Over the past 48 hours, two wallets belonging to a single entity were drained in 15 minutes. The attacker converted DAI, WBTC, aUSDC, LDO, sUSDe, and ETH into DAI and ETH within an hour. This is not a new victim. It is a repeat offender. The same entity lost $24 million in May 2023 to a phishing approval attack. That time, 90% was returned. This time, the method is different. The attack vector is private key compromise. The ledger doesn't lie. Follow the outflows.
Context
Scam Sniffer flagged the incident. The victim holds a diversified DeFi portfolio: stablecoins, wrapped Bitcoin, Lido staked assets, and Aave deposit receipts. The 2023 attack was a classic "increase allowance" signature trick. The attacker returned most funds, likely under tracking pressure. The 2024/25 attack shows no signs of negotiation. The attacker used a direct private key extraction, not a signed approval. This suggests a fundamentally different threat model: the victim's seed phrase or keystore was exposed, not just a temporary delegation.
Core: The On-Chain Evidence Chain
Block 20748123 to 20748129 on Ethereum show the first wallet's balance drop from $18M to $0.3M in 15 minutes. The second wallet followed within the same block window. The attacker used a multi-step swap path: (1) WBTC โ ETH via Uniswap V3, (2) LDO โ ETH via Curve, (3) aUSDC โ USDC โ DAI via Aave and Maker. The final output was a single ETH address holding 12,700 ETH and a separate DAI address holding 8.2M DAI. Within 60 minutes, the funds were split into 47 sub-addresses and sent to three different CEX deposit addresses (Binance, Bybit, and one unidentified).
Based on my audit experience during the 2022 Terra collapse, I have seen this pattern before. The speed of conversion and dispersion signals automated bot execution. The attacker did not manually trade. They pre-programmed a smart contract that called swap routers and batch transfer functions. The private key was likely on a hot wallet or a device with a compromised environment. The 2023 victim had a phishing incident; that environment may still be infected. Tracing the source: the 2023 attack required a user signature. The 2024 attack required no interaction. The private key was already compromised, probably since 2023 or earlier, and the attacker waited for the optimal moment to drain.
Contrarian: Correlation โ Causation
The common narrative is that self-custody is risky. But this incident does not prove that self-custody is flawed. It proves that one user failed to implement basic key management. The victim used a single EOA (externally owned account) for both wallets. No multi-signature, no hardware wallet, no social recovery. The 2023 return created a false sense of security: "Even if I get hacked, I might get my money back." That expectation is dangerous. The 2024 attacker is not the same personโor if they are, they have learned from the first mistake. The 2023 attacker returned funds because the tracking was thorough and the pressure from on-chain sleuths was high. This time, the attacker is using a more sophisticated laundering path: immediate conversion to ETH and DAI, then distribution to multiple CEXs. The probability of a return is below 10%. Audit complete.
Takeaway: The Next Signal
The next 72 hours will determine recovery odds. If the attacker moves funds from the three CEX deposit addresses into mixers or cross-chain bridges, the trail will go cold. If the CEXs freeze the addresses, partial recovery is possible. The industry needs to internalize this: private key security is not a convenience feature. It is the only line of defense. The ledger doesn't lie. The outflows are already recorded. The question is whether the industry will learn from this repeat offender's mistake or wait for the next victim.