals, support impersonation, you name it. The goal is not to beat cryptography. The goal is to get you to authorize the theft yourself.

Security reports from 2026 show the same problem has not gone away. CertiK's Hack3D report for the first half of 2026 put total Web3 losses above $1.31 billion across 344 incidents, with adjusted losses of about $1.2 billion after frozen and returned funds. Wallet compromise was the largest loss category in that report, accounting for more than $444 million across 33 incidents.

AMBCrypto, citing TRM Labs, reported a different cut of the same rough year: 207 crypto hacks in the first half of 2026, the highest six-month incident count the firm had tracked. Its report put losses at $972 million as of June and said key, custody and signing infrastructure made up most of the stolen value.

Frankly, that is the real security story. Crypto has spent years telling users to avoid centralized custody, but a self-custodied wallet is not magic. It is an operating environment. If approvals are left open, if old wallets keep holding large balances, or if a signer cannot clearly read what a transaction will do, the user is carrying institutional-scale risk with consumer-grade habits.

For anyone holding meaningful assets, the response has to be practical. Use hardware wallets, separate long-term storage from active DeFi wallets, revoke stale approvals, test new sites with small amounts, and stop treating every signature request as a formality. A wallet with eight figures in it should not behave like a browser tab you forgot to close.

The 2023 whale loss is old news by date, but not by relevance. The same approval mechanics still sit underneath daily crypto use, and attackers are still betting that users will move faster than they read.

Also read: OKX's OKB Token Nears $110 as Its 2025 Supply Burn Keeps Paying OffBinance Cuts Off HTX and 10 Other Platforms Over Russia SanctionsTrump Family Crypto Venture Wins Federal Bank Charter for Its Own Stablecoin

Source

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论