Market Prices

BTC Bitcoin
$62,977.5 +0.28%
ETH Ethereum
$1,878.44 +0.18%
SOL Solana
$75.19 -0.71%
BNB BNB Chain
$611.4 +0.54%
XRP XRP Ledger
$1 -0.25%
DOGE Dogecoin
$0.0700 +0.53%
ADA Cardano
$0.1790 -2.08%
AVAX Avalanche
$6.59 +3.18%
DOT Polkadot
$0.7758 +2.47%
LINK Chainlink
$9.25 +5.20%

Event Calendar

{{年份}}
22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

12
05
halving BCH Halving

Block reward halving event

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

18
03
unlock Sui Token Unlock

Team and early investor shares released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

28
03
unlock Arbitrum Token Unlock

92 million ARB released

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0x4b5d...63e2
Top DeFi Miner
+$4.2M
76%
0xafcf...79ca
Early Investor
+$5.0M
63%
0xb531...14c9
Experienced On-chain Trader
+$2.2M
82%

🧮 Tools

All →

The $25.6M Ghost: Tracing a 2023 Attacker’s Return to the Same Wallet

CryptoEagle
Daily

The logic held; the incentives were broken. On August 13, 2025, a wallet address that had been dormant for nearly two years suddenly lit up. The same wallet that drained $24.23 million in September 2023 through a malicious token approval attack—then returned 90% of the funds after public pressure—was now moving again. I traced the hash to the wallet. The new haul: WBTC, cbBTC, LDO, USDS, and CRV, worth approximately $25.6 million. Every single asset was converted to DAI and ETH within hours. The attacker had returned, and the pattern was identical. Code does not lie, but it can be misled.

This is not a new attacker. It is the same entity, using the same playbook, targeting the same class of victims. The 2023 incident was extensively documented: the address 0x8fEB...F95Ae exploited a permit-based phishing scheme, stealing tokens from users who had signed infinite approvals. After the theft, the attacker returned 90% of the assets, claiming it was a “white hat” operation. But the 10% retention—roughly $2.4 million—was kept. Now, two years later, the attacker has struck again, converting a fresh $25.6 million into DAI and ETH. The question is not whether the attacker is a repeat offender, but why the industry has failed to learn from the first incident.

The $25.6M Ghost: Tracing a 2023 Attacker’s Return to the Same Wallet

Context: The Historical Pattern

The 2023 attack was a textbook case of malicious token approval: the attacker created a fake front-end or phishing link that tricked users into signing an approve or permit transaction for a malicious contract. Once the approval was granted, the attacker could call transferFrom to drain the victim's wallet. The attacker then converted the stolen assets—mostly ETH, USDC, and other ERC-20 tokens—into DAI and sent them through a series of mixers. After public scrutiny, the attacker returned 90% of the funds, likely to avoid legal consequences and maintain the illusion of a “responsible disclosure.” The remaining 10% was never recovered.

The $25.6M Ghost: Tracing a 2023 Attacker’s Return to the Same Wallet

The new attack, occurring in August 2025, mirrors this structure. The stolen assets include WBTC (wrapped Bitcoin from BitGo), cbBTC (Coinbase’s wrapped Bitcoin, launched in September 2024), Lido’s LDO governance token, Sky’s USDS stablecoin, and Curve’s CRV token. The attacker converted all of these into DAI and ETH within a single day. The conversion path is revealing: WBTC and cbBTC were swapped on decentralized exchanges, likely through Uniswap or Curve pools, while LDO, CRV, and USDS were also traded. The final destination is a wallet holding only DAI and ETH. The attacker has not yet moved the funds to Tornado Cash, but the window is closing.

Core: Systematic Teardown of the Attack Vector

Let me dissect the technical details. The attacker’s method relies on the fact that most users leave infinite approvals on their tokens. A single phishing transaction can grant the attacker permission to transfer any amount of a specific token. The 2023 attack exploited this, and the 2025 attack does the same. The key difference is the asset composition: the stolen tokens now include cbBTC, a relatively new asset that relies on Coinbase’s centralized custody. By converting cbBTC to DAI, the attacker avoids the risk of Coinbase freezing the asset. Similarly, WBTC can be frozen by BitGo if the address is flagged. The attacker’s choice to convert to DAI and ETH is a deliberate attempt to avoid censorship.

Based on my audit experience in 2017, I have seen this pattern before. The attacker is not a sophisticated hacker; they are a sophisticated social engineer. The code is not the vulnerability—the user’s trust is. The approval mechanism is a feature, but it becomes a weapon when users are tricked. The attacker’s wallet now holds roughly $25.6 million in DAI and ETH. The next step is almost certainly a mixer or a centralized exchange. If the attacker uses Tornado Cash, the funds become untraceable. The on-chain surveillance community has flagged the address, but the attacker is likely monitoring the same channels.

Tokenomic Implications: The Real Damage

The market impact of the stolen assets is minor. $25.6 million is a rounding error in the $2 trillion crypto market. However, the tokenomic consequences are more subtle. The attacker’s conversion of CRV and LDO could create temporary sell pressure. Curve’s governance token, CRV, has a circulating supply of roughly 1.9 billion. A $10 million sell order could push the price down by 2-3% in a low-liquidity environment. Lido’s LDO is similarly vulnerable. The attacker’s decision to sell these tokens immediately suggests they have no interest in governance participation. The yield was not profit; it was liquidity.

But the larger tokenomic issue is trust. The 2023 attack was a warning. The fact that the same wallet could execute a similar attack two years later indicates that the industry has not learned. Infinite approvals remain the default. wallet providers like MetaMask and Ledger have introduced approval revocation tools, but adoption is slow. The attacker’s return is a systemic failure of UX and security design.

Contrarian: What the Bulls Got Right

There is a contrarian angle here. The attacker’s return actually validates the “white hat” narrative from 2023. If the attacker had intended to keep all the funds, they would not have returned 90% the first time. By returning the majority, they established a reputation as a “vigilante” or “ethical hacker,” which might have reduced the scrutiny on their wallet. This allowed them to strike again with a different set of victims. The bulls might argue that the attacker’s behavior is rational: exploit a flawed system, return enough to avoid legal action, and keep a small profit. The math does not lie; the incentives were aligned for a repeat offense.

The $25.6M Ghost: Tracing a 2023 Attacker’s Return to the Same Wallet

However, this logic ignores the fact that the attacker is still a thief. The 10% retention from the first attack was a calculated risk. The 2025 attack shows that the attacker is not a one-time opportunist but a professional predator. The contrarian view also misses the broader systemic issue: the industry’s reliance on permissionless approvals creates a constant attack surface. Until the default UX changes, these attacks will continue.

Takeaway: The Accountability Call

The attacker’s wallet is still holding DAI and ETH. The gold window is closing. If the funds enter Tornado Cash within the next 48 hours, the trail will go cold. The on-chain community must act now. But the real takeaway is for protocol developers and wallet providers. Infinite approvals are a liability. The 2023 attack was a warning; the 2025 attack is a confirmation. The industry must move toward granular, time-limited approvals and mandatory revocation prompts. The code is law, but the law must be rewritten. The attacker’s ghost will return, but the next time, the victims may not be anonymous wallets—they could be the protocols themselves.

Fear & Greed

34

Fear

Market Sentiment

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$62,977.5
1
Ethereum ETH
$1,878.44
1
Solana SOL
$75.19
1
BNB Chain BNB
$611.4
1
XRP Ledger XRP
$1
1
Dogecoin DOGE
$0.0700
1
Cardano ADA
$0.1790
1
Avalanche AVAX
$6.59
1
Polkadot DOT
$0.7758
1
Chainlink LINK
$9.25

🐋 Whale Tracker

🔵
0x1095...707e
1h ago
Stake
3,929,939 USDT
🔴
0x0467...4e1a
1h ago
Out
412 ETH
🔴
0xd346...3296
30m ago
Out
2,849.88 BTC