Trust Wallet users are reporting unexplained drains from mobile wallets, including a case involving two separately generated wallets with different recovery phrases on the same iPhone. The wa
Trust Wallet users are reporting unexplained drains from mobile wallets, including a case involving two separately generated wallets with different recovery phrases on the same iPhone. The wallets were reportedly emptied weeks apart, raising questions over how valid signing authority was obtained across two independent seeds.
The first loss occurred on August 12 when USDT left one wallet through a direct TRON token transfer that the owner says was never authorized. The second wallet remained untouched at first but was later drained after new funds were sent to it. The original user report does not establish whether the exposure originated from Trust Wallet, the phone, recovery-phrase handling or another compromise.
Direct Transfers Raise Key-Exposure Questions
The first reported transaction was a direct transfer() rather than an approval-based transferFrom transaction. That distinction points toward valid signing authority being used rather than an attacker simply exploiting a previously granted token approval.
Trust Wallet’s Wallet Core generates a new seed at random using secure random generation available on the device. Its self-custody model also keeps private keys under user control instead of storing them on Trust Wallet servers. The available evidence does not identify how the signing material in the reported drains was obtained.
Mobile Reports Differ From the 2025 Extension Breach
Trust Wallet has faced a confirmed wallet-draining compromise before, but through a different attack path. The December 2025 browser-extension compromise involved a malicious version 2.68 uploaded to the Chrome Web Store after attackers gained access to publishing credentials.
That breach ultimately affected 2,520 wallet addresses and about $8.5 million. Trust Wallet specifically excluded mobile-app-only users from the incident scope, making the 2025 extension compromise insufficient to explain the current mobile reports without additional evidence.
Wallet Attacks Expand Beyond Software Exploits
The reports arrive as wallet owners face another security campaign built around social engineering rather than compromised wallet software. Trezor and BitBox users were targeted this week by a coordinated hardware-wallet phishing campaign using fabricated warnings that claimed defective microcontrollers had weakened recovery phrases.
Trezor’s warning confirmed that no genuine security advisory existed and that its wallets and recovery phrases remained safe. BitBox issued a parallel warning after users received similar messages.
Trust Wallet had published no September 2026 security incident as of September 10, while its public status page continued to list the wallet app, browser extension and supporting services as operational.
The post Trust Wallet Users Report Unexplained Mobile Drains as Cause Remains Unknown appeared first on Crypto Adventure.