T
iTokenly

Individual holder (12,083 spWETH) hack — September 2024

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident(approximate)
Publicly disclosedSeptember 28, 2024
Target typeIndividual holder
Loss$32,400,000Published estimates range $32,000,000 to $32,430,000Price at time of incident
MethodPhishing signaturePermit-signature phishing delivered through a spoofed DeFi front-end. The holder is reported to have signed an off-chain 'permit' message rather than broadcasting a visible approval transaction, which granted the attacker spend authority over the wallet's 12,083 spWETH (Spark Protocol wrapped ether) balance. The drain was executed immediately afterwards. ScamSniffer first identified the theft; Arkham Intelligence linked it to the Inferno Drainer phishing-as-a-service kit, which supplies spoofed interfaces to affiliates for a commission on proceeds. The permit-specific mechanism is asserted by Cryptopolitan only; other outlets describe the signature generically.
ChainsEthereum
Attributed toUnidentified affiliate of the Inferno Drainer phishing-as-a-service kitSuspected
OutcomeUnresolved

What happened

An individual holder lost 12,083 spWETH, the interest-bearing wrapped-ether token issued by Spark Protocol, worth about $32.4 million at the time. The wallet was emptied in a single sequence after the holder signed a phishing message served by a spoofed DeFi interface.

The reported mechanism was a permit signature rather than a conventional on-chain token approval. A permit is an off-chain signed message that grants a spender allowance over a token balance; because nothing is broadcast to the chain at the moment of signing, wallet software of the period gave the signer little indication that funds were at risk. Once the signature was collected the attacker used it to move the entire spWETH balance. Only Cryptopolitan specifies the permit mechanism; The Block describes a malicious transaction signature in general terms and Cointelegraph does not describe the mechanism. ScamSniffer detected and first reported the drain, and Arkham Intelligence linked it to Inferno Drainer, a phishing-as-a-service operation that had relaunched in May 2024 after shutting down the previous November.

The stolen tokens were unwrapped and dispersed. A message was posted to the victim's wallet offering a 20 percent reward for the return of the funds. No return, recovery or arrest has been reported.

The victim has not been publicly confirmed. Cointelegraph reported that Arkham data suggested a link to a known industry figure but stated the identification remained unverified; the name is not recorded here. Dating is contested: Cointelegraph places the theft on 27 September 2024, while The Block and Cryptopolitan date it to 28 September. The loss is given as $32.4 million by The Block, $32.43 million by Cryptopolitan and rounded to $32 million by Cointelegraph.

Sources

  1. The BlockSecondary · retrieved 2026-08-01
  2. CointelegraphSecondary · retrieved 2026-08-01
  3. CryptopolitanSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Individual holder (12,083 spWETH) hack — September 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/individual-holder-12083-spweth
https://itokenly.com/hacks/individual-holder-12083-spweth

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.