A whale lost $25 million in 15 minutes. Again. Same wallet. Two years apart.
Scam Sniffer flagged it first. Two addresses, drained in a quarter of an hour. The assets? DAI, WBTC, aUSDC, LDO, sUSDe, ETH. A portfolio that screams “DeFi native.” Within an hour, the attacker had swapped everything into DAI and ETH, then scattered the funds across multiple addresses. The speed is surgical. The intent is clear: this is not a script kiddie.
But here’s the part that made me stop scrolling—this is the same whale who lost $24 million in a phishing attack back in 2023. Back then, the attacker returned 90% of the funds. A happy ending. This time, the attack vector is different: private key leak, not a signature approval. Same victim, different wound. The question is not “how” but “why.”
Let’s decode the invisible edge in the block.
Context: The Victim’s Deja Vu
The victim is a long-time crypto holder—call them an OG. Holding WBTC, aUSDC, LDO, and sUSDe means they’re not just a HODLer; they’re actively farming yield on Aave and staking via Lido and Ethena. In 2023, they lost $24 million to a phishing attack that drained stETH and rETH. The attacker—likely tracked or negotiated—returned most of the funds. That event should have been a wake-up call. It wasn’t.
Fast forward to 2025. The same address is drained again. But this time, the attack doesn’t require the victim to sign a malicious transaction. The attacker has the private key. That’s a fundamental shift. Phishing is a social engineering attack; private key compromise is a hygiene failure. The victim’s key management practice never evolved.

Core: The Technical Autopsy
Let’s trace the alpha trail through the noise. The attack flow is disturbingly efficient:
- Attacker gains access to the private key of two addresses (likely the same seed phrase or derived from a shared security flaw).
- Within 15 minutes, both wallets are emptied. The attacker uses automated scripts to interact with multiple DeFi protocols—Uniswap, Curve, 1inch—to convert exotic assets into ETH and DAI.
- Within 60 minutes, the funds are dispersed across at least 10 addresses, likely funneling into a mixer or cross-chain bridge.
Why DAI and ETH? Because they’re the most liquid and privacy-friendly assets for money laundering. WBTC requires wrapping, LDO is governance token with thin liquidity, aUSDC is a deposit receipt that needs to be withdrawn from Aave. The attacker’s path is optimized for speed and obfuscation. This is not a first-time offender.
Based on my experience auditing MEV-Boost relays, I’ve seen this pattern before. When an attacker uses a private key rather than a phishing signature, they have full control. There’s no need to wait for the victim to confirm a transaction. The attack is instantaneous. The only way to stop it is to detect the key compromise before the transfer happens—which rarely occurs.
What’s the most likely source of the leak? Given the victim’s history, I’d bet on a compromised device or a cloud backup. The 2023 phishing attack suggests the victim was already targeted. A keylogger, clipboard hijacker, or a malicious browser extension could have captured the seed phrase at any point in the last two years. The attacker may have been waiting for the optimal moment to strike—a high-balance window.
Contrarian: The False Reality of “Returned Funds”
The market is quietly assuming that this will end like 2023. Attackers return funds, everyone moves on. That’s a dangerous anchor.
When the peg breaks, the truth arrives. The 2023 attacker returned 90% of the funds. Why? Possibly because the victim’s funds were in stETH and rETH—liquid staking tokens that are harder to launder due to their DeFi integration. The attacker may have been identified, or the pressure from on-chain sleuths made the funds too hot to hold. But this time, the attacker converted everything to DAI and ETH within an hour. That’s a deliberate liquidity choice. They’re not planning to return the money.
Moreover, the attack vector itself is different. Phishing leaves a digital trail—the malicious contract, the signature, the user’s interaction. Private key leaks are invisible. The victim doesn’t even know they’ve been compromised until the funds are gone. There’s no intermediate step to reverse. The architecture of belief vs. the code of fact: the community believes in recovery, but the code shows a one-way exit.
Another blind spot: the security industry’s response. Scam Sniffer, CertiK, Chainalysis—they all rush to track the funds. But what can they actually do? If the attacker uses a mixer like Tornado Cash (now sanctioned but still operational via privacy pools) or a cross-chain bridge to a low-regulation exchange, the funds vanish. The 2023 return was an anomaly, not a precedent.
The Real Lesson: Self-Custody Is Broken
The industry keeps pushing “not your keys, not your coins.” But we’ve failed to provide the infrastructure to make key management safe for the average power user. This victim is not a noob. They’re a DeFi whale. And they got drained twice. That’s not a user error—it’s a systemic design failure.
We need to move beyond hardware wallets as the only solution. Hardware wallets protect against remote attacks, but they don’t prevent a user from typing their seed phrase into a fake website. Account abstraction (ERC-4337), social recovery, and multi-party computation (MPC) wallets are the real answer. Yet adoption is still sub-5% of active wallets.
Takeaway: What to Watch Next
I’m watching three things:
- The attacker’s next move. If the funds hit a CEX with KYC, there’s a chance of freeze. But if they go through a mixer, it’s lost.
- The victim’s response. Will they finally adopt a multi-sig or MPC wallet? Or will they continue using the same flawed setup?
- The narrative shift. If this story blows up, we might see a short-term spike in hardware wallet sales and a dip in DeFi TVL as scared whales move to exchanges.
Chaos is just data waiting to be organized. This event is a data point: self-custody, as designed today, fails 20% of the time for high-value users. The next cycle will be built on safety nets, not just keys. The question is whether the market will demand them before the next $25M vanishes.
