NewsCryptoTrust Wallet Users Report Unexplained Mobile Wallet Drains

Trust Wallet Users Report Unexplained Mobile Wallet Drains

Author: Crypto Adventure·

Key Takeaways

  • One user reported that two separately generated Trust Wallet wallets on the same iPhone were emptied at different times.
  • The first reported loss involved a direct TRON USDT transfer, indicating that valid signing authority may have been used.
  • Available information does not establish how the signing material was obtained or whether the incidents share a common source.
  • Trust Wallet’s 2025 browser-extension breach affected 2,520 addresses and about $8.5 million but excluded mobile-app-only users.
  • As of September 10, Trust Wallet had not published a September 2026 mobile security incident, and its public services were listed as operational.
Trust Wallet Users Report Unexplained Mobile Wallet Drains

Trust Wallet users are reporting unexplained drains from mobile wallets, including one case involving two separately generated wallets with different recovery phrases on the same iPhone. The wallets were reportedly emptied weeks apart, raising questions about how valid signing authority could have been obtained across two independent seeds.

The first loss occurred on August 12, when USDT left one wallet through a direct TRON token transfer that the owner said was unauthorized. The second wallet initially remained untouched but was later drained after new funds were sent to it. The user’s report does not establish whether the exposure originated with Trust Wallet, the phone, recovery-phrase handling, or another compromise.

Because the account is based on a user report rather than a confirmed incident, transaction records and any official Trust Wallet findings would be needed to determine whether the two drains share a common source. Until then, the reports do not establish a platform-wide compromise of Trust Wallet’s mobile app.

The original report is available on Reddit: https://www.reddit.com/r/CryptoScams/comments/1wbbh5w/two_separate_trust_wallets_with_different/?utm_source=chatgpt.com

Direct Transfers Raise Questions About Key Exposure

The first reported transaction was a direct transfer() rather than an approval-based transferFrom transaction. That distinction points to the use of valid signing authority, rather than an attacker merely exploiting a previously granted token approval.

Trust Wallet’s Wallet Core generates a new seed at random using secure random-generation capabilities available on the device. Its self-custody model also keeps private keys under the user’s control instead of storing them on Trust Wallet’s servers. The available evidence does not identify how the signing material involved in the reported drains was obtained.

Trust Wallet’s Wallet Core documentation is available at and its security information is published at

Mobile Reports Differ From the 2025 Extension Breach

Trust Wallet has previously faced a confirmed wallet-draining compromise, but through a different attack path. The December 2025 browser-extension compromise involved a malicious version 2.68 uploaded to the Chrome Web Store after attackers gained access to publishing credentials.

That breach ultimately affected 2,520 wallet addresses and involved about $8.5 million. Trust Wallet specifically excluded mobile-app-only users from the incident’s scope, making the 2025 extension compromise insufficient to explain the current mobile reports without additional evidence. Trust Wallet’s official community update is available at

Wallet Attacks Extend Beyond Software Exploits

The reports emerged as wallet owners faced another security campaign based on social engineering rather than compromised wallet software. Trezor and BitBox users were targeted this week by a coordinated hardware-wallet phishing campaign using fabricated warnings that claimed defective microcontrollers had weakened recovery phrases.

Trezor’s warning confirmed that no genuine security advisory existed and that its wallets and recovery phrases remained safe. BitBox issued a parallel warning after users received similar messages. The companies’ posts are available at https://x.com/Trezor/status/2097786518110609620?s=20\u0026utm_source=chatgpt.com and https://x.com/BitBoxSwiss/status/2097793026336981079?s=20\u0026utm_source=chatgpt.com.

As of September 10, Trust Wallet had published no September 2026 security incident. Its public status page continued to list the wallet app, browser extension, and supporting services as operational:

Source: https://cryptoadventure.com/trust-wallet-users-report-unexplained-mobile-drains-as-cause-remains-unknown/