Loading market data...

Crypto Whale Loses $26M in Second Major Theft, Private Key Compromise Suspected

Crypto Whale Loses $26M in Second Major Theft, Private Key Compromise Suspected

A crypto whale known as TLBL lost more than $26 million in a second major theft, two years after a phishing attack drained $24 million from the same wallet. The latest incident appears to involve a compromised private key, according to blockchain security firm Lookonchain, which flagged the case on August 13. The two thefts together total roughly $50.3 million in assets.

What was taken this time

Stolen assets include aWBTC, DAI, WBTC, ETH, aUSDC, sDAI, USDS, cbBTC, and several other tokens. PeckShield, another security firm, put the loss at about $25.6 million, including roughly $6.3 million in aWBTC, $5.1 million in DAI, $4.7 million in WBTC, and $2.6 million in ETH. The attacker swapped part of the stolen holdings into 20 million DAI and about 3,000 ETH (worth about $5.64 million), with funds spread across four addresses.

The earlier phishing attack

In the first incident, the same wallet lost 9,579 stETH worth $15.54 million and 4,851 rETH worth $8.51 million in a phishing attack. That brought the total to about $50.3 million across both events. The difference between Lookonchain's and PeckShield's figures comes down to how they value the assets they track.

A broader problem with key misuse

Lookonchain also flagged a separate case of address poisoning where a victim lost $100,000 by copying a lookalike wallet address. A Blockaid report found hackers stole $1.1 billion across 212 incidents in the first half of 2026, with privileged key misuse accounting for roughly $790 million — about 75% of all funds stolen. Monthly incident counts climbed from 18 in January to 57 in June. North Korea-linked hackers accounted for about 55% of all funds stolen in the period, roughly $609 million, but nothing ties TLBL's case to that cluster specifically.

The attacker's funds remain spread across four addresses, and it's unclear if any recovery efforts are underway. The case adds to a growing list of incidents where private key compromise, not smart contract bugs, is the entry point.