Either someone is careless, or there’s something fishy...: $24 million was phished three years ago. The address wasn’t changed and the funds were still used—today, another $26 million was stolen.

But this time wasn’t just authorization phishing from a single address; it looks like they were “caught in one net”: funds from 3 wallets were transferred out, including a clean wallet that had never had any authorization (0x8f3...914).

◎ $24 million phished three years ago; later the attacker returned 90% of the funds.
◎ About $26 million in assets were stolen today from 3 wallets; they have all currently been converted into DAI and ETH.