
A crypto whale lost over $26 million in a second major theft. Private key compromise is the suspected cause, adding to a record year for crypto heists.
A wallet tied to the crypto whale TLBL lost more than $26 million this week, two years after a phishing attack drained $24 million from the same holder. Lookonchain flagged the incident August 13, reporting that the wallet “appears to have had its private key compromised.” The stolen assets include aWBTC, DAI, WBTC, ETH, aUSDC, sDAI, USDS, cbBTC, and several other tokens, the analytics firm said.
PeckShield put the loss at roughly $25.6 million. Broken out, the haul included about $6.3 million in aWBTC, $5.1 million in DAI, $4.7 million in WBTC, and $2.6 million in ETH, according to the security firm. The attacker had already swapped part of the stolen holdings into 20 million DAI and about 3,000 ETH, worth about $5.64 million, with the funds spread across four addresses, PeckShield added.
The two firms' figures differ slightly because each values the assets at the time of tracking. On the broad shape of the event they agree: a TLBL-linked wallet got drained, and a compromised private key appears to be the cause.
This is the second large theft tied to the TLBL cluster. The first, two years ago, involved a phishing attack that stole 9,579 stETH worth $15.54 million and 4,851 rETH worth $8.51 million. Combined, the two incidents amount to about $50.3 million in losses from one holder over roughly 24 months.
The latest hit lands in what is already a record year for crypto theft. A Blockaid report published August 1 found that hackers stole $1.1 billion across 212 incidents in the first half of 2026. Privileged key misuse, the same category as what hit TLBL, accounted for roughly $790 million of that total, about three-quarters of all funds stolen in the period, the report said. Monthly incident counts climbed from 18 in January to 57 in June. Blockaid separately tied North Korea-linked hackers to about 55% of all funds stolen in the period, roughly $609 million, though nothing in the TLBL data points to that group specifically.
Separately, Lookonchain flagged a smaller case this week involving address poisoning. A victim copied a wallet address straight from their transaction history without checking it and sent funds to a lookalike address, losing $100,000. That method differs from the private-key compromise that hit TLBL, Lookonchain said.
The question for large holders is how much stronger security practices help when a wallet has already been targeted once. TLBL moved funds after the first theft, presumably to fresh addresses, the second loss suggests the attacker either retained access to a related key or found a new vector through the same infrastructure. No wallet service, exchange, or custody provider has been publicly tied to either theft.
The Blockaid data show that private-key and seed-phrase compromises are not isolated to whales. The first half of 2026 saw an average of 35 incidents per month, up from 18 in January. The incident count nearly doubled by June, driven partly by targeted attacks on DeFi protocols and individual wallets. The TLBL case fits a pattern where attackers wait months or years after an initial compromise to strike again, often after the victim assumes the danger has passed.
For the broader sector, each high-profile wallet theft feeds two trends. It pushes more institutional holders toward qualified custodians with insurance and hardware-backed key management. And it drives demand for on-chain security tools that monitor wallet activity for suspicious patterns before funds move. The TLBL case is the second time a single whale has lost more than $20 million. It reinforces that self-custody, even with cold storage, carries risk when private keys are generated or stored on a device that has been connected to the internet.
PeckShield said the attacker had already begun moving the stolen assets through multiple addresses, a common obfuscation step. The firm did not name any exchange or mixer that received the funds. Lookonchain said it would continue tracking the addresses linked to the theft.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.