Individual holder (9,579 stETH and 4,851 rETH) hack — September 2023
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | September 6, 2023 |
| Target type | Individual holder |
| Loss | $24,100,000Published estimates range $24,000,000 to $24,100,000Price at time of incident |
| Method | Phishing signatureApproval phishing. After visiting a phishing site, the holder signed two separate approval transactions, one for stETH and one for rETH, granting the attacker's address spending authority over both balances. The tokens were then removed in later transactions using transferFrom. Cointelegraph identifies the approval function as increaseAllowance; The Block's sources describe the two approvals without naming the function. The receiving address was associated with multiple phishing sites impersonating projects or promising airdrops, but no source establishes what lure this particular victim was shown. |
| Chains | Ethereum |
| Outcome | Unresolved |
What happened
On 6 September 2023 an individual holder lost 9,579 stETH and 4,851 rETH, the liquid-staking tokens issued by Lido and Rocket Pool, in what was at the time among the largest single-wallet phishing thefts recorded. The Block valued the stETH at about $15.6 million and the rETH at about $8.5 million, roughly $24.1 million combined; Cointelegraph and other accounts round the total to $24 million. The Block dates the theft to 7 September; Cointelegraph and Web3 Is Going Just Great both give 6 September, which is the date recorded here.
The holder visited a phishing site and signed two separate approval transactions, one for each token. That granted the attacker's address spending authority over the balances, which were then removed with transferFrom calls in subsequent transactions. The two-step pattern is what distinguishes this case from a single malicious transfer: the victim authorised the spend, and the drain followed. Analysts at Beosin and BlockSec independently reconstructed the sequence from on-chain data, and ScamSniffer identified the phishing vector. Etherscan tagged the receiving address as a known phishing wallet linked to multiple other phishing sites; those sites are described as impersonating crypto projects or promising airdrops, though no source establishes which lure this victim encountered.
The funds were converted and laundered over the following months. PeckShield reported that the attacker exchanged the staked-ether tokens for 13,785 ETH and about 1.64 million DAI, routing part of the DAI through FixedFloat and dispersing the remainder across multiple wallets. In March 2024, roughly six months after the theft, CertiK flagged a further 3,700 ETH, worth about $10 million at the time, moving into Tornado Cash.
No arrests have been reported, no funds have been recovered, and no named actor or group has been publicly identified. The victim is a private individual and is not named here.
Sources
- The BlockSecondary · retrieved 2026-08-01
- Cointelegraph (via TradingView)Secondary · retrieved 2026-08-01
- Web3 Is Going Just GreatAggregator · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Individual holder (9,579 stETH and 4,851 rETH) hack — September 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/individual-holder-9579-steth-4851-rethhttps://itokenly.com/hacks/individual-holder-9579-steth-4851-rethPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.