← Radar

Incident case file

Sign in to watch

TLBL Whale — $25.6M Private Key Compromise & DeFi Position Drain

Incident date 2026-08-11Last updated Aug 20, 2026

2 views

ActiveEthereum L1Private key compromise — systematic DeFi position unwindingCluster: TLBL-KEY-2026-08

Estimated loss

$25.6M

Victims identified

1
Victim group joining is coming soon.

Investigation

50%

Facts and investigation

Ledger

Attacker

Unidentified. Controlled victim wallet via suspected private key compromise (not phishing — ETH native also drained, ruling out simple ERC-20 approval attack). Consolidation wallet: 0x8fEB0c6eF08B20bA19C04F951d4408bB5A1F95Ae (confirmed Etherscan — 804 transactions, receives ETH and tokens from victim). Downstream wallets (funds still moving as of Aug 16): 0xe4C3422A189ae40d5898987423bCf6477eA4400e (received 321.6 ETH on Aug 16) | 0x994AE00b0F86f905FB4B1A7D9107686a9ab57Ad6 (received 320 ETH o

Funds moved to

~20,000,000 DAI + ~3,000 ETH (~$5.64M) consolidated across 4+ attacker-controlled addresses from conversion of stolen assets. Ongoing movement: Aug 16 — 321.6 ETH to 0xe4C3422A... + 320 ETH to 0x994AE00b... Funds remain active. No recovery or return offer from attacker (unlike the 2023 incident where ~90% was returned).

Linked

Victim wallet: 0x13e382dfe53207E9ce2eeEab330F69da2794179E (confirmed Etherscan — 5+ year old wallet, 1,325 txs; balance near-zero after drain; multiple Fake_Phishing address poisoning attempts visible in history) | Attacker consolidation: 0x8fEB0c6eF08B20bA19C04F951d4408bB5A1F95Ae (confirmed Etherscan) | DeFi positions unwound by attacker: Aave V2 Lending Pool, MakerDAO sDAI Token, Yearn yvDAI Vault, Convex Finance Booster (×2), Curve OETHCRV-f Pool, Curve cbBTC-WBTC Pool, Curve MtEthena Pool

Chronology

8 beats
  1. August 12–16, 2026 — The crypto whale known on-chain as 'TLBL' (Lookonchain label) suffered an apparent private key compromise resulting in $25.6M drained from at least three Ethereum wallets — the whale's second major loss, following a $24.2M phishing attack in September 2023.

  2. Background: In September 2023, the same primary wallet (0x13e382...) lost 4,851 rETH (~$8.58M) and 9,579.2 stETH (~$15.63M) via malicious token approvals. The 2023 attacker swapped the proceeds for ~13,785 ETH and 1.64M DAI, then returned approximately 90% of funds. The 2026 incident follows a different pattern and method.

  3. August 12–13, 2026: Attacker, having gained apparent direct private key access to the victim's wallet, begins systematically unwinding all DeFi positions: - Withdrawals from Aave V2 Lending Pool - Redemptions from MakerDAO sDAI and Sky sUSDS - Withdrawal from Yearn yvDAI Vault - Withdraw All from Convex Finance Booster (×2) - Remove liquidity from Curve OETHCRV-f Pool, cbBTC-WBTC Pool, MtEthena Pool - Swap Sky SKY Token rewards - Transfers of LDO, CRV, Ethena sUSDe, cbBTC, WBTC, WETH, USDS, DAI, aWBTC

  4. ETH is transferred incrementally to consolidation wallet 0x8fEB0c6e... (transactions of 627 ETH, 289 ETH, 25 ETH, 149 ETH visible on Aug 13–14).

  5. Aug 13, ~12:00 UTC: @SpecterAnalyst publishes first alert (tweet 2087661729945723040): 'An unknown victim was just drained of $25.6M in assets. The attacker swapped all the assets, including WBTC, cbBTC, LDO, USDS, and CRV, for DAI and ETH.'

  6. Aug 13: @PeckShieldAlert confirms (tweet 2087697355978227931): aWBTC $6.3M, DAI $5.1M, WBTC $4.7M, ETH $2.6M. @lookonchain identifies victim as 'TLBL' and notes the 2023 precedent (tweet 2087708203677274283). Yahoo Finance and BeInCrypto publish articles at 02:01 UTC.

  7. Aug 16: Two large transfers OUT from consolidation wallet 0x8fEB0c6e...: 321.6 ETH to 0xe4C3422A... and 320 ETH to 0x994AE00b... — funds are still actively moving.

  8. As of Aug 20, 2026: No contact from attacker, no return of funds, no identification of the actor. Combined losses for the same wallet now total approximately $49.8M across two incidents over three years.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)