In September 2023, a crypto holder lost about $24 million in a sophisticated phishing attack that drained their staked Ether (stETH) and rETH (liquid staking tokens from Lido and Rocket Pool) after they were tricked into signing a malicious smart contract approval. The attacker later routed many transfers of roughly $100,000 each through the FixedFloat exchange, a venue frequently used by hackers to obfuscate stolen funds. Nearly a year after the theft, on July 6, 2024, the victim received an unexpected on‑chain message from a new address in which the attacker wrote, “Hello, I am the guy who took your money… I want to give the money back, waiting for your reply.” On‑chain data shows that the attacker has since begun returning part of the haul, sending three transactions totaling 10.3 million DAI to the victim’s address. The victim acknowledged receipt of the 10.3 million DAI in an on‑chain message and asked for the remaining funds to be sent back, but as of the time of reporting only less than half of the original $24 million had been refunded. The episode underscores both the ongoing risk of phishing attacks in DeFi and the unusual dynamic in which some attackers later attempt partial restitution, facilitated and documented entirely through on‑chain communication and stablecoin transfers.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on $DAI

Comments