The $25 Million Security Lesson: Same Whale, Two Attacks, Zero Improvement

CryptoSignal
Analysis

On February 2025, a crypto whale lost approximately $25 million in assets from two wallets in under 15 minutes. The attacker converted the haul—DAI, WBTC, aUSDC, LDO, sUSDe, and ETH—into DAI and ETH within an hour and dispersed it across multiple addresses. Scam Sniffer flagged the event. The victim? The same entity that lost $24 million in a phishing attack in 2023 and later received 90% back. This time, the mechanism was different: private key leak, not phishing approval. The repeat offense reveals a systemic failure in user security that no protocol patch can fix.

Let me be clear: I don’t buy claims of impenetrable security. The industry loves to talk about smart contract audits and formal verification, but the most expensive vulnerabilities are often the simplest. In this case, the vulnerability was a private key stored or managed in a way that allowed an attacker to drain two wallets simultaneously. The 2023 attack was a phishing approval—the user signed a malicious “increase allowance” transaction. Two years later, the attacker bypassed the need for user interaction entirely. They had the keys.

This is not a protocol-level exploit. It is a user-side operational security failure. But the implications ripple across the entire ecosystem. If a whale—someone who lost $24 million before—can be hit again, what chance does the average user have? The answer lies in understanding the technical details and the uncomfortable truth about self-custody.

Context: The Victim’s Profile

The victim first appeared in security reports in 2023 when they lost 4,851 rETH and 9,579 stETH to a phishing attack. At that time, the attacker eventually returned about 90% of the funds. That return may have created a dangerous precedent: the victim may have believed that even if funds were stolen, they could be recovered. This time, the attacker converted assets within 60 minutes and dispersed them—a clear sign of intent to launder, not negotiate.

From the asset composition—DAI, WBTC, aUSDC, LDO, sUSDe, ETH—the victim is a sophisticated DeFi participant. They held positions in Aave (aUSDC), Lido (LDO), Ethena (sUSDe), and wrapped Bitcoin. This is not a novice. Yet the fundamental security practice of private key management was not upgraded after the first incident. The attacker likely had access to the private key for months, waiting for the optimal moment to strike.

Core Analysis: Private Key Leak vs. Phishing — Same Root Cause

Phishing attacks require the victim to sign a malicious transaction. They are dangerous but leave a window for user vigilance and wallet-level warnings. A private key leak, however, grants the attacker full control. No approvals needed. No user interaction required. The attacker can drain the wallet as soon as they have the key.

The speed of the attack confirms automation. Within 15 minutes, two wallets were emptied. Within an hour, the stolen assets were swapped and sent to multiple addresses. This is not a manual operation. The attacker used bots and liquidity aggregators to execute the conversion. The fact that the attacker targeted DAI and ETH—not USDC or USDT—suggests they prioritized privacy and liquidity. DAI and ETH have deeper on-chain liquidity and are easier to route through mixers or bridges.

Based on my audit experience, private key leaks typically stem from one of three vectors: (1) seed phrase stored on a device with internet access (screenshot, cloud sync, email), (2) clipboard hijacking malware, or (3) compromise of a third-party wallet management tool. Given the victim’s history with phishing, the first vector is most likely. They probably did not migrate to a hardware wallet or multi-signature setup after the first attack.

The gap between technical sophistication and operational security is the industry’s most expensive vulnerability. This victim knew how to use DeFi protocols, but they treated security as a one-time setup rather than a continuous process. The attacker exploited that gap.

Contrarian Angle: The 2023 Return Was a Trap

The prevailing narrative around the 2023 attack is that it had a happy ending: 90% returned. That narrative is dangerous. It gives users false hope that stolen funds can be recovered. This attack is fundamentally different. The attacker did not negotiate. They did not return anything. They executed a professional money-laundering pipeline within minutes.

Moreover, the fact that the same victim was targeted again suggests that the attacker either had persistent access to the private key since 2023 or that the victim’s security practices were so weak that a new attacker easily found the key. Either way, the 2023 return may have inadvertently lowered the victim’s guard. "If they gave it back last time, maybe they will again" is a cognitive bias that leads to complacency.

Self-custody is not a philosophy; it's a risk management exercise. The victim’s experience shows that self-custody without proper risk management is just gambling. The industry needs to move away from the ideological purity of "not your keys, not your coins" and toward practical solutions that protect users from themselves.

The $25 Million Security Lesson: Same Whale, Two Attacks, Zero Improvement

Takeaway: The Industry Must Invest in User Security Infrastructure

The $25 million loss is a microcosm of a larger problem: the DeFi ecosystem is built for the technically proficient, but even the technically proficient fail at security. The solution is not to abandon self-custody but to augment it with layers of protection that do not rely solely on the user’s discipline.

What does that look like?

  • Account abstraction (ERC-4337): Enables social recovery, session keys, and spending limits. If the user had set up a social recovery wallet, the attacker could not have drained the wallet without the recovery guardians’ approval.
  • Multi-signature wallets: For high-value holdings, require at least two signatures. Even if the attacker had one key, they would need another.
  • On-chain insurance: Protocols like Nexus Mutual could cover private key theft, but adoption is low. Events like this could drive demand.
  • Behavioral monitoring: Wallets and security tools should flag unusual activity—like a sudden transfer of all assets—and delay execution or require additional confirmation.

Scam Sniffer did its job: it detected the attack and reported it. But detection is not prevention. The industry needs to prioritize prevention through infrastructure that raises the cost of attack.

The $25 Million Security Lesson: Same Whale, Two Attacks, Zero Improvement

The biggest risk in crypto is not the code; it's the human. Until we build systems that accommodate human error, we will keep seeing the same headlines. The victim of this attack is a cautionary tale, but they are also a signal. The market is saturated with sophisticated users who are one mistake away from losing everything. The next wave of innovation should focus on making security idiot-proof, because the idiots are the ones with the money.

Will the funds be recovered? Unlikely. The attacker’s speed and laundering method suggest they are not interested in returning anything. And even if they are, the damage to the self-custody narrative is done. The industry must now confront the uncomfortable truth: self-custody, as currently practiced, is a luxury few can afford.