At 06:15:23 UTC on September 28, 2024, a successful Ethereum transaction produced a net outflow of 12,083.625352887294427537 Spark WETH tokens, or spWETH, from wallet 0xAA1582084c4f588eF9BE86F5eA1a919F86A3eE57. Scam Sniffer, which identified the event as permit-signature phishing, valued the loss at approximately $32.43 million in a contemporaneous alert.

The event mattered because the public transaction did not resemble a conventional private-key transfer initiated directly by the affected wallet. Its decoded input included a permit authorization followed by token transfers executed through contracts. That structure illustrated how a signature obtained away from the blockchain could subsequently authorize an on-chain spender to move a large token position.

The available evidence established the movement of the tokens. Attribution, the website or message used to solicit the signature, and the identity of the wallet’s controller remained uncertain on September 28.

What the transaction recorded

Etherscan recorded the transaction in Ethereum block 20,847,274. The affected address received approximately 40.945673 spWETH through an interest-related mint during the same execution, while outgoing transfers totaled approximately 12,124.571026 spWETH. The resulting net reduction was 12,083.625353 spWETH, consistent with Scam Sniffer’s rounded report of 12,083 tokens.

The outgoing amount was divided principally between approximately 10,002.771096 spWETH sent to address 0x471c725bd1f29850cbb8eea4cdf6c9ce3cac5607 and approximately 2,121.799929 spWETH sent to another recipient. The transaction paid no ether to the called contract, although it incurred an Ethereum network fee of approximately 0.010632 ETH.

Before the transfers, the decoded logs recorded a permit approval associated with the affected wallet and the Spark WETH contract. Scam Sniffer characterized that authorization as a phishing signature. The blockchain proves that the authorization and transfers were executed; it does not reveal what the signer saw, how consent was obtained or who operated the receiving addresses.

A wallet compromise, not a demonstrated Spark exploit

No evidence available on September 28 established that Spark’s lending contracts had been exploited or that other depositors were affected. The transaction instead appeared to use token-approval functionality to obtain spending authority over one account. That distinction matters: a protocol-level exploit can endanger shared pools, while a malicious approval primarily exposes the assets controlled by the signer granting it.

The incident also showed why transaction counts alone can obscure the sequence. One Ethereum transaction bundled an approval, an interest-related balance update and multiple outgoing transfers. The net balance change, rather than either outgoing leg viewed alone, is therefore the appropriate token-loss measurement.

Contemporaneous reports speculated about the wallet owner based on address-labeling services and prior transfers. Those associations were not verified, so this reconstruction does not identify the victim. Current explorer labels likewise cannot establish what was known about attribution on September 28.

Valuation and recovery limits

The approximately $32.43 million figure was Scam Sniffer’s event-time estimate for 12,083 spWETH, not a realized-dollar sale or a Coinburn price calculation. spWETH represents an interest-bearing Spark position, and its value need not equal the spot price of ether precisely. Crypto assets also trade continuously, making any dollar conversion dependent on its timestamp and pricing method.

Later on September 28, The Block reported that an on-chain message from the affected wallet offered a 20% reward for returning the funds. No accepted offer or completed recovery was established in the reviewed event-day record. The defensible conclusion at the end of September 28 was therefore limited: the token outflow was verified, apparent permit phishing was reported, and attribution and recovery remained unresolved.

Primary sourceEtherscan — Ethereum transaction 0xf7c00f18175cdea49f8fdad6a1d45edeb318f18f3009f51ab9f4675171c1d8fb

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.