The Ethereum wallet Bofur Capital lost close to $2 million after falling victim to an address poisoning attack identified by blockchain security firm PeckShield. The funds were withdrawn from the Compound III USDC market at 16:01:23 UTC on August 21, 2026, and transferred 30 minutes later at 16:31:11 UTC to a poisoned address controlled by the attacker. The phisher introduced the fake address through a 0.0002 USDC dust transaction one day earlier. The stolen USDC was rotated into about 2 million DAI and remains held at the attacker’s wallet, underscoring how address poisoning continues to drain large sums in 2026.