Hacker who stole 37K ETH, then worth ~$7M, during CoinDash's ICO in July by changing wallet address on site, has unexpectedly returned ~30K ETH, now worth ~$26M
Sead Fadilpaši / CryptoNews :
Context & Ripple Effects
In July 2017, CoinDash halted its ICO after a hacker swapped the ethereum address on its site and siphoned off 37,000 ETH — about $7M at the time (the address-swap heist that froze the token sale). The return of roughly 30,000 ETH seven months later turns that loss into a paper gain for the project: at current prices the returned stash is worth around $26M, more than triple what was taken.
This is not an isolated gesture. The Lendf.Me attacker handed back nearly everything they took from dForce in 2020 (returning ~$24M of the ~$25M haul), and Poly Network's $611M attacker began surrendering funds within weeks in 2021. CoinDash's return predates both, making it one of the earliest data points in a recurring pattern of crypto thieves giving loot back.
First-order effects
- CoinDash goes from victim of a frozen ICO to holder of an appreciated asset — the ~30K ETH returned is worth several times the $7M originally stolen, materially changing the project's treasury and its obligations to ICO participants.
- The hacker still holds the difference between the 37K ETH taken and the ~30K returned, plus all price appreciation on the returned portion accrued before repayment — an effective multi-million-dollar payday for a seven-month hold.
Second-order effects
- Victim projects gain a playbook: rather than writing off hacks, they can publicly track wallets and negotiate returns, as later seen with Lendf.Me and Poly Network — turning stolen-fund recovery into a negotiation rather than a loss.
- Every high-profile return raises the perceived risk of holding traceable stolen ETH, since the same public ledger that exposed CoinDash's loss makes spending the remainder difficult without attribution.
Third-order effects
- If the pattern holds — CoinDash, Lendf.Me, Poly Network, and Euler Finance all saw substantial returns — crypto theft settles toward a de facto bounty system in which attackers keep a cut and return the rest, blurring the line between hacking and extortion-with-refund.
- Regulators and exchanges face growing pressure to define how returned hack funds are treated: whether victims, insurers, or the returning hacker's legal exposure governs recovered assets will shape how often these repayments happen.
The trend: Major crypto thefts are increasingly ending in negotiated partial returns, as transparent blockchains make hoarding stolen funds riskier than giving most of them back.