📈 Get daily crypto insights that make you smarter about your money

Hundreds of Dormant Ethereum Wallets Drained in Coordinated Exploit Raising Key Security Fears

On April 30, blockchain investigator WazzCrypto flagged a chilling discovery on Ethereum mainnet: hundreds of long-dormant wallets had been systematically drained into a single tagged address, turning old key exposure into one of the sharpest crypto security warnings of the year. By May 1, the scale of the incident became clear — over 500 wallets, some idle for four to eight years, had been quietly emptied of approximately 260 ETH, worth roughly $600,000 at current prices near $2,295 per ether. Total losses across affected wallets approached $800,000.

The Exploit Mechanics

The attacker consolidated drained funds into an Etherscan-labeled address tagged Fake_Phishing2831105, which recorded 596 transactions and moved approximately 324.741 ETH through the THORChain Router v4.1.1 during the April 30 window. Unlike typical DeFi exploits that target smart contract vulnerabilities, this attack operated at the wallet layer itself. The affected wallets shared a common pattern: they were old, largely untouched accounts that had been quiet for years before suddenly activating and transferring their entire balances to the attacker’s collection address.

What makes this attack particularly concerning is the absence of a clear compromise vector. The wallets did not interact with any new phishing contracts or suspicious dApps before being drained. Instead, the attacker appears to have obtained private keys or seed phrases through historical exposure — potentially from weak entropy in legacy wallet generation tools, compromised mnemonic storage, or leaked key material from earlier breaches. Multiple affected users have raised the possibility that the compromise traces back to the 2022 LastPass breach, where encrypted vault data was exfiltrated and has been slowly cracked by attackers over the intervening years.

Affected Systems

The incident affected Ethereum mainnet wallets spanning multiple generations of tooling. Some wallets dated back to the 2017-2018 ICO era, while others were created during the 2020-2021 DeFi summer. The diversity of affected wallets suggests the compromise is not limited to a single wallet application or generation tool. Any wallet whose seed phrase was stored in a compromised password manager, generated using weak random number generators, or exposed through other historical breaches could be at risk.

This attack landed amid an already devastating month for crypto security. April 2026 became the most hacked month in crypto history, with DefiLlama recording 28 to 30 separate incidents totaling over $625 million in stolen funds. The Wasabi Protocol lost $4.5 to $5.5 million through an admin key exploit, and the Drift decentralized exchange suffered a $285 million social engineering attack. The dormant wallet drain adds a distinctly personal dimension to this wave, as it targets individual holders rather than protocol treasuries.

The Mitigation Strategy

For users holding significant value in older wallets, the response is straightforward but urgent. Idleness does not mitigate private key risk. A wallet’s security depends on the full history of its key — the device that generated it, the software that touched it, every location where the seed phrase was stored, and every tool that had access to the private key material.

The recommended course of action is to immediately inventory any high-value wallets that have been dormant for extended periods, generate fresh key material using modern hardware wallets with strong entropy sources, and transfer funds to these new addresses. Users should never enter old seed phrases into online checkers, recovery scripts, or unfamiliar verification tools, as these can be harvesting fronts. For wallets that used password managers for seed storage, particularly LastPass prior to its 2022 breach, migration should be treated as time-critical.

Lessons Learned

This incident exposes a fundamental truth about crypto security that many users overlook: the security of a wallet does not improve with time. Unlike traditional financial accounts that benefit from institutional monitoring and fraud detection, a cryptocurrency wallet’s security is only as strong as the moment its keys were generated and every interaction since. A seed phrase exposed in 2022 can be exploited in 2026 with no warning and no recourse.

The attack also highlights the long tail of data breaches in the crypto space. When password managers or cloud storage services are compromised, the stolen data does not expire. Attackers can spend years brute-forcing encrypted vaults or correlating leaked data across multiple breaches before finding the keys to unlock valuable wallets. The four-to-eight-year dormancy period of the affected wallets suggests the attacker has been patient and methodical, building a database of vulnerable addresses over an extended period.

User Action Required

If you hold cryptocurrency in wallets created before 2023, especially if seed phrases were ever stored digitally, take immediate action. Generate new wallets using trusted hardware devices, transfer assets, and verify that old wallets are fully emptied. Monitor the tagged address on Etherscan for any connection to your historical activity. The crypto ecosystem rewards proactive security — in this case, silence from your old wallets does not mean safety.

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research and consult with security professionals regarding your specific situation.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

27 thoughts on “Hundreds of Dormant Ethereum Wallets Drained in Coordinated Exploit Raising Key Security Fears”

    1. 500 dormant wallets drained through a single collection address. the LastPass breach from 2022 is the likely root cause. encrypted vaults being slowly cracked over years

      1. wallet_dr the LastPass breach angle is terrifying. encrypted vaults from 2022 being cracked in 2026 means anyone who stored seed phrases in any cloud password manager from that era should rotate everything immediately

        1. vault_migrate_

          LastPass vaults from 2022 being cracked in 2026 is the slowest ticking bomb in crypto. if you ever stored a seed phrase in a password manager move those funds NOW

          1. lastpass_refugee_

            vault_migrate_ moved everything off LastPass in January 2023. the encryption was AES-256 but if your master password was weak its crackable on consumer GPUs now

          2. 4 years sitting on cracked LastPass vaults waiting for ETH to pump before draining. cold patience from the attacker, terrifying for anyone who stored seeds in browser extensions back then

          3. phantom_w_ 4 years of patience waiting for ETH to pump before draining. that kind of discipline is scarier than any DeFi exploit

          4. phantom_w_ 4 years of patience is what makes LastPass the slowest ticking bomb in crypto. seeds stored in 2022 are still being cracked today

      2. the LastPass angle explains why wallets from 2017-2018 were targeted specifically. those were the years people were most likely storing seed phrases in password managers

        1. dormant_wallet_scout

          Brecht D. the 2017-2018 targeting window lines up perfectly with when LastPass was the default recommendation for seed phrase storage. everyone did it, nobody thought twice

  1. cold_storage_grind

    500 wallets drained and the only takeaway is LastPass was bad. nobody talks about how exchange withdrawal flows in 2017-2018 exposed keys the same way. the attack surface was way bigger than one password manager

    1. waiting 4 to 8 years before draining suggests the attacker was monitoring these keys passively the whole time. that kind of automated key-watching infrastructure is the scary part, not the phishing label

  2. cold_storage_grind

    500 wallets drained and the only takeaway is LastPass was bad. nobody talks about how exchange withdrawal flows in 2017-2018 exposed keys the same way. the attack surface was way bigger than one password manager

    1. waiting 4 to 8 years before draining suggests the attacker was monitoring these keys passively the whole time. that kind of automated key-watching infrastructure is the scary part, not the phishing label

    1. Raluca Dumitrescu

      260 ETH stolen from wallets idle for 4-8 years. if you have old wallets from 2017-2018 sitting in LastPass, move those funds now. the cracking is ongoing

      1. Raluca this is exactly why I moved everything off LastPass in 2023. the slow cracking of encrypted vaults is a ticking time bomb for thousands of crypto users

  3. Tomasz Kowalski

    596 transactions flowing into a single collection address and nobody noticed for hours. on-chain monitoring tools need to do better at flagging unusual consolidation patterns from dormant wallets

    1. Sebastien C.

      Tomasz Kowalski 596 transactions into one address and THORChain router processing the exit. mixing privacy protocols with stolen funds is why regulators come for the whole stack

  4. 500 dormant wallets drained through one collection address. the attacker knew exactly which keys were compromised and waited years to use them. patience from a thief is terrifying

    1. waiting 4 years to crack LastPass vaults and drain 500 wallets is next level patience. most attackers would have dumped everything within months

  5. 500 wallets drained through Fake_Phishing2831105 and the funds went through THORChain router. privacy chains are great for criminals and terrible for everyone else

    1. key_entropy_

      260 ETH across 500 wallets is barely $500 per victim. thats why nobody noticed til WazzCrypto flagged it. small balances, old keys, zero monitoring

      1. key_entropy_ $500 average per victim is why law enforcement wont touch this. 500 small victims vs one 50M hack. resources go where the headlines are

  6. seed_migrate_

    LastPass breach in 2022 is the trojan horse of crypto. seeds stored in notes, passwords in vaults. the cracking will continue for years as GPU costs drop

  7. waiting 4 years on cracked LastPass vaults to drain at ETH price peaks. the patience alone makes this scarier than any DeFi hack

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,487.00+0.2%ETH$1,896.84+1.2%SOL$73.47-1.1%BNB$592.50-1.7%XRP$1.05-2.6%ADA$0.1908-0.9%DOGE$0.0696-0.9%DOT$0.8407-2.0%AVAX$6.63-1.1%LINK$8.11-0.9%UNI$4.10+5.4%ATOM$1.34-3.0%LTC$44.99-0.3%ARB$0.0797-2.1%NEAR$1.70-1.8%FIL$0.7094-1.2%SUI$0.6849-1.4%BTC$64,487.00+0.2%ETH$1,896.84+1.2%SOL$73.47-1.1%BNB$592.50-1.7%XRP$1.05-2.6%ADA$0.1908-0.9%DOGE$0.0696-0.9%DOT$0.8407-2.0%AVAX$6.63-1.1%LINK$8.11-0.9%UNI$4.10+5.4%ATOM$1.34-3.0%LTC$44.99-0.3%ARB$0.0797-2.1%NEAR$1.70-1.8%FIL$0.7094-1.2%SUI$0.6849-1.4%
Scroll to Top