CASE STUDY: How our investigation discovered the ZondaCrypto liquidity issues, one of Europe's largest crypto scandals. [Read the case study]

Incident Reports // 04.05.2026 // 7 min read // recoveris-team

Weekly Incident Report: April 27–May 3, 2026

$12M+ drained April 27–May 3 across 6 incidents: Wasabi, SWEAT, Purrlend, Aftermath, Alchemix, dormant ETH wallets. Weekly breakdown by Recoveris.

$12M+ drained April 27–May 3 across 6 incidents: Wasabi, SWEAT, Purrlend, Aftermath, Alchemix, dormant ETH wallets. Weekly breakdown by Recoveris.

This week’s Recoveris report covers the Wasabi Protocol admin-key compromise, a coordinated drain of hundreds of long-dormant Ethereum wallets, the SWEAT token-contract drainer on NEAR, the Purrlend multisig takeover on HyperEVM and MegaETH, the Aftermath Finance signedness flaw on Sui, and a $1M Alchemix approval-phishing loss.

Wasabi Protocol – ~$4.55M | April 30, 2026 | Infrastructure Breach

Attackers compromised wasabideployer.eth, the externally owned account holding sole ADMIN_ROLE on Wasabi’s permission contract. The attacker called grantRole to give a helper contract admin privileges with no timelock, then UUPS-upgraded the perpetual vaults and Long Pool to malicious implementations that drained funds. Compromised contracts spanned wWETH, sUSDC, wBITCOIN, wPEPE, and the Long Pool on Ethereum, plus sUSDC, wWETH, sBTC, sVIRTUAL, sAERO, and sBRETT vaults on Base.

Single-EOA admin control with no multisig, no timelock, and no emergency pause continues to produce the largest losses in DeFi. Most protocols treat admin-key hygiene as an internal governance question rather than a security boundary, even when the same key controls upgrade authority across every vault. UUPS proxies amplify the blast radius because a single privileged transaction rewrites the implementation of every contract pointing at it.

Once admin keys are compromised and contracts are upgraded, on-chain recovery is rarely possible without coordinated freezes at the off-ramp layer. Exchange notifications, validator engagement, and obfuscation-service mapping in the first hours determine whether any funds are seizable.

Sources: CoinDesk, The Block, Blockaid X (@blockaid_)

Dormant Ethereum wallets – ~$600K–$800K | April 29–30, 2026 | Mass Private-Key Compromise

Onchain analyst Wazz flagged a coordinated drain of hundreds of long-dormant Ethereum mainnet wallets, many idle 4 to 8 years and some inactive close to 14 years, all consolidated into a single Etherscan-tagged address (Fake_Phishing2831105). Public records show 596 transactions from victim wallets, with 324.74 ETH routed via THORChain Router v4.1.1. Affected wallets had no recent contract interactions, which suggests the attacker holds the actual private keys.

The vector remains unconfirmed. Community analysis points to legacy key generation tools, weak entropy in early wallet software, brainwallets, or downstream effects of historical credential leaks (the 2022 LastPass breach has already been linked to roughly $35M in prior crypto thefts). What sets this incident apart is scale: a coordinated drain of long-idle keys at this volume has not been documented before, and the pattern argues for a single source of compromise rather than independent phishing campaigns.

For long-term holders the takeaway is operational. Wallets created on legacy software, restored from old backups, or tied to compromised password managers carry latent risk that no on-chain hygiene can mitigate. Migration to fresh keys generated on hardware devices is the only durable fix.

Sources: Cryptopolitan, CryptoSlate, Blockzeit, X (@WazzCrypto)

SWEAT Protocol – ~$3.5M | April 29, 2026 | Smart Contract

Starting at 13:36 UTC, an attacker exploited a vulnerability in the SWEAT token contract on NEAR Protocol using a custom Rust drainer, emptying multiple top-100 holder accounts (including Sweat Foundation wallets) to zero in roughly 30 seconds. The drained tokens, 13.71B SWEAT or around 65% of total supply at the time, were routed through Ref Finance and the Wormhole Portal Bridge for laundering. The Sweat team paused the token contract, MEXC froze the attacker’s exchange account, and Rhea Finance halted SWEAT trading on its NEAR-based liquidity layer.

Token-contract drainers that target privileged accounts via refund or callback logic are increasingly common as teams add functionality to base ERC-20-equivalent contracts on alternative L1s. The vulnerability surface grows quickly because each new external-call path creates another opportunity for reentrancy-adjacent or signedness-adjacent flaws that escape audit attention.

The Sweat response illustrates what coordinated post-incident action looks like when treasury control stays intact: pause, freeze at the off-ramp, restore user balances from treasury, deploy the patched contract. All external user balances were fully restored within the same week.

Sources: The Block, BSC News, Tekedia, Blockaid X (@blockaid_), Sweat Economy X (@SweatEconomy)

Purrlend – ~$1.52M | April 25 attack / April 29 disclosure | Infrastructure Breach

An attacker compromised Purrlend’s 2-of-3 admin multi-signature wallet, which had no timelock configured. By escalating privileges and granting malicious addresses the BRIDGE_ROLE, the attacker exploited the mintUnbacked function to generate roughly 2M unbacked pUSDm and 4.85M pUSDC without providing collateral. These fabricated tokens were then deposited into liquidity pools as collateral to borrow and steal $1.52M in real assets across the HyperEVM and MegaETH deployments, approximately $1.2M on HyperEVM and $325K on MegaETH.

The combination of a small-quorum multisig (2-of-3) and the absence of a timelock is a recurring failure mode on newer chains where teams move quickly and security controls lag deployment. A timelock would not have prevented compromise but would have created a window for the team or watchers to detect the unauthorized role grant and pause the protocol before mint functions were called.

Purrlend paused the protocol, revoked all malicious permissions, and engaged law enforcement and blockchain analytics firms for tracing. The team is exploring user compensation options.

Sources: SlowMist Hacked Database

Aftermath Finance – ~$1.14M USDC | April 28–29, 2026 | Smart Contract

The attacker first appeared on April 28 with 405 SUI, assembled around 278 USDC of seed collateral via a SOR swap by the morning of April 29, then between 08:55 and 09:31 UTC ran 17 drain attempts (11 successful, 6 reverted). Root cause was a signed-integer flaw in the perpetuals clearing-house integrator fee logic. The attacker registered as their own integrator, set a negative 100,000 taker fee, and pulled synthetic collateral out as real USDC. Each successful transaction was a single PTB that opened two accounts, executed a market order against a real counterparty, then withdrew. The vulnerability was introduced August 29, 2025; an OtterSec audit in November 2025 missed it. Spot trading, AMM pools, afSUI staking, and the aggregator/SOR were unaffected.

Signedness mismatches in fee accounting are a textbook integer-handling bug that auditors have caught reliably for years on EVM. The Move and Sui ecosystem still has a thinner audit history, which means the same bug classes that are well-covered on Solidity continue to slip through. The pattern argues for second-pass audits before mainnet on any Sui or Aptos protocol that handles user collateral.

Mysten Labs and the Sui Foundation pledged to cover all losses, an affected wallets list was published, and compensation claims were set to open the following Monday. Bucket Protocol set its afSUI mint cap to zero as a precaution.

Sources: Cryptopolitan, Live Bitcoin News (initial), Live Bitcoin News (compensation), Aftermath Finance X (@AftermathFi)

Alchemix yvVault user – ~$1M | April 28–29, 2026 | Approval Phishing

A single user’s Yearn yvVault position was drained after they approved an unverified contract that had been deployed approximately 10 days earlier and contained an arbitrary-call vulnerability. PeckShield disclosed the mechanics on April 29, identifying that the attacker exploited the approval to transfer the victim’s full Yearn vault position.

Single-victim approval phishing rarely makes weekly summaries. This one is included because the loss size signals a broader pattern. As headline DeFi exploits shift toward infrastructure compromise, drainer crews continue to convert at high individual-loss values against high-net-worth wallets that hold concentrated DeFi positions. The technical pattern (unverified contract, arbitrary call, dormant approval) has not changed in two years.

Standing approvals are the persistent risk surface. Periodic revocation through Revoke.cash or equivalent tooling, paired with hardware-wallet signing for any new approval, remains the only durable defense for active DeFi users.

Sources: Phemex News, PeckShield X (@peckshield)


If your platform or users have been affected by recent exploits, immediate forensic intervention is critical to tracing and freezing assets before they reach obfuscation services.

Schedule a confidential consultation with Recoveris

Read more

Does MiCA help recover stolen crypto? What EU victims and advisers need to know
05.10.2026

Does MiCA help recover stolen crypto? What EU victims and advisers need to know

Does MiCA help recover stolen crypto in the EU? Learn what provider rules cover, what they cannot reverse, and which steps still matter.

Recoveris Monthly – September 2026
30.09.2026

Recoveris Monthly – September 2026

The civil route in crypto cases, September’s investigation lessons, CoTrace, our NCA/FCA workshop and October events.

Crypto Source of Funds report: evidence checklist
18.09.2026

Crypto Source of Funds report: evidence checklist

What should a crypto Source of Funds report include? An evidence checklist for bank reviews, exchange records, DeFi profits and complex asset histories.