
Attackers successfully drained approximately $800,000 from hundreds of inactive Ethereum wallets in a coordinated attack that spanned over 24 hours. According to reports from BitcoinEthereumNews, the attackers targeted wallets that had been dormant for up to seven years, representing a significant security vulnerability in the cryptocurrency ecosystem. The funds were primarily moved through THORChain to Bitcoin, with approximately $66,000 remaining in EVM wallets, as observed by on-chain investigator Specter. User @WazzCrypto on X disclosed that hundreds of wallets had their funds drained in this coordinated sweep, with the attack affecting wallets that had not moved funds in nearly 14 years in some cases. The most worrying aspect of the attack is the unknown vector for compromising the wallet's private keys, with even advanced and experienced crypto users reporting their wallets were drained after no known interactions with smart contracts or protocols.
On-chain investigator Specter documented that the attacker bridged 324.741 ETH worth $734,000 to the Bitcoin Network, while around $66,000 in assets remained in EVM wallets. As reported by AMBCrypto, the wallet labeled by Etherscan as Fake_Phishing2831105 received these funds from multiple addresses, then moved them through swaps and cross-chain infrastructure. According to MastrXYZ, the attack involved no new approvals, contracts, or signatures, unlike recent DeFi exploits, suggesting the vulnerability stemmed from old leaks or breaches such as the 2022 LastPass incident. Following the initial asset sweep, the attackers moved to mixing the coins and tokens, similar to other recent DeFi hacks, with some of the wallets not fully drained and researchers still searching for signs of wallet filtering or clustering. The actions were similar to attempts to disguise funds performed by DPRK hackers, with around $32,000 in ETH stored in another wallet and some funds swapped into 9.56 BTC.
Despite the significant security incident involving over 500 wallets, ETH prices remained stable, continuing to trade between $2,200 and $2,300. According to AMBCrypto, this market stability occurred because the Ethereum network consensus mechanism remained secure, with infrastructure remaining untouched. The incident contrasted with previous attacks like the KelpDAO exploit, which triggered chain losses across LayerZero and Aave protocols, causing DeFi total value to plummet to $83 billion. ETH prices even slightly gained, rising to $2,285, demonstrating the market's resilience to isolated security incidents. However, the recent wave of attacks has led to a decline in trust in DeFi protocols, continuing to make the argument against efforts to present Ethereum and other chains as suitable for large-scale financial activity.
The coordinated attack highlights the ongoing security challenges facing cryptocurrency users, particularly those with older wallets. As reported by AMBCrypto, old wallets are at higher risk due to their lack of modern security features and standards, with many users having created wallets using random weak generators that produced low-entropy keys. The incident demonstrates how inactivity can weaken wallet security, leaving them vulnerable to attackers who have kept pace with advancing blockchain technology and sophisticated exploitation tools. The coordinated nature of this attack, targeting wallets with no recent activity, suggests the attacker had access to comprehensive wallet databases or sophisticated scanning tools. One possible explanation includes leaked private key databases, activated after years to claim coins, or flawed Electrum wallet usage linked to contaminated versions. Similar attacks have happened in connection with the LastPass breach, with one hypothesis being that another batch of wallets and passwords was exposed, while another possibility involves the usage of trading bots that often require users to input private keys.