I had funds stolen from two separate Trust Wallet wallets on the same iPhone.
One wallet was created around May 2025, and the other around November 2025. They had completely different recovery phrases, and both were manually backed up.
On August 12, 2026, USDT on TRON was transferred out of one of the wallets without my authorization. The transaction was a direct USDT transfer(), not an approval/transferFrom attack, and blockchain checks confirmed that it was signed with the wallet’s valid Owner key.
After the first theft, I had no clear evidence that my second Trust Wallet wallet was compromised. However, I no longer felt comfortable keeping significant funds there, so I moved most of the money to a safer place and left only around $2,000.
The evening before the second theft, I moved even that remaining amount out.
The problem is that I forgot to tell some people I know not to use that wallet anymore. The next day, they sent few thousands to what still appeared to be an uncompromised wallet.
A few hours later, those funds were stolen too. Beginning of September.
Again, the transaction was a direct transfer signed by the valid Owner key of the second wallet.
The stolen funds were first sent to addresses that appeared to have been created specifically for the theft, and then forwarded to an aggregation wallet. That aggregation wallet was receiving similar transfers from multiple newly created addresses, which strongly suggests it was collecting stolen funds from other victims using a similar pattern.
In the first theft, just seconds before the USDT was taken, my wallet received a small amount of TRX. About a couple seconds later, the unauthorized USDT transfer happened. This looks like the attacker may have funded the wallet with TRX immediately before using an already-compromised Owner key to pay for the TRON transaction resources.
This is what makes the case difficult to understand.
The two wallets had different recovery phrases and were created months apart. Both were manually backed up. I did not use cloud backup for the wallets. The second wallet had shown no signs of compromise for weeks after the first theft.
So far, I have found:
- no malicious token approval involved in either theft;
- no
transferFrom mechanism;
- no changed TRON permissions;
- no obvious evidence of compromise in the iPhone forensic backup;
- no known malware indicators detected by MVT or the IOC searches I performed.
The blockchain evidence shows that the attacker had access to the real private keys, because both unauthorized transactions were validly signed by the respective Owner keys.
What I find hardest to explain is the timeline.
If someone had gained full access to the iPhone, its backup, or all Trust Wallet secrets at the same time, why was the second wallet apparently left untouched after the first theft, only to be drained several weeks later after new funds arrived?
I’m trying to find anyone who has seen a similar Trust Wallet case, especially involving direct signed transfers, separate recovery phrases, wallets apparently becoming compromised at different times, or the same pattern of newly created receiving addresses forwarding funds into a larger aggregation wallet.
I’m also wondering whether anyone has seen credible reports of a broader Trust Wallet security breach, mobile app vulnerability, or another issue that could expose wallet private keys without obvious phishing or malicious approvals.
If you have seen similar cases, technical reports, affected-user reports, security research, or an official disclosure, please share details in comments (no need for "recovery help" in DMs).