An Ethereum wallet labeled Bofur Capital has been drained of close to $2 million after falling victim to an address poisoning attack, moments after withdrawing the same amount from decentralized lending protocol Compound Finance.
Blockchain security firm PeckShield flagged the incident on August 22, noting that the attacker had set the trap a full day before the victim ever touched the withdrawal, and that the stolen funds have already been rotated into a stablecoin to break the direct paper trail.
According to on-chain data, Bofur Capital’s address (0x7Ba7f477…eDffB3520) received 2,000,000 USDC through a withdrawal from the Compound III USDC market at 16:01:23 UTC on August 21, 2026. Exactly thirty minutes later, at 16:31:11 UTC, the same wallet transferred the full 2 million USDC out to what appeared, at a glance, to be a familiar counterparty.
That receiving wallet, 0xF0e6A496…fc19721aF, was in fact controlled by a phisher. The address had first been introduced into Bofur Capital’s transaction history a day earlier, on August 20 at 20:20:59 UTC, through a tiny 0.0002 USDC “dust” transfer designed to look like a benign incoming payment.
How the poisoning played out
Address poisoning attacks depend on two things: wallet interfaces that abbreviate long Ethereum addresses to only their first and last few characters, and the very human habit of copy-pasting from recent transaction history rather than verifying the full 42-character string.
In this case, the attacker generated a “vanity” wallet whose leading and trailing characters closely mimicked a real counterparty that Bofur Capital regularly interacted with. When the operator moved to send the freshly withdrawn 2 million USDC, they appear to have pulled the wrong address from their history and pasted it into the transfer field. Once the transaction was broadcast to the Ethereum network, it became irreversible within seconds.
Notably, the attacker’s dust transfer landed almost exactly 20 hours before the Compound withdrawal, suggesting the phisher was actively monitoring the Bofur Capital wallet for signs of a pending large outflow and pre-planted the poisoned entry so it would be sitting in the transaction history at just the right moment.
Funds swapped into DAI and parked
After receiving the 2 million USDC, the attacker quickly rotated the entire haul into MakerDAO’s DAI stablecoin, a common laundering step that puts distance between the freshly stolen USDC (which issuer Circle can blacklist) and the eventual off-ramp.
On-chain records show that wallet 0xe2e..1816a currently holds 1,999,939.4763139 DAI, valued at 1,999,939.48,alongwitharesidual0.000557818440752734ETH(1.40) used to cover gas. The wallet was funded roughly one hour before the theft by another address, 0x692729bC…0F4e17251, which appears to be a staging or gas-funding wallet controlled by the same actor.
At the time of writing, the stolen DAI had not been moved through Tornado Cash or any cross-chain bridge, meaning the funds remain fully traceable if exchanges and on-ramp providers coordinate to flag the wallet.
A rising threat vector across 2026
Address poisoning has quietly become one of the most costly attack categories in crypto through 2025 and 2026, hitting retail users, high-net-worth traders, and now labeled institutional wallets.
Earlier in the year, a crypto user lost more than $500,000 in USDT to a near-identical scheme on Ethereum, and a separate trader lost $50 million in December 2025 after copy-pasting a poisoned address whose first three and last four characters matched the intended recipient.
The pattern peaked in March 2026, when crypto influencer Sillytuna was drained of roughly $24 million in aEthUSDC through the same vector, also flagged by PeckShield. Academic research published on arXiv this year found that of 53 popular Ethereum wallets tested, only three throw an explicit warning when a user tries to send funds to a previously flagged phishing address, underlining how thin the on-interface protection layer remains.
The Bofur Capital case adds a specific institutional wrinkle: the attacker did not need to compromise a private key, exploit a smart contract, or breach any protocol logic. They only had to correctly guess that a wallet freshly withdrawing $2 million from Compound would forward those funds to a known counterparty, and place a spoofed address in the history a day in advance.
At the time of publication, Bofur Capital had not issued a public statement acknowledging the loss, and no recovery bounty had been announced.
Also Read: User Loses 1,010 ETH in Phishing Attack via Hijacked Tornado Cash Domain
