TLDR A private key hack caused a $27 million loss from an Ethereum whale’s wallet. Ethereum, WETH, OKB, and FET tokens were among those drained by the attacker.TLDR A private key hack caused a $27 million loss from an Ethereum whale’s wallet. Ethereum, WETH, OKB, and FET tokens were among those drained by the attacker.

Ethereum Whale’s Wallet Drained of $27 Million After Private Key Leak

2025/12/18 23:08
3 min read

TLDR

  • A private key hack caused a $27 million loss from an Ethereum whale’s wallet.
  • Ethereum, WETH, OKB, and FET tokens were among those drained by the attacker.
  • The compromised multisig wallet used a flawed “1-of-1” signature setup.
  • The attacker laundered funds through Tornado Cash in staggered transactions.

A recent hack has drained over $27 million from an Ethereum whale’s multisig wallet, caused by a private key compromise. The wallet’s private key was allegedly leaked or stolen, allowing the attacker to access and control the funds. The attacker has been able to launder some of the stolen assets using Tornado Cash, a tool known for anonymizing cryptocurrency transactions. This incident has raised concerns about the security of multisig wallets and private key management.

Multisig Wallet Compromised

The attack was first noticed by blockchain security firm PeckShield, which reported that the victim’s multisig wallet was compromised shortly after it was created. The hacker managed to take control of the wallet just six minutes after its creation on November 4, 2025. At this point, ownership of the wallet was transferred from the victim to the attacker.Image

The wallet, initially set up with multisig security, was later discovered to have been configured as a “1-of-1” wallet. This setup allowed a single signature to approve transactions, making it vulnerable to attack. Experts argue that this flaw essentially defeated the purpose of a multisig setup, which typically requires multiple signatures for transaction approval.

Funds Laundered Through Tornado Cash

Once the attacker gained control, they started moving the stolen funds in batches, using Tornado Cash to launder the assets. PeckShield reports that approximately $12.6 million, or around 4,100 ETH, was sent through Tornado Cash. This technique helps obfuscate the origin of the funds, making it more difficult for authorities or blockchain analysts to trace the stolen assets.

In addition to the 4,100 ETH, the attacker also held a portion of the funds in liquid assets, including $2 million in stablecoins and tokens. These tokens included ETH, WETH (Wrapped Ethereum), OKB, LEO, and FET, which were among the assets drained from the wallet. The total value of the stolen assets could be as high as $40 million, based on new findings from forensic experts.

Leveraged Position at Risk

At the time of the hack, the victim’s wallet had a significant leveraged position on the decentralized lending platform Aave. The victim had supplied about $25 million worth of Ethereum, borrowing roughly $12.3 million in DAI against it.

However, with the wallet compromised, the attacker could potentially liquidate these assets if the Ethereum price drops significantly. The current health factor of the leveraged position is around 1.68, meaning it is close to being liquidated if Ethereum’s price declines further.

This situation poses a risk not only to the victim but also to the broader market, as forced liquidations could create selling pressure on Ethereum and other assets involved in the attack.

Security Vulnerabilities in Multisig Setup

Experts have pointed to several potential vulnerabilities in the way the victim handled their multisig wallet. Malware or phishing attacks targeting the victim’s device or poor security practices might have led to the private key compromise. To prevent such attacks, security professionals recommend using isolated, offline signing devices and verifying transactions beyond the user interface.

Furthermore, the fact that the wallet was configured as a “1-of-1” raises questions about the victim’s operational security. A multisig wallet ideally requires multiple signatures from different participants, reducing the risk of a single point of failure.

The post Ethereum Whale’s Wallet Drained of $27 Million After Private Key Leak appeared first on CoinCentral.

Market Opportunity
Ambire Wallet Logo
Ambire Wallet Price(WALLET)
$0.00767
$0.00767$0.00767
-0.90%
USD
Ambire Wallet (WALLET) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

The post CEO Sandeep Nailwal Shared Highlights About RWA on Polygon appeared on BitcoinEthereumNews.com. Polygon CEO Sandeep Nailwal highlighted Polygon’s lead in global bonds, Spiko US T-Bill, and Spiko Euro T-Bill. Polygon published an X post to share that its roadmap to GigaGas was still scaling. Sentiments around POL price were last seen to be bearish. Polygon CEO Sandeep Nailwal shared key pointers from the Dune and RWA.xyz report. These pertain to highlights about RWA on Polygon. Simultaneously, Polygon underlined its roadmap towards GigaGas. Sentiments around POL price were last seen fumbling under bearish emotions. Polygon CEO Sandeep Nailwal on Polygon RWA CEO Sandeep Nailwal highlighted three key points from the Dune and RWA.xyz report. The Chief Executive of Polygon maintained that Polygon PoS was hosting RWA TVL worth $1.13 billion across 269 assets plus 2,900 holders. Nailwal confirmed from the report that RWA was happening on Polygon. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 The X post published by Polygon CEO Sandeep Nailwal underlined that the ecosystem was leading in global bonds by holding a 62% share of tokenized global bonds. He further highlighted that Polygon was leading with Spiko US T-Bill at approximately 29% share of TVL along with Ethereum, adding that the ecosystem had more than 50% share in the number of holders. Finally, Sandeep highlighted from the report that there was a strong adoption for Spiko Euro T-Bill with 38% share of TVL. He added that 68% of returns were on Polygon across all the chains. Polygon Roadmap to GigaGas In a different update from Polygon, the community…
Share
BitcoinEthereumNews2025/09/18 01:10
SEC approves generic listing standards, paving way for rapid crypto ETF launches

SEC approves generic listing standards, paving way for rapid crypto ETF launches

The Securities and Exchange Commission has approved new generic listing standards for spot crypto exchange-traded funds, clearing the way for faster approvals. The U.S. SEC has approved new generic listing standards that will allow exchanges to fast-track spot crypto ETFs,…
Share
Crypto.news2025/09/18 13:51
United Kingdom CFTC GBP NC Net Positions declined to £-42.4K from previous £-25.8K

United Kingdom CFTC GBP NC Net Positions declined to £-42.4K from previous £-25.8K

The post United Kingdom CFTC GBP NC Net Positions declined to £-42.4K from previous £-25.8K appeared on BitcoinEthereumNews.com. Information on these pages contains
Share
BitcoinEthereumNews2026/02/21 04:50