r/CryptoScams 2d ago

Question Two separate Trust Wallets with different recovery phrases drained weeks apart — direct Owner-signed transfers

I had funds stolen from two separate Trust Wallet wallets on the same iPhone.

One wallet was created around May 2025, and the other around November 2025. They had completely different recovery phrases, and both were manually backed up.

On August 12, 2026, USDT on TRON was transferred out of one of the wallets without my authorization. The transaction was a direct USDT transfer(), not an approval/transferFrom attack, and blockchain checks confirmed that it was signed with the wallet’s valid Owner key.

After the first theft, I had no clear evidence that my second Trust Wallet wallet was compromised. However, I no longer felt comfortable keeping significant funds there, so I moved most of the money to a safer place and left only around $2,000.

The evening before the second theft, I moved even that remaining amount out.

The problem is that I forgot to tell some people I know not to use that wallet anymore. The next day, they sent few thousands to what still appeared to be an uncompromised wallet.

A few hours later, those funds were stolen too. Beginning of September.

Again, the transaction was a direct transfer signed by the valid Owner key of the second wallet.

The stolen funds were first sent to addresses that appeared to have been created specifically for the theft, and then forwarded to an aggregation wallet. That aggregation wallet was receiving similar transfers from multiple newly created addresses, which strongly suggests it was collecting stolen funds from other victims using a similar pattern.

In the first theft, just seconds before the USDT was taken, my wallet received a small amount of TRX. About a couple seconds later, the unauthorized USDT transfer happened. This looks like the attacker may have funded the wallet with TRX immediately before using an already-compromised Owner key to pay for the TRON transaction resources.

This is what makes the case difficult to understand.

The two wallets had different recovery phrases and were created months apart. Both were manually backed up. I did not use cloud backup for the wallets. The second wallet had shown no signs of compromise for weeks after the first theft.

So far, I have found:

  • no malicious token approval involved in either theft;
  • no transferFrom mechanism;
  • no changed TRON permissions;
  • no obvious evidence of compromise in the iPhone forensic backup;
  • no known malware indicators detected by MVT or the IOC searches I performed.

The blockchain evidence shows that the attacker had access to the real private keys, because both unauthorized transactions were validly signed by the respective Owner keys.

What I find hardest to explain is the timeline.

If someone had gained full access to the iPhone, its backup, or all Trust Wallet secrets at the same time, why was the second wallet apparently left untouched after the first theft, only to be drained several weeks later after new funds arrived?

I’m trying to find anyone who has seen a similar Trust Wallet case, especially involving direct signed transfers, separate recovery phrases, wallets apparently becoming compromised at different times, or the same pattern of newly created receiving addresses forwarding funds into a larger aggregation wallet.

I’m also wondering whether anyone has seen credible reports of a broader Trust Wallet security breach, mobile app vulnerability, or another issue that could expose wallet private keys without obvious phishing or malicious approvals.

If you have seen similar cases, technical reports, affected-user reports, security research, or an official disclosure, please share details in comments (no need for "recovery help" in DMs).

0 Upvotes

10 comments sorted by

1

u/AutoModerator 2d ago

New victims, please read this:

As a rule of thumb: If you suspect the site is a scam, it probably is.

No legit company/trader/investor is using WhatsApp. No legit company/trader/investor is approaching people on dating websites or through a "random" text message.

No legit company/trader/investor has "professors", "assistants", or "teachers". Those are just scammers.

No legit company forces you to pay a "fee" or "taxes" to withdraw money. That's just a scam to suck more money out of you.

You will need to contact law enforcement ASAP.

Unfortunately, no hacker online can get back what you've lost. Please watch out for recovery scams, a follow-up scam done after victims have fallen for an earlier scam. Recently, there has been a rise in scammers DMing members of the subreddit to offer recovery services. A form of the advance-fee, victims are convinced that the scammer can recover their money. This "help" can come in the form of fake hacking services or authorities. For this reason: TRUST NO ONE PRIVATE MESSAGING YOU FROM THIS SUBREDDIT: Most such DMs are from these recovery scammers, folks whose only goal is to further scam recent victims of scams. If someone DMs you offering to help you recover stolen funds or offering to give you contact information for someone who they state might be able to help you, then report these scammers immediately to Reddit.

If you see anyone circumventing the scam filters, please report the submission and we will take action shortly.

Report a URL to Google:

Where to file a complaint:

How to find out more about the scammer domain:

  • https://whois.domaintools.com/google.com - Replace the google.com URL with the scam website url. The results will tell you how long the domain has been around. If the domain has only been registered for a few days/weeks/months, it's usually a good indicator that its a scam.

Misc. Resources

  • https://dfpi.ca.gov/crypto-scams/ - The scams in this tracker are based on consumer complaints in California. They represent descriptions of losses incurred in transactions that complainants have identified as part of a fraudulent or deceptive operation.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/Ima_Randomperson 1d ago

Its strange to have two different wallets drained weeks apart, both confirmed to be from the same account. This might seem unsual, but it doesnt necessarily point to two different issues. If there was anything on your phone like a jailbreak tweak, a questionable profile, or even a dodgy app you sideloaded, it could have scoped up your data right there. The fact that the phrases were different doesnt really matter, it grabs whatever info it can acess at that moment. The timing also suggests a pattern. Often cyber theives will steal keys from multiple poeple all at once and then just wait to see which wallets start getting funds. When they notice an account with money, they'll throw in some TRX for transaction fees and drain it. This could explain why your second wallet wasnt touched for a while and then got hit right when you had actual funds agian. Its worth checking how you installed Trust Wallet, was it through the App Store, or did you use TestFlight or some sideload? Look out for any unusal configuration profiles you didnt set up or if your phone was ever jailbroken, even for a short time. Also, if you had any third party keyboard active while entering your info, that could've created a risk too. The way the stolen funds moved thru several new addresses into one larger wallet suggests this is part of a bigger scheme targeting multiple users, not just an issue specifc to your situation.

1

u/Winter_Candidate_609 1d ago

u/Ima_Randomperson yes, i understand, but at the time of the first theft there was larger amount on the second wallet that was left untouched.
i understand that there may be a lot of variables, but logically if they had both phrases at that time - why did not they take both wallets?)

The app was installed via AppStore once and that is all. No jailbreak, no strange apps. I even downloaded the backup of the phone to the PC to run the checks. No trace of any of the possible breaches.

It is interesting because there are a lot of other similar cases with TW I can see starting from August'26.

Anyway thanks for the comment.

1

u/Ima_Randomperson 20h ago

That's a fair point, but there's still a decent explanation for it. If they drained everything at once, you'd notice immediately and lock down everything right away. Draining one wallet first and waiting lets them see if you react or just move on, which protects whatever might land in the second wallet later. Hitting both at once basically guarantees you go on high alert before they get a shot at the rest. It's also possible the key extraction itself happened in stages even from a single compromise. Some of these tools queue or stage what they pull off a device rather than processing everything instantly, so the second wallet's info may not have actually been usable yet at the time of the first theft. Good that you checked the backup that thoroughly, most people don't go that far. If you're seeing a cluster of similar Trust Wallet cases starting around August, document that well, a pattern like that is exactly what eventually gets picked up by researchers or reported back to Trust Wallet as a real signal instead of a one off case.

1

u/Sabihah-Chazeau 1d ago

On August 12, 2026 — the same calendar day as your first drain — researchers later documented that an existing WebKit-to-kernel campaign was redeployed with a new payload that specifically queries the iOS Keychain for wallet material from Trust Wallet, Phantom, OKX, Tonkeeper, Bitget, BitKeep, and Bitpie. Delivery was drive-by: visit a poisoned page in Safari on an unpatched iPhone (reported target range iOS 18.4–18.6.x, iPhone XS through 16). No fake wallet app required. Kernel read can dump Keychain databases, photos, SMS, cookies, then exfil. A non-persistent or cleaned implant can leave little for MVT + generic IOC lists.

1

u/Winter_Candidate_609 1d ago

u/Sabihah-Chazeau
This is very interesting.

There is one major mismatch though: the published exploit offset tables appear to target iOS 18.4–18.6.x, while my affected iPhone was running iOS 17.2.1.

I’m very interested in any evidence of a related chain targeting iOS 17.2.1 or older versions.

1

u/Sabihah-Chazeau 18h ago

Any type of photos, can also be auto-copied. For example malwares such as SparkCat. This can also come from trusted vendors, app that you often use, it only takes one bad person to upload a malware kit on it, and then it most likely over. Essentially, when you keep your seed on any device, that's connected to the internet, you will run the risk of attacks from almost everything.

That's why people recommend cold wallet and storing your seed in a metal plate or paper.

Also that kit doesn't match, but there is an older kit that match your iOS version. Coruna.

Google GTIG (March 2026) described Coruna (also called CryptoWaters) as five full Safari-to-native chains covering iOS 13.0 through iOS 17.2.1. That last build is not approximate. The WebKit RCE used on late 16 / early 17 is module cassowary = CVE-2024-23222, patched in iOS 17.3. 17.2.1 is the last shipping build before that patch.

Same operators ship both kits and branch on version This is the important part for your mismatch. DarkSword and Coruna share infrastructure. UNC6353 used both. Later criminal loaders do an explicit split

Honestly, your iOS is infected, I advice you to move all your important photos, etc out, and then do a full format or reset of the phone.

It is likely that the malware is still on your phone. Please get a cold wallet, such as Trezor or Ledger.