How a Dormant Approval Enabled a $13.3M Ethereum Exploit

LiveBTCNews
ETH-0,54%

An old Ethereum token approval was exploited, allowing an attacker to drain $13.3M from a wallet within seconds of receiving funds.

An Ethereum wallet lost about $13.3 million in seconds after a long-forgotten token approval was activated.

The funds arrived through an account abstraction transaction, and the attacker acted immediately. Blockchain data shows the wallet had unknowingly granted spending rights weeks earlier.

Once the transfer landed, the approval allowed full access without further confirmation. The incident shows how dormant permissions can remain active and be used without warning.

Wallet Receives Funds and Is Drained Quickly

The victim wallet, identified as 0xba15E9b644685cB845aF18a738Abd40C6Bcd78eD, received about $13.3 million in a single transaction.

The attacker executed the transfer using an account abstraction mechanism designed to simplify wallet operations.

Moreover, blockchain records show the funds arrived and the attacker removed them within seconds. Consequently, the rapid timing left no window for manual intervention or defensive action.

The speed of the drain suggested the attacker did not need new permissions. Instead, the attacker already had access before the transfer occurred.

Additionally, security trackers confirmed that no new approval transactions took place during the incident. This ruled out common phishing or signature-based attacks.

Investigators then reviewed historical onchain activity linked to the wallet. Their focus shifted to older token approvals that had never been revoked.

This review revealed an earlier approval that still allowed third-party spending. That dormant permission became the entry point for the exploit.

Old Approval Enabled the Exploit

Investigators traced the root cause to an approval transaction made on January 1, 2026. That call granted spending rights to address 0x616000e384Ef1C2B52f5f3A88D57a3B64F23757e.

At the time, the approval did not raise public concern. The permission remained active and was not revoked.

An old approval just cost $13.3M.

The victim address 0xba15E9b644685cB845aF18a738Abd40C6Bcd78eD received ~$13.3M via an account abstraction transaction and was drained within seconds.

The root cause traces back to an approve() call made on Jan 1, 2026, granting spending rights… pic.twitter.com/vDVhX8emXD

— QuillAudits 🥷 (@QuillAudits_AI) January 26, 2026

The attacker address, 0x6cAad74121bF602e71386505A4687f310e0D833e, later used this approval.

It allowed full access to the incoming funds. Once the funds arrived, the attacker executed transfers without delay. The attacker removed the entire balance in one coordinated action.

Fund Movements After the Drain

After the drain, the attacker swapped the stolen assets from tokens into WETH and then into ETH. These steps reduced exposure to token-level tracking.

The attacker then moved funds across multiple wallets. Transfers were fast and spread across several addresses.

This method created a complex transaction pattern. Attackers often use such patterns to slow down tracing efforts.

Blockchain analysis shows a portion of the ETH remains on-chain. These funds sit in addresses still linked to the attacker.

Related Reading: $25M in Losses: Machi Liquidated for 1,000 ETH After Market Drop

Ongoing Onchain Observations

Security observers continue monitoring the attacker-linked wallets. However, investigators found no mixing services during the initial movements.

The presence of funds on-chain leaves room for tracking. Analysts rely on transaction timing and address links.

The incident shows how older approvals can remain active. Wallet owners often forget these permissions over time. The event adds to recent cases involving stale approvals. It reinforces the need for regular permission reviews.

As of the latest data, no recovery transaction has occurred. The stolen funds remain under attacker control.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Whale Stakes 50,000 ETH on Everstake Worth Over $116.97M

Gate News message, April 15 — According to Onchain Lens, a major whale has staked 50,000 ETH on Everstake, worth approximately $116.97 million.

GateNews1h ago

Bitcoin, Ethereum and Solana ETFs Record Positive Net Inflows on April 15

Gate News message, according to the April 15 update, Bitcoin ETFs recorded a single-day net inflow of 4,566 BTC (approximately $337.41 million) and a 7-day net inflow of 6,753 BTC (approximately $499.04 million). Ethereum ETFs saw a single-day net inflow of 23,405 ETH (approximately $54.37 million)

GateNews3h ago

ETH 15-minute pullback of 0.60%: Long leverage getting liquidated at high levels as whale short-term selling aligns, driving the move downward

From 13:30 to 13:45 (UTC) on 2026-04-15, ETH recorded a -0.60% return at a short-term high, and the price fluctuated within 2317.79 - 2333.92 USDT, with an amplitude reaching 0.69%. In the preceding 24 hours, ETH had risen strongly, with the highest gain reaching 9.5%, and market attention noticeably heated up. The negative return during this period reflects a rapid shift in local sentiment in the high-price area. The main driver behind this move is long liquidation profit-taking in the derivatives market and partial deleveraging (cutting) of local leveraged funds. In the ETH futures market over the past 24 hours, the shorts

GateNews3h ago

BlackRock Transfers 15,101 ETH and 566 BTC to Major CEX, Worth $75.96M

BlackRock recently transferred over $35 million in ETH and $41 million in BTC through its ETFs to a major CEX, totaling nearly $76 million in value.

GateNews5h ago

On-Chain Trader 0x049b Opens 20x Leveraged Long on BTC and ETH, Accumulates $5.17M Profit in Two Months

A trader known as 0x049b has opened a 20x leveraged long position, buying 269 BTC and 8,586 ETH. Over two months, they executed 47 trades, achieving a 63.83% win rate and a total profit of $5.17 million.

GateNews6h ago

Gate Idle Coin Wealth ETH 7-day fixed-term financial management additional reward pool is live; subscribe to enjoy a 10% annualized return bonus.

Gate News, according to Gate’s official announcement Gate’s Yuebi Bao launches an ETH 7-day term wealth management product with an additional rewards pool. Subscription users can enjoy a 10% annualized return bonus. This rewards pool cumulatively provides 500,000 OFC in additional rewards, using a first-come, first-served mechanism. The additional rewards will be distributed to users’ accounts on a daily basis in the form of an equivalent amount of OFC. The platform has an overall cap on the total activity rewards and a limit on the maximum amount each individual user can receive.

GateAnnouncement9h ago
Comment
0/400
No comments