At 09:00 UTC on August 13, 2025, a wallet historically tied to a $24.23M exploit in September 2023 reawakened. The address 0x8fEB...F95Ae drained approximately $25.6 million in assets—WBTC, cbBTC, LDO, USDS, and CRV. Within hours, the entire haul was converted to DAI and ETH. The market yawned. The DeFi ecosystem should not.
This is not a new attack. It is a sequel. The same method—malicious token approval via phishing—that worked two years ago worked again. The attacker returned 90% of the 2023 loot. He kept 10%. Now he is back. The infrastructure of decentralized finance has not fixed the fundamental flaw: user-authorized infinite approvals remain the single largest attack surface.
Context: The 2023 Blueprint
In September 2023, the same address exploited a series of users by tricking them into signing permit or approve transactions. The attacker netted $24.23 million. Then, in a move that baffled the community, he returned 90% of the funds—$21.8 million—within weeks. The remaining 10% stayed. The narrative at the time was that the attacker was a "white hat" or a "ethical hacker" who made a point. I never bought that narrative. Based on my experience reverse-engineering DeFi yield aggregators in 2020, I saw a calculated risk-reward calculus. Return the bulk to avoid legal heat, keep a slice as profit. The attacker understood the legal system better than the victims.
Now, two years later, the same address is active again. The stolen assets this time are more diverse: WBTC (wrapped Bitcoin via BitGo), cbBTC (Coinbase's wrapped Bitcoin, launched in September 2024), LDO (Lido DAO governance token), USDS (the new Sky stablecoin), and CRV (Curve DAO token). The conversion to DAI and ETH is textbook—a move to maximize liquidity before entering privacy tools.
Core: The Technical Walkthrough of a Silent Drain
Let me be precise. The attack vector is not a smart contract vulnerability. It is a human vulnerability. The victims approved the attacker's address to spend their tokens—likely through a phishing site that mimicked a legitimate DeFi protocol. The attacker then called transferFrom or burnFrom to move the assets. This is the same tactic used in the $1.5B Bybit hack? No, that was a different vector. Here, it is purely approvals.
The conversion path is where the story gets technical. According to on-chain data tracked by Specter (a chain sleuth), the attacker executed a series of swaps on decentralized exchanges—likely Uniswap V3 and Curve. WBTC and cbBTC were swapped for ETH, then ETH for DAI. LDO and CRV were sold directly for DAI. USDS was likely converted to DAI via the Sky ecosystem's Peg Stability Module. The result: a portfolio of 100% DAI and ETH.
Why DAI and ETH? Because these are the most liquid assets that can be moved into Tornado Cash or cross-chain bridges. The attacker is not holding these assets for investment. He is preparing for the next step: obfuscation. The current window—before the funds enter a mixer—is the golden period for tracing. Every hour that passes, the probability of recovery drops.
The network congestion of approvals is the real bottleneck. Most DeFi users have approved dozens of contracts to spend their tokens. These approvals accumulate over time—like dust on a server rack. The attacker exploits this dust. He waits for a user to interact with a malicious dApp, and then he drains every approved asset. In this case, the victim held assets across four ecosystems: Bitcoin wrappers, Ethereum staking, stablecoins, and Curve. The approval chain was a single point of failure.
Contrarian: The 90% Return Was a Trap
Here is the narrative that needs to be deconstructed. The 2023 return of 90% was hailed as a sign of redemption. Some even claimed the attacker was a "good actor" who made a mistake. I disagree. The 90% return was a calculated move to preserve the attacker's ability to operate again. By returning the bulk, he avoided FBI attention, avoided OFAC sanctions, and built a reputation of "fairness" that made the community trust him. But he kept 10%—$2.4 million. That was his profit. Now he is back for another $25.6 million, and he will likely keep 100% this time because the legal landscape has changed.
The contrarian angle is that the attacker is not a lone wolf; he is a professional. His behavior mirrors that of state-sponsored actors in the 2014-2016 era—test the defenses, return a portion to build cover, then strike again when the heat is off. The 2023 return was a smoke screen. The $25.6 million theft is the real operation.
Moreover, the choice of assets shows sophistication. WBTC and cbBTC are both subject to blacklisting by their respective custodians (BitGo and Coinbase). By converting them to DAI and ETH, the attacker avoids the risk of frozen funds. He knows the infrastructure. He knows the weak points.
Takeaway: The Next Watch
The attacker's next move is predictable. Within 48 hours, the DAI and ETH will likely flow into Tornado Cash or a cross-chain bridge like Across or Stargate. From there, they will be converted to native ETH on a sidechain or L2, then cashed out via a non-KYC exchange or a privacy coin. The window for action is closing.
For DeFi users, the lesson is brutally simple: revoke unused approvals. Use tools like Revoke.cash or Etherscan's token approval checker. The infrastructure of blockchain is secure; the infrastructure of user behavior is not. The 2023 ghost is back, and he will keep coming until the approval model is deprecated.
The network congestion of approvals is the real bottleneck. Fix it or lose more.