Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
No Result
View All Result

Someone just drained long-forgotten dormant Ethereum wallets, and the cause may trace back years

CryptoExpert by CryptoExpert
May 1, 2026
in Trending Cryptos
0
Someone just drained long-forgotten dormant Ethereum wallets, and the cause may trace back years
  • Facebook
  • Twitter
  • Pinterest


You might also like

ew Ledger Scan Shows How Much XRP Is Quantum-Exposed

US Treasury yields spike to highest levels in a year adding new problem for Bitcoin liquidity

Cardano Builder IO Says It Delivered 16 Of 18 Treasury Commitments

Make CryptoSlate preferred on

Hundreds of Ethereum wallets that had sat untouched for years were drained into the same tagged address, turning old key exposure into this week’s sharpest crypto security warning.

On Apr. 30, WazzCrypto flagged the incident affecting mainnet wallets on X, and their warning spread quickly because the affected accounts did not appear to be freshly baited hot wallets. They were old wallets with quiet histories, some tied to assets and tooling from an earlier Ethereum era.

Over 260 ETH, roughly $600,000, was drained from hundreds of dormant wallets. More than 500 wallets appear to be affected, with losses totaling roughly $800,000, and many wallets have been idle for four to eight years. The related Etherscan address is labeledFake_Phishing2831105, and shows 596 transactions, and records a 324.741 ETH movement to THORChain Router v4.1.1 around the Apr. 30 window.

The constant across them is more important for now: long-idle wallets have been moved to a common destination, while the compromise path remains unresolved.

Tokenmetrics

That unresolved vector makes the drain the strongest warning this week, following a surge in DeFi hacks. Protocol exploits usually give investigators a contract, a function call, or a privileged transaction to inspect.

Here, the central question sits at the wallet layer. Did someone obtain old seed phrases, crack weakly generated keys, use leaked private-key material, abuse a tool that once handled keys, or exploit another path that has yet to surface?

Public discussion has produced theories including weak entropy in legacy wallet tools, compromised mnemonics, trading-bot key handling, and LastPass-era seed storage. One affected user personally raised the LastPass theory.

The practical advice for users is limited but urgent. Idleness does not mitigate private-key risk. A wallet with value depends on the full history of the key, the seed phrase, the device that generated it, the software that touched it, and every place that secret may have been stored.

For users, the response is probably to inventory high-value old wallets, move funds only after setting up fresh key material through trusted hardware or modern wallet software, and avoid entering old seeds into checkers, scripts, or unfamiliar recovery tools. Revoking approvals helps for protocol exposure, including Wasabi’s user warning, but a direct wallet drain points first to key security rather than token approvals.

April widened the control surface

The wallet cluster landed amid April’s crypto exploit tally, which was already elevated. DefiLlama-linked reporting put April at roughly 28 to 30 incidents and more than $625 million in stolen funds. As of May 1, the live DefiLlama API showed 28 April incidents totaling $635,241,950.

A May 1 market thread captured the pressure point: this week’s wallet drains, Wasabi Protocol’s admin-key exploit, and April’s larger DeFi losses all hit control surfaces that ordinary users rarely inspect. The link across the month is architectural rather than attributional.

Timeline infographic showing April 2026 Drift, KelpDAO, Wasabi, and dormant Ethereum wallet incidents with loss amounts and hidden control points.

North Korea hit crypto for $500M+ this month — and the $6.75 billion threat is not over yetNorth Korea hit crypto for $500M+ this month — and the $6.75 billion threat is not over yet
Related Reading

North Korea hit crypto for $500M+ this month — and the $6.75 billion threat is not over yet

Drift Protocol and KelpDAO were hit for roughly $286 million and $290 million as attackers targeted peripheral infrastructure.

Apr 21, 2026 · Oluwapelumi Adejumo

Admin paths became attack paths

Wasabi Protocol supplies the clearest recent protocol example. The Apr. 30 exploit reportedly drained roughly $4.5 million to $5.5 million after an attacker gained deployer/admin authority, granted ADMIN_ROLE to attacker-controlled contracts, and used UUPS proxy upgrades to drain vaults and pools across Ethereum, Base, and Blast. Early security alerts flagged the admin-upgrade pattern as the attack unfolded.

The reported mechanics put key management at the center of the incident. Upgradeability can be normal maintenance infrastructure. Concentrated upgrade authority turns that maintenance path into a high-value target. If one deployer or privileged account can change implementation logic across chains, the boundary around an audited contract can vanish once that authority is compromised.

That is the user-facing problem hidden inside many DeFi interfaces. A protocol can present open contracts, public front ends, and decentralization language while critical upgrade power still sits in a small set of operational keys.

Signers and verifiers carried the largest losses

Drift pushed the same control problem into signer workflow. Chainalysis described social engineering, durable nonce transactions, fake collateral, oracle manipulation, and a zero-timelock 2-of-5 Security Council migration. Blockaid put the loss around $285 million and argued that transaction simulation and stricter co-signer policies could have changed the outcome.

The Drift case matters here because the path did not depend on a simple public-function bug. It depended on a workflow where valid signatures and fast governance machinery could be turned toward a hostile migration. A signer process became the control surface.

Compromised developers lying dormant within crypto projects risks next major crypto exploitCompromised developers lying dormant within crypto projects risks next major crypto exploit
Related Reading

Compromised developers lying dormant within crypto projects risks next major crypto exploit

The bigger risk after Drift may be the access attackers gain before a protocol knows it has a problem.

Apr 8, 2026 · Gino Matos

KelpDAO moved the stress test into cross-chain verification. The incident statement described a bridge configuration in which the rsETH route used LayerZero Labs as the sole DVN verifier. Forensic reviews described compromised RPC nodes and DDoS pressure feeding false data to a single-point verification path.

CryptoSlate Daily Brief

Daily signals, zero noise.

Market-moving headlines and context delivered every morning in one tight read.

5-minute digest 100k+ readers

Free. No spam. Unsubscribe any time.

Whoops, looks like there was a problem. Please try again.

You’re subscribed. Welcome aboard.

The result, according to Chainalysis, was 116,500 rsETH, worth roughly $292 million, released against a non-existent burn. The token contract could remain intact while the bridge accepted a false premise. That is why a verifier failure can become a market-structure problem once the bridged asset sits inside lending markets and liquidity pools.

DeFi lost $13B this month as the KelpDAO rescue shows both the best and worst of DeFiDeFi lost $13B this month as the KelpDAO rescue shows both the best and worst of DeFi
Related Reading

DeFi lost $13B this month as the KelpDAO rescue shows both the best and worst of DeFi

The rescue effort that has already lined up tens of thousands of ETH also exposes the uncomfortable reality that DeFi’s biggest crises still depend on multiple factors.

Apr 26, 2026 · Gino Matos

AI belongs in the speed discussion

I think Project Glasswing deserves a special mention here for context, separate from causation. Anthropic says Claude Mythos Preview found thousands of high-severity software vulnerabilities and shows how AI can compress vulnerability discovery. That raises the bar for defenders, but the causal record in these crypto incidents points to keys, signers, admin powers, bridge verification, RPC dependencies, and unresolved wallet exposure.

The security implications are still serious. Faster discovery gives attackers and defenders more parallel surface to work through. It also makes old operational shortcuts more expensive because dormant secrets, privileged keys, and single-verifier paths can be tested faster than teams can manually review them.

The repair list is operational

The controls that follow from April sit above and around the codebase.

IncidentHidden control pointFailure modePractical controlDormant Ethereum walletsOld wallet materialFunds moved from long-idle wallets into a tagged address while the vector remains unresolvedFresh key generation for valuable dormant funds, cautious migration, and no seed entry into unknown toolsWasabiAdmin and upgrade authorityPrivileged role grants and UUPS upgrades enabled vault and pool drainsKey rotation, stronger thresholds, bounded admin powers, timelocks, and independent monitoring of upgrade actionsDriftSecurity Council signer workflowPre-signed durable nonce transactions and zero-delay governance enabled fast admin takeoverHigher thresholds, delay windows, transaction simulation, and policy-enforced co-signingKelpDAOBridge verification pathRPC poisoning and a 1-of-1 DVN route allowed a false cross-chain message to passMulti-DVN verification, cross-chain invariant monitoring, and independent checks outside the same verifier path

Control map infographic showing admin keys, signer workflows, bridge verifiers, and old wallet material with operational defenses and user checks.Control map infographic showing admin keys, signer workflows, bridge verifiers, and old wallet material with operational defenses and user checks.

For protocols, the priority is to reduce the amount that any single authority can do at once. That means time locks on admin operations, stronger and more stable signer thresholds, monitored privileged-transaction queues, explicit limits on parameter changes, and co-signing systems that simulate transaction effects before humans approve them.

For bridges, the priority is independent verification and invariant checks. A cross-chain message should be tested against the economic fact it claims to represent. If rsETH leaves one side, the system should verify the corresponding state change on the other side before the destination side releases value. That monitoring needs to exist outside the same path that signs the message.

For users, the repair list is smaller. Move valuable old funds to fresh keys through a process you already trust. Separate that action from protocol-specific approval cleanup. Treat every claim about the wallet-drain root cause as provisional until forensic work identifies a common tool, storage path, or exposure source.

The next test

April proved that the average user’s security checklist is likely incomplete. Audits, public contracts, and decentralized interfaces can coexist with concentrated admin authority, weak signer procedures, brittle bridge verification, and old wallet secrets.

The next quarter will reward proof over decentralization language: constrained upgrade powers, visible timelocks, independent verifier paths, transaction simulation for privileged actions, disciplined access controls, and documented key rotation.

The dormant-wallet drains show the uncomfortable user-side version of the same problem. A system can look quiet while an old control failure waits in the background. April’s exploit wave exposed that layer above the code; the next phase will show which teams treat it as core security before funds move.



Source link

  • Facebook
  • Twitter
  • Pinterest
Tags: Ethereum
CryptoExpert

CryptoExpert

Recommended For You

ew Ledger Scan Shows How Much XRP Is Quantum-Exposed

by CryptoExpert
May 1, 2026
0
New Ledger Scan Shows How Much XRP Is Quantum-Exposed

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure A full-history scan of the XRP Ledger has put fresh numbers on one of crypto’s...

Read more

US Treasury yields spike to highest levels in a year adding new problem for Bitcoin liquidity

by CryptoExpert
April 30, 2026
0
US Treasury yields spike to highest levels in a year adding new problem for Bitcoin liquidity

Make CryptoSlate preferred on Bitcoin's April rebound is now facing a two-front macro test. The official Treasury curve for Apr. 29 placed the 10-year yield at 4.42%, the...

Read more

Cardano Builder IO Says It Delivered 16 Of 18 Treasury Commitments

by CryptoExpert
April 30, 2026
0
Cardano Builder IO Says It Delivered 16 Of 18 Treasury Commitments

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Input Output said it progressed 16 of 18 treasury-funded Cardano commitments across Q4 2025 and...

Read more

Bitcoin surges alongside oil as BTC price finally decouples from the war narrative… until US markets opened

by CryptoExpert
April 29, 2026
0
Bitcoin surges alongside oil as BTC price finally decouples from the war narrative… until US markets opened

Make CryptoSlate preferred on Bitcoin is trading near $76,600 after reversing from an earlier intraday push toward $78,000, while crude oil trades near $103 and the S&P 500...

Read more

Bitcoin Coinbase Gap Breaks Green Streak: US Selling Back?

by CryptoExpert
April 29, 2026
0
Bitcoin

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure American Bitcoin sellers may be making a return as data shows the Coinbase Premium Gap...

Read more
Next Post
Cointelegraph

Dogecoin May Rise 20% in May as DOGE Whale Holdings Hit Record Levels

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

Sitemap

  • Market Cap
  • Donations
  • Trading
  • Mining
  • Contact

Legal Information

  • Privacy Policy
  • Anti-Spam Policy
  • Copyright Notice
  • DMCA Compliance
  • Social Media Disclaimer
  • Terms Of Service

Categories

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

© Copyright 2024 InvestInCryptoNews.com

No Result
View All Result
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO

© Copyright 2024 InvestInCryptoNews.com

This website is using cookies to improve the user-friendliness. You agree by using the website further.

Privacy policy
bitcoin
Bitcoin (BTC) $ 78,537.00
ethereum
Ethereum (ETH) $ 2,308.76
tether
Tether (USDT) $ 0.999813
xrp
XRP (XRP) $ 1.39
bnb
BNB (BNB) $ 620.43
usd-coin
USDC (USDC) $ 0.999753
solana
Solana (SOL) $ 84.16
tron
TRON (TRX) $ 0.326577
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03
staked-ether
Lido Staked Ether (STETH) $ 2,265.05

Pin It on Pinterest

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?