Whale wallet TLBL has lost more than $26 million in a second major crypto theft, two years after a phishing attack drained $24 million from the holder.

The latest incident appears to involve a compromised private key, raising a difficult question for large crypto holders: how much can stronger security practices help when a wallet has already been targeted?

TLBL Loses $26M in Second Attack

Lookonchain reported on August 13 that more than $26 million in assets had been drained from three wallets linked to TLBL. The blockchain analytics account said the whale “appears to have had its private key compromised,” with the stolen assets including aWBTC, DAI, WBTC, ETH, aUSDC, sDAI, USDS, cbBTC, and several other tokens.

Lookonchain’s analysis puts the total value of assets associated with TLBL’s two thefts at about $50.3 million. The earlier incident, which took place two years ago, involved 9,579 stETH worth $15.54 million and 4,851 rETH worth $8.51 million being stolen in a phishing attack.

The latest loss is different. PeckShield said that the victim had lost about $25.6 million, including roughly $6.3 million in aWBTC, $5.1 million in DAI, $4.7 million in WBTC, and $2.6 million in ETH. According to the security firm, the attacker had already swapped part of the stolen holdings into 20 million DAI and about 3,000 ETH, worth about $5.64 million, with the funds spread across four addresses.

The slight difference between the figures from Lookonchain and PeckShield comes from the asset valuations included in their respective tracking. Both accounts, however, point to the same broad event: a large TLBL-linked wallet was drained, with private-key compromise identified as the apparent cause by Lookonchain.

Separately, Lookonchain flagged a smaller case this week involving address poisoning, where a victim copied a wallet address straight from their transaction history without checking it and sent funds to a lookalike address controlled by an attacker, losing $100,000 in the process. It’s a different method than what hit TLBL, but it points to the same underlying problem: wallets are still one of the weakest links.

A Bad Year for Private Keys

TLBL’s second hit lands in the middle of what has already been a record run for crypto theft. A Blockaid report published August 1 found hackers stole $1.1 billion across 212 incidents in the first half of 2026, and privileged key misuse, the same category as what hit TLBL today, accounted for roughly $790 million of that total, about three-quarters of all funds stolen in the period.

Monthly incident counts climbed from 18 in January to 57 in June. Blockaid separately found that North Korea-linked hackers accounted for about 55% of all funds stolen in the period, about $609 million, although so far nothing in the data tied to TLBL’s case points to that cluster specifically.

The post Crypto Whale Loses $26M After Apparent Private Key Compromise appeared first on CryptoPotato.

By

Leave a Reply

Your email address will not be published. Required fields are marked *