Two Crypto Hacks Drain Over $51M Through Key Compromises

Two Crypto Hacks Drain Over $51M Through Key Compromises
Table of Contents

TL;DR:

  • A private key compromise hack stole more than $26M from three wallets linked to whale TLBL, who had already lost $24M in 2024.
  • PeckShield identified the stolen assets: $6.3M in aWBTC, $5.1M in DAI, $4.7M in WBTC and $2.6M in ETH, later partially converted into DAI and ETH.
  • In the first half of 2026, $1.1 billion was stolen across 212 attacks; private key misuse accounted for nearly 75% of all cases.

A hack via private key compromise caused losses of more than $26 million in assets across three wallets linked to the whale known as TLBL, according to blockchain analytics platform Lookonchain.

This incident is not the first this trader has suffered: in 2024, a phishing attack had already drained $24 million in stETH and rETH. The combined total of both losses amounts to approximately $50.3 million, according to tracking conducted by Lookonchain.

Security firm PeckShield specified that the stolen assets included approximately $6.3 million in aWBTC, $5.1 million in DAI, $4.7 million in WBTC and $2.6 million in ETH, among other tokens. Following the hack, the attacker converted part of the funds into roughly 20 million DAI and around 3,000 ETH, valued at approximately $5.64 million at current market prices. The funds are distributed across four separate addresses.

A Record Year in Hacks: The Weakness of Private Keys

The TLBL case joins the growing list of incidents this year, which has already accumulated historic figures. According to a report by Blockaid published on August 1, hackers stole $1.1 billion across 212 attacks during the first half of 2026.

Hackers exploit wallet

Misuse of private keys led to the loss of approximately $790 million of that total, close to 75% of all funds stolen during the period. Monthly incidents escalated from 18 in January to 57 in June, reflecting a consistent deepening of attacks.

Lookonchain also identified this week a separate case of address poisoning, in which a victim lost $100,000 by copying a fake address from their transaction history without verifying it. Although the method differs from private key compromise, both cases point to the same structural problem: wallets remain the weakest link in the ecosystem.

Seguridad

According to data from Nominis, security incidents in the crypto market generated cumulative losses of approximately $1.65 billion in the first seven months of 2026. April was the most damaging month, marked by hacks on Kelp DAO and Drift Protocol, which together lost approximately $578 million. July ranks second, with $242 million in losses, of which $116 million stemmed from a firmware vulnerability in Coldcard hardware wallets by Coinkite.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews