In 2023, this Ethereum address lost around $24.2M in stETH and rETH after the owner signed malicious increaseAllowance transactions.
Almost three years later, the same address was compromised again. This time, together with a linked wallet, around $25.6M in assets was drained.
There is no evidence that old token allowances were used. Instead, DeFi positions across both wallets were closed, liquidity was withdrawn, and tokens and ETH were transferred directly.
In other words, the attacker was able to control both wallets almost like the owner. On-chain data confirms control over transaction signing, but cannot tell us exactly how that access was obtained. The compromise could involve private keys, a signing device, a signer, or an active session.
Most of the assets were converted into DAI and ETH and split across several addresses. At the time of our analysis, the largest single balance, 20M DAI, was still sitting at an identified storage address.
Another 206K USDC took a more complex route: Ethereum → Arbitrum → Hyperliquid → FXMR → an address where the funds mixed with other users’ flows
One address. Two major thefts. Almost $50M lost across two different compromise mechanisms.
Website | Telegram | BitOK bot


