News

Global security awareness — not only PulseChain.

Permalink for this incident. Same content as the News feed — use Share to post it.

Cross-chain security awareness in plain English. Not an audit. Not financial advice. We never publish drain recipes or exploit steps. News items are research snapshots from public reporting — not always a full 369 deep-dive.

highEthereumcustody

Whale: ~$25.6M private-key drain — same victim as 2023 phishing

12–13 Aug 2026: Scam Sniffer / Specter / PeckShield-class alerts mapped roughly $25.6–26M emptied from a related multi-wallet cluster in about 15 minutes (aWBTC, WBTC, DAI, ETH, aUSDC, LDO, sUSDe and more), then largely swapped into DAI and ETH. Firm reporting links this cluster to the same high-value holder who lost ~$24M to an increaseAllowance phishing event in September 2023. Current window is assessed as private-key compromise rather than another signature-phishing play — press notes at least one drained wallet had never granted token approvals. Dollar band confirmed across secondary press; exact wallet count varies slightly by writeup (multi-wallet cluster).

369 take: A prior phishing hit does not “clear” a wallet cluster — if keys or devices stayed in play, size remains a permanent target. Pulse lesson for holders and wallet UX: after any compromise, assume residual key risk, rotate, segregate, and never leave high balances on the same exposed set; monitoring related wallets beats hoping the first incident was the last.