On September 2nd, my main DeFi wallet was drained. There were no suspicious approvals or phishing sites. To be honest, I don't understand how it happened, especially since the drain occurred on all the chains where I had assets. You know, if you approve a malicious contract on the Arbitrum chain, you'll be drained there. The same goes for token approvals: if you approve "infinite spending limit" on USDC on the Base network, you'll be drained of USDC (if you have them in your wallet), and so on. My case is different because:
1) I didn't encounter any phishing sites.
2) I had no token approvals (other than deprecated ones or assets no longer present in the wallet).
So what happened? I believe the attacker somehow stole the private key and then configured it with a script (sweeper) that extracts tokens and NFTs. On September 2nd, several addresses were affected, not just mine. It wasn't a large-scale attack, but it drained about $140,000 from multiple users.
Keep in mind that this was an address I use for airdrops and speculation, but no one likes being robbed. It's good practice to hold your assets in multiple wallets, primarily hardware wallets.
HOW DID HE RECOVER THE PRIVATE KEY
How did he steal the private key? I believe it was some browser malware or extension that managed to extract the private key from the wallet. I can't be certain of this. Another mistake I made several years ago was importing this seed into a new device to use Metamask with the same address. I think I imported the seed three times: once into Trust Wallet and twice into two new Metamasks (new devices). You know, in 7-8 years, you might change computers several times. I know, the seed should never be imported, except to recover your tokens if the device breaks... and then move them to a new address. However, it had always worked well, so I underestimated the situation. I want to point out that the computers were new and I disconnected the internet (as a precaution), but you never know. The seed entered remains recorded in the wallet, so it can be dangerous, especially today...in this era of increasingly dangerous AI and malware.
THE DAY OF THE ATTACK
It happened at 1 AM and continued intermittently (my last transaction was 5 hours earlier). In about an hour, it drained assets on Ethereum and Base. Subsequently, it drained assets on Arbitrum, $UNI on Ethereum, and $ETH staked in the Metamask pool. It stole assets held in the wallet as well as those deposited on Aave, Morpho, Relay, and Pendle.

I was still awake at the time and was shopping on eBay; unfortunately, I wasn't on DeBank, otherwise I would have seen the assets being withdrawn live. I could have limited the damage somewhat, even though the bot is usually faster than humans. I didn't notice anything and went to bed. In the morning, I opened the Opensea app that tracks my address and saw that many funds were missing; I thought it was a bug. Then I went to DeBank and there too I saw that the wallet was almost empty. Of course I was worried, but you know, DeBank sometimes doesn't track chains well (just reload the page or wait).

However, by going to "transactions", I realized it was all true because someone had withdrawn most of the assets eight hours earlier. Not all. They would probably have completed everything the next day. I managed to save some assets, although I suffered a loss.
POST-ATTACK
Obviously, it was brutal. When Terra (Luna-UST) collapsed, I lost more funds, but I had never suffered a private key/seed theft in eight years of DeFi (basically since its inception). In addition to withdrawing the remaining assets, not knowing exactly what happened, I emptied most of the other addresses I use in DeFi, moving the assets to hardware wallets. Personally, I keep my holdings in hardware wallets; those in DeFi I use Metamask and Rabby (I have multiple DeFi addresses because I interact with the same protocols multiple times, and you know, you never know what could happen to you, whether it's phishing, malware, or private key leaks).
IS IT WORTH THE RISKS IN DEFI?
You might be wondering if the DeFi risk is worth it, and my answer is "it depends". All these assets (stolen by the hacker on September 2nd and the others I hold on Metamask and Rabby) come from various farming methods: airdrops, income, speculation. If I didn't take risks, I wouldn't have them. In a way, it's part of the game, even though no one likes being robbed. You know, it's a bit like when someone burglarizes your house. There's not much difference. It's sad and brutal at the same time. However, if I were to advise someone to invest at least 70-100k, I'd tell them to keep it safe in a hardware wallet and only keep funds they're willing to lose in DeFi. Would a hardware wallet have saved me? It depends. No one can escape a private key leak, but it depends on how it was stolen. Hardware wallets don't interact with extensions or browsers, and you don't enter the seed. However, if you use DeFi a lot (dozens of transactions a day), it's not convenient to confirm the transaction every time with a hardware wallet. Now my assets that were in DeFi (on other addresses) are in a new hardware wallet and a new Rabby on a different browser. I'll have to decide how to reorganize everything for airdrop farming. Never give up.
Stay safe, don't import your seed anywhere, be careful what you approve, and when in doubt, avoid interacting with shady protocols and revoke approvals at Revoke Cash.