Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Charlie Lee, creator of Litecoin, standing in front of a blue Litecoin corporate logo wall
    Litecoin Turns 15: Original Bitcointalk Records Show How Charlie Lee Launched LTC in 2011
    Elon Musk with folded arms flanked by a giant Bitcoin coin, Tesla electric car, and SpaceX rocket launch
    Elon Musk’s Tesla and SpaceX Still Hold Over 30,000 Bitcoin: Why Is He Not Selling?
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
    Bitget exchange coin token set in front of a blurred FTX building backdrop.
    Is Bitget the Next FTX? What the $351.6 Million Hack Does and Doesn’t Have in Common
    Gold Bitcoin BTC coin standing vertically in front of a rising green financial candlestick chart
    Inside Bitcoin’s September 2026 Rally: BTC Reclaiming $87K, $2B in ETF Inflows and a Short Squeeze
  • Opinion
    OpinionShow More
    Donald Trump speaking at a presidential podium with the White House and U.S. Capitol building in the background.
    Trump Just Declared the Super Intelligence Era in the “Unites States.” So Who Controls It?
    Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers
    Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Bofur Capital Drained of $2M Minutes After Compound Withdrawal

A $2 million USDC theft from Bofur Capital highlights how a tiny “dust” transfer helped a phisher poison the wallet’s transaction history before the funds were drained.

Written By Dishita Malvania
Edited by Divya Mistry
Published 2026-08-22·Updated 1 month ago
Make The Crypto Times preferred on GoogleGoogle
Bofur Capital Drained of $2M Minutes After Compound Withdrawal

An Ethereum wallet labeled Bofur Capital has been drained of close to $2 million after falling victim to an address poisoning attack, moments after withdrawing the same amount from decentralized lending protocol Compound Finance. 

Blockchain security firm PeckShield flagged the incident on August 22, noting that the attacker had set the trap a full day before the victim ever touched the withdrawal, and that the stolen funds have already been rotated into a stablecoin to break the direct paper trail.

AI Summary
Show
Bofur Capital withdrew 2 M USDC from Compound, then sent it to a poisoned address within 30 minutes.
Attacker pre‑seeded a dust transaction a day earlier, exploiting UI address abbreviation to trigger copy‑paste error.
Stolen USDC was instantly swapped to DAI, remaining traceable in a single wallet with minimal gas ETH.

According to on-chain data, Bofur Capital’s address (0x7Ba7f477…eDffB3520) received 2,000,000 USDC through a withdrawal from the Compound III USDC market at 16:01:23 UTC on August 21, 2026. About 30 minutes later, at 16:31:11 UTC, the same wallet transferred the full 2 million USDC out to what appeared, at a glance, to be a familiar counterparty.

That receiving wallet, 0xF0e6A496…fc19721aF, was in fact controlled by a phisher. The address had first been introduced into Bofur Capital’s transaction history a day earlier, on August 20 at 20:20:59 UTC, through a tiny 0.0002 USDC “dust” transfer designed to look like a benign incoming payment.

How the poisoning played out

Address poisoning attacks depend on two things: wallet interfaces that abbreviate long Ethereum addresses to only their first and last few characters, and the very human habit of copy-pasting from recent transaction history rather than verifying the full 42-character string.

In this case, the attacker generated a “vanity” wallet whose leading and trailing characters closely mimicked a real counterparty that Bofur Capital regularly interacted with. When the operator moved to send the freshly withdrawn 2 million USDC, they appear to have pulled the wrong address from their history and pasted it into the transfer field. Once the transaction was broadcast to the Ethereum network, it became irreversible within seconds.

Notably, the attacker’s dust transfer landed almost exactly 20 hours before the Compound withdrawal, suggesting the phisher was actively monitoring the Bofur Capital wallet for signs of a pending large outflow and pre-planted the poisoned entry so it would be sitting in the transaction history at just the right moment.

Funds swapped into DAI and parked

After receiving the 2 million USDC, the attacker quickly rotated the entire haul into MakerDAO’s DAI stablecoin, a common laundering step that puts distance between the freshly stolen USDC (which issuer Circle can blacklist) and the eventual off-ramp.

On-chain records show that wallet 0xe2e..1816a currently holds 1,999,939.4763139 DAI, valued at 1,999,939.48,alongwitharesidual0.000557818440752734ETH(1.40) used to cover gas. The wallet was funded roughly one hour before the theft by another address, 0x692729bC…0F4e17251, which appears to be a staging or gas-funding wallet controlled by the same actor.

At the time of writing, the stolen DAI had not been moved through Tornado Cash or any cross-chain bridge, meaning the funds remain fully traceable if exchanges and on-ramp providers coordinate to flag the wallet.

A rising threat vector across 2026

Address poisoning has quietly become one of the most costly attack categories in crypto through 2025 and 2026, hitting retail users, high-net-worth traders, and now labeled institutional wallets. 

Earlier in the year, a crypto user lost more than $500,000 in USDT to a near-identical scheme on Ethereum, and a separate trader lost $50 million in December 2025 after copy-pasting a poisoned address whose first three and last four characters matched the intended recipient.

The pattern peaked in March 2026, when crypto influencer Sillytuna was drained of roughly $24 million in aEthUSDC through the same vector, also flagged by PeckShield. Academic research published on arXiv this year found that of 53 popular Ethereum wallets tested, only three throw an explicit warning when a user tries to send funds to a previously flagged phishing address, underlining how thin the on-interface protection layer remains.

The Bofur Capital case adds a specific institutional wrinkle: the attacker did not need to compromise a private key, exploit a smart contract, or breach any protocol logic. They only had to correctly guess that a wallet freshly withdrawing $2 million from Compound would forward those funds to a known counterparty, and place a spoofed address in the history a day in advance.

At the time of publication, Bofur Capital had not issued a public statement acknowledging the loss, and no recovery bounty had been announced.

Also Read: User Loses 1,010 ETH in Phishing Attack via Hijacked Tornado Cash Domain

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Crypto HackEthereum (ETH)
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Physical Bitcoin and Ethereum coins standing side-by-side in front of financial market candlestick charts.
Bitcoin, Ethereum Slide as Fed Minutes Point to Year-End Rate Hike
39 States Urge Supreme Court to Review Kalshi Sports Betting Dispute
39 States Urge Supreme Court to Review Kalshi Sports Betting Dispute
Coinbase Prime screen and official US government documents positioned in front of the US Capitol dome.
U.S. Government Moves Over $565M to Coinbase Prime in Seized Assets
Hooded hacker working on a laptop displaying Uranium Finance branding next to a system breach alert.
US Jury Convicts Uranium Finance Hacker Over $54 Million Crypto Theft
Physical dog memecoin token sitting beside a wooden judge's gavel and handcuffs.
Kishu Inu Founder Indicted on Wire Fraud Charges

Find Us on Socials

You may also like

Gold frog memecoin medallion set against a Singapore skyline at dusk with red market charts.

Crypto Trader Frogman Loses Over $4M in Wallet Hack in Singapore During TOKEN2049

Speaker on stage at a Deconomy conference wearing an Ethereum shirt.

Ethereum Researcher Drake Flags ECDSA Risk for Crypto Holders

BitGo and Lido logos mounted side-by-side on an office wall.

BitGo Expands Lido ETH Staking to Eligible U.S. Clients

Smartphone displaying the Bitmine logo next to a physical Ethereum coin.

BMNR Price Drops 7% as Ethereum Falls and BitMine Limits ETH Holdings

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Masthead
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram
© 2026 The Crypto Times | Protocols And Tokens Pvt Ltd.
DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information