Ethereum users noticed over 500 wallets were drained in the past 24 hours

Source Cryptopolitan

On-chain investigators noted multiple Ethereum wallets drained after up to seven years of no activity. The exploit caused up to $800K in losses, with the proceeds moved and mixed through ThorChain. 

In a post on X (formerly Twitter), user @WazzCrypto disclosed that hundreds of wallets have had their funds drained. While wallet-draining is not a new type of attack, one thing that stood out this time was that the affected wallets were dormant for up to 7 years. Aside from the on-chain record, over the past 24 hours, there have been reports on X by some users confirming their wallets had been drained.

The ongoing attack mostly affected wallets aged 4 to 8 years, according to on-chain data. The oldest wallet had not moved funds in nearly 14 years. Even advanced and experienced crypto users reported having their wallets drained after no known interactions with smart contracts or protocols. 

The most worrying part of the attack is the unknown vector for compromising the wallet’s private keys. Users may prevent losses by preemptively moving funds to new storage with a safely generated private key.

Ethereum attack sweeps hundreds of wallets

The attacker swept over 500 wallets, collecting 2 ETH to swap into XMR for privacy. The wallets contained not only ETH, but other assets as well, and some of the tasks may have been done manually, as noted by on-chain researcher @tayvano. Some of the wallets were not fully drained, and researchers are still searching for signs of wallet filtering or clustering. 

Following the initial asset sweep, the attackers moved to mixing the coins and tokens, similar to other recent DeFi hacks. The actions were similar to other attempts to disguise funds performed by DPRK hackers. 

A total of 324.741 ETH was bridged as wrapped assets on the Bitcoin network using ThorChain. Around $32,000 in ETH were stored in another wallet. Some of the funds were swapped into 9.56 BTC.

Wallets may be exposed through trading bots, contracts, or npm attacks

One possible explanation includes leaked private key databases, activated after years to claim coins. Other hypotheses include flawed Electrum wallet usage, which has been linked to contaminated versions. It is possible that some of the old addresses were in a database of compromised keys. 

As Cryptopolitan reported, similar attacks have happened in connection with the LastPass breach. One of the hypotheses is that another batch of wallets and passwords was exposed. 

The recent wallet-draining attacks happened just days after the Bitwarden hack, but other npm supply chain attacks have shown it is possible to steal crypto from hot wallets.

The other possible explanation is the usage of trading bots, which often require the user to input a private key. 

The recent wave of attacks has led to a decline in trust in DeFi protocols, and continues to make the argument against efforts to present Ethereum and other chains as suitable for large-scale financial activity.

Still letting the bank keep the best part? Watch our free video on being your own bank.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Trillion-dollar, lifetime CEO Musk emerges as early winner ahead of SpaceX IPOThe paperwork that SpaceX submitted to the SEC for its upcoming IPO reportedly contains the provisions for a deal that will assure Elon Musk has unchallenged control over the firm even after its mega trillion-dollar public listing.  The report by Reuters claims that the X IPO deal contains provisions that validate only Elon Musk’s vote […]
Author  Cryptopolitan
19 hours ago
The paperwork that SpaceX submitted to the SEC for its upcoming IPO reportedly contains the provisions for a deal that will assure Elon Musk has unchallenged control over the firm even after its mega trillion-dollar public listing.  The report by Reuters claims that the X IPO deal contains provisions that validate only Elon Musk’s vote […]
placeholder
Top 3 Meme Coins to Watch in May 2026Three meme coins delivered standout gains during April 2026. Dogecoin (DOGE) climbed 13.5%, Pudgy Penguins (PENGU) jumped 53%, and SkyAI rocketed 290% over the month.The trio reflects three different
Author  Beincrypto
19 hours ago
Three meme coins delivered standout gains during April 2026. Dogecoin (DOGE) climbed 13.5%, Pudgy Penguins (PENGU) jumped 53%, and SkyAI rocketed 290% over the month.The trio reflects three different
placeholder
Powell to Stay on Fed Board as Governor, Blocking Trump’s Path to MajorityFederal Reserve Chair Jerome Powell announced he will stay on the Fed Board of Governors after his term as Chair ends on May 15, 2026, citing an ongoing Department of Justice (DOJ) investigation as th
Author  Beincrypto
19 hours ago
Federal Reserve Chair Jerome Powell announced he will stay on the Fed Board of Governors after his term as Chair ends on May 15, 2026, citing an ongoing Department of Justice (DOJ) investigation as th
placeholder
Big Tech AI Capex Tops $650 Billion as Q1 Earnings Beats Pressure Bitcoin Risk TradeAmazon, Meta, Microsoft, and Alphabet all topped Wall Street revenue forecasts on Wednesday. However, aggressive capital spending plans triggered after-hours selloffs and pressured tech-correlated ris
Author  Beincrypto
19 hours ago
Amazon, Meta, Microsoft, and Alphabet all topped Wall Street revenue forecasts on Wednesday. However, aggressive capital spending plans triggered after-hours selloffs and pressured tech-correlated ris
placeholder
XRP ledger sees $418M surge in tokenized treasuries as RWAs go parabolicTokenized U.S. Treasuries on the XRP Ledger climbed from about $50M to over $418M in one year, an 8x increase.
Author  Cryptopolitan
Yesterday 02: 29
Tokenized U.S. Treasuries on the XRP Ledger climbed from about $50M to over $418M in one year, an 8x increase.
goTop
quote