TL;DR:
A hack via private key compromise caused losses of more than $26 million in assets across three wallets linked to the whale known as TLBL, according to blockchain analytics platform Lookonchain.
This incident is not the first this trader has suffered: in 2024, a phishing attack had already drained $24 million in stETH and rETH. The combined total of both losses amounts to approximately $50.3 million, according to tracking conducted by Lookonchain.
Insane!
More than $50M has been stolen from whale "TLBL".
Two years ago, whale "TLBL" lost $24M in a phishing attack.
Today, the whale appears to have had its private key compromised, and over $26M in assets across 3 wallets were completely drained.https://t.co/JVrb19u5gi pic.twitter.com/m3DNL6whov
— Lookonchain (@lookonchain) August 13, 2026
Security firm PeckShield specified that the stolen assets included approximately $6.3 million in aWBTC, $5.1 million in DAI, $4.7 million in WBTC and $2.6 million in ETH, among other tokens. Following the hack, the attacker converted part of the funds into roughly 20 million DAI and around 3,000 ETH, valued at approximately $5.64 million at current market prices. The funds are distributed across four separate addresses.
#PeckShieldAlert Specter has reported that unknown victims were drained of $25.6M in crypto, including aWBTC ($6.3M), DAI ($5.1M), WBTC ($4.7M), and ETH ($2.6M).
The hacker has swapped the stolen funds for 20M $DAI and 3K $ETH ($5.64M) and now holds them across 4 addresses. pic.twitter.com/GcmqDA91MW
— PeckShieldAlert (@PeckShieldAlert) August 13, 2026
The TLBL case joins the growing list of incidents this year, which has already accumulated historic figures. According to a report by Blockaid published on August 1, hackers stole $1.1 billion across 212 attacks during the first half of 2026.

Misuse of private keys led to the loss of approximately $790 million of that total, close to 75% of all funds stolen during the period. Monthly incidents escalated from 18 in January to 57 in June, reflecting a consistent deepening of attacks.
Lookonchain also identified this week a separate case of address poisoning, in which a victim lost $100,000 by copying a fake address from their transaction history without verifying it. Although the method differs from private key compromise, both cases point to the same structural problem: wallets remain the weakest link in the ecosystem.

According to data from Nominis, security incidents in the crypto market generated cumulative losses of approximately $1.65 billion in the first seven months of 2026. April was the most damaging month, marked by hacks on Kelp DAO and Drift Protocol, which together lost approximately $578 million. July ranks second, with $242 million in losses, of which $116 million stemmed from a firmware vulnerability in Coldcard hardware wallets by Coinkite.