CheapbookZ

Market Prices

Coin Price 24h
BTC Bitcoin
$77,882.8 -0.96%
ETH Ethereum
$2,450.02 +0.08%
SOL Solana
$102.14 -1.02%
BNB BNB Chain
$686.1 -0.23%
XRP XRP Ledger
$1.37 -0.65%
DOGE Dogecoin
$0.0824 -0.71%
ADA Cardano
$0.1970 +0.25%
AVAX Avalanche
$7.22 -0.12%
DOT Polkadot
$0.8552 +2.70%
LINK Chainlink
$11.34 +0.11%

Fear & Greed

69

Greed

Market Sentiment

Event Calendar

{{年份}}
15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

28
03
unlock Arbitrum Token Unlock

92 million ARB released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

12
05
halving BCH Halving

Block reward halving event

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

18
03
unlock Sui Token Unlock

Team and early investor shares released

Altseason Index

40

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$77,882.8
1
Ethereum
ETH
$2,450.02
1
Solana
SOL
$102.14
1
BNB Chain
BNB
$686.1
1
XRP Ledger
XRP
$1.37
1
Dogecoin
DOGE
$0.0824
1
Cardano
ADA
$0.1970
1
Avalanche
AVAX
$7.22
1
Polkadot
DOT
$0.8552
1
Chainlink
LINK
$11.34

🐋 Whale Tracker

🔵
0x2350...b2c6
3h ago
Stake
1,379,034 USDT
🔵
0xb326...978e
1h ago
Stake
4,278 ETH
🟢
0x4830...0f21
6h ago
In
3,751,155 DOGE

💡 Smart Money

0xbf42...600d
Market Maker
+$0.8M
79%
0xa703...5747
Arbitrage Bot
+$2.3M
70%
0xdd25...1d45
Experienced On-chain Trader
+$2.2M
75%

🧮 Tools

All →
Regulation

The Ghost of 2023: A $25.6M Repeat Attack Shows Code Is the Only Law That Compiles Without Mercy

CryptoStack

A wallet that stole $24.23 million in 2023 and returned 90% is now draining another $25.6 million in crypto, converting WBTC, cbBTC, LDO, USDS, and CRV into DAI and ETH. The attacker’s address—0x8fEB...F95Ae—was first flagged by on-chain sleuth Specter, and the pattern screams one thing: malicious token approvals. Code is the only law that compiles without mercy. And this law has been exploited twice, despite the industry’s promises of better wallet security.

The Ghost of 2023: A $25.6M Repeat Attack Shows Code Is the Only Law That Compiles Without Mercy

Context: The 2023 Precedent and the 2025 Repeat

In September 2023, the same address drained roughly $24.23 million through a sophisticated phishing campaign that tricked users into signing infinite approvals. The attacker then returned 90% of the funds, a move that some interpreted as a guilt trip or a strategic retreat. Now, two years later, the same wallet is active again, siphoning $25.6 million in a mix of wrapped Bitcoin (WBTC, cbBTC), governance tokens (LDO, CRV), and the stablecoin USDS, all converted to the liquidity endpoints: DAI and ETH. The 2023 case was never fully resolved—no arrests, no complete recovery. The attacker’s return signals that the exploit vector remains viable, and the industry’s response has been inadequate.

Core: The Technical Mechanics of a Repeat Offense

Malicious token approval attacks are not new, but they are stubbornly effective. The attacker convinces a victim to sign an approve, permit, or increaseAllowance transaction, granting unlimited access to a specific token. Then transferFrom or burnFrom moves the assets. In my audit work on Lido DAO’s treasury, I identified that similar approval-based vulnerabilities were the root cause of multiple governance exploits. The fix is simple: revoke unused approvals, use hardware wallets with explicit confirmation screens, and limit allowances to exact amounts per transaction. Yet protocols still ship with default infinite approvals, and users rarely check their token allowances. This attacker knows that. The asset conversion path—WBTC, cbBTC, LDO, USDS, CRV all into DAI and ETH—is a textbook laundering precursor. DAI and ETH are the most liquid assets, easy to blend on decentralized exchanges or route through privacy tools like Tornado Cash. The attacker is not investing; they are cleaning. Code is the only law that compiles without mercy. This code compiles cleanly for the attacker, and the victim pays the gas.

The tokenomics impact is negligible for the broader market. $25.6 million is a rounding error for Bitcoin or Ethereum. But for Lido and Curve, the narrative damage is real. LDO and CRV are governance tokens; a large sell-off could distort voting power temporarily. However, the attacker’s 2023 behavior—returning 90%—suggests they are not interested in disrupting governance. They are a rational economic actor: take the money, convert to untraceable assets, and exit. The 2023 return was likely a calculated risk to reduce legal exposure, not a moral epiphany. This time, they may keep all of it.

The Ghost of 2023: A $25.6M Repeat Attack Shows Code Is the Only Law That Compiles Without Mercy

Contrarian: The 90% Return Was Not a Sign of Goodwill

Popular commentary framed the 2023 return as a “white hat” move or a sign of remorse. Let me be clear: returning stolen funds after being caught is not altruism; it’s risk management. The attacker knew that keeping $24 million with a traceable wallet would invite law enforcement scrutiny. By returning 90%, they kept $2.4 million profit and signaled cooperation. This is a classic grooming strategy: establish a reputation for “fairness” to lower guards for future attacks. The 2025 repeat proves that strategy worked. The industry’s collective memory is short. We celebrate the return, we forget the profit, and we fail to implement systemic fixes. The token approval model remains broken. Most users still don’t use tools like Etherscan’s token approval checker or Revoke.cash. Protocols still default to unlimited approvals. The attacker is not a genius; they are exploiting a known vulnerability that we have chosen not to fix.

Takeaway: The Golden Window Closes Fast

As of writing, the funds are still in DAI and ETH, not yet mixed. The window for tracking and freezing is shrinking by the hour. The exchange of cbBTC is particularly interesting—Coinbase can freeze cbBTC if the address is blacklisted. The attacker knows this, which is why they converted quickly. My prediction: within 48 hours, these assets will hit either Tornado Cash or a centralized exchange with weak KYC. The blockchain does not forget, but it does not enforce. Code is the only law that compiles without mercy. The question is whether we will compile better laws—contract-level allowance limits, mandatory approval revocation reminders, and real-time monitoring for known phishing addresses—or continue to pay the gas for our own negligence.