Fake Trezor Support: One Recovery Phrase, $282 Million Gone
Someone posing as Trezor support talked a holder into revealing a wallet recovery phrase, then took $282 million in bitcoin and litecoin.
Key numbers
$282M
Stolen
$700K
Frozen
Fake Trezor support
Method
Unknown
Attacker
At about 11 o'clock on the night of Saturday 10 January 2026, UTC, a crypto holder did the one thing every wallet maker tells its customers never to do. Someone claiming to work for Trezor support asked for the wallet's recovery phrase, and the holder handed it over. Within minutes the wallet was empty.
It held 1,459 bitcoin and about 2.05 million litecoin. ZachXBT, the pseudonymous blockchain investigator who made the theft public on 16 January, put the loss at more than $282 million. It was the largest theft of 2026 at that point, and one of the largest ever taken from a single person by social engineering, the craft of manipulating people rather than breaking computers. It beat the roughly $243 million taken from a Washington, D.C. investor in August 2024, though it fell short of the $330 million an elderly American lost in April 2025.
Trezor was not hacked. No device, app or server belonging to the company was breached. ZeroShadow, the security firm that traced the money, described the incident as "social engineering rather than any compromise of wallet software or private-key infrastructure". The lock worked. The owner was talked into opening the door.
AI agents and automation
Could AI answer your customers from your own documents?
Assistants trained on your files, website and FAQs, with limits on what they can say. Fixed price before any work starts.
AI agents and automation
What a recovery phrase is
Trezor is made by SatoshiLabs, a company based in Prague, and sells hardware wallets: small devices about the size of a car key fob that store the secret codes controlling crypto. The coins themselves never sit on the device. They live on a blockchain, a public ledger that works like a company's share register. What the device holds is the private key, the signature that authorises moving them. Keeping that key on a gadget that never touches the internet is like keeping share certificates in a home safe instead of on a laptop.
When a hardware wallet is first set up, it shows its owner a list of ordinary English words, usually 12 or 24. This is the recovery phrase, also called the seed phrase. It is the backup. If the device is lost, broken or stolen, typing those words into any new wallet rebuilds the key and restores every coin. The closest everyday comparison is the key to a safe-deposit box, written on a piece of paper. Whoever holds the paper holds the box, from anywhere in the world, with no PIN, no signature check and no bank manager to call.
That is why nobody legitimate ever asks for it. A wallet maker does not need the words to repair a device, update software or confirm who a customer is, and the words cannot be "verified" without giving the money away. Trezor's own guidance says there is only one occasion when a Trezor device will reveal the backup: during the backup procedure itself. Any support agent, exchange employee or official who asks for the phrase is, by definition, trying to take the money.
How the theft worked
ZeroShadow said the victim was an individual who had been "tricked into sharing their seed phrase by an actor impersonating Trezor 'Value Wallet' support". Several reports described the approach as a phone call. How the impostor found the victim, and what story made the request sound reasonable, has not been made public. The victim has never been named.
The rest took minutes. The attacker typed the words into a wallet of their own, which rebuilt the victim's keys on a different device. Then they sent everything out, exactly as the real owner could have done. To the Bitcoin and Litecoin networks this was a normal, authorised transfer, because in their terms it was one. Neither network has a way to reverse or cancel a payment.
Litecoin, one of the oldest cryptocurrencies, launched in 2011 by former Google engineer Charlie Lee, made up more than half of the haul. The 2.05 million coins taken amount to roughly 2.7 percent of all litecoin in existence. The dollar figure depends on the hour it is measured. ZachXBT's $282 million is the number most reports used and CertiK, a blockchain security firm, later counted $284 million. At CoinGecko prices on the night itself, about $81 per litecoin and $90,400 per bitcoin, the total was nearer $298 million.
Where the money went
The thief moved fast, and mostly into Monero, a privacy coin built so that the sender, the receiver and the amount of every payment are hidden. Where bitcoin works like a cheque that leaves a paper trail, Monero works more like cash. The swaps ran through instant exchanges, websites that trade one coin for another in minutes without asking for identity documents, closer to a no-questions bureau de change than to a regulated broker.
Monero's market is small next to a sum like this. Buying tens of millions of dollars of it in a few days acted like a huge buy order in a thinly traded small-cap stock. CoinGecko data shows Monero (XMR) trading between about $440 and $470 on 10 January. It rose every day after the theft and set an all-time high of $797.73 at 11:34 UTC on 14 January, up roughly 75 percent in four days. By 20 January it was back at about $512. Litecoin moved the other way, sliding from about $81 to about $72 by 15 January while bitcoin rose, although no firm has attributed that drop to the thief's selling.

Part of the bitcoin went through THORChain, a decentralised swap network: an automated currency exchange run by code, with no company in the middle and no customer checks. On-chain trackers counted 818 BTC swapped there into 19,631 ether, 3.15 million XRP and 77,285 litecoin. The security firm PeckShield later put the THORChain total at about 928.7 BTC, roughly $71 million, and tracked 1,468.66 ether, about $4.9 million, into Tornado Cash, a mixer that pools deposits from many users so that the coins coming out cannot be matched to the coins going in.
ZeroShadow said it flagged the flows as they happened and got about $700,000 frozen within roughly 20 minutes, before it could be turned into Monero. That is about a quarter of one percent of the loss.
Who did it
Nobody has been named, charged or arrested. Early online speculation pointed at North Korea's Lazarus Group, the state hacking unit behind the $1.5 billion Bybit theft. ZachXBT rejected that directly: "It's not North Korea."
The method, a call to a wealthy holder from someone posing as customer support, matches the playbook of the English-speaking phone-scam crews ZachXBT has tracked for years. No investigator has publicly tied this theft to any of them.
The August 2024 case shows how these crews can come undone. On 18 August 2024 a Washington, D.C. investor lost more than 4,100 bitcoin to callers posing as Google and Gemini staff. The FBI arrested Malone Lam, a Singaporean citizen living in Miami, in September 2024. In September 2026 Lam, now 22, pleaded guilty to RICO conspiracy, a charge written for organised crime, becoming the 11th of 18 defendants to plead guilty. He faces up to 20 years in prison. That crew spent its money in the open. The January 2026 thief went almost straight into Monero, which leaves far fewer threads to pull.
The aftermath
More than eight months on, none of the money has been returned. About $700,000 was frozen on the night, and everything else is either in Monero, where it cannot be followed on a public ledger, or has passed through THORChain and Tornado Cash. The victim has not been identified and no law enforcement agency has publicly announced an investigation, a suspect or a seizure connected to the theft.
The loss dominated the year's early figures. CertiK, the blockchain security firm, counted about $400 million stolen across crypto in January 2026 and said this single theft made up roughly 71 percent of the adjusted total. Later in the year several hacks of companies overtook it, including Kelp DAO ($292 million), Drift Protocol ($285 million) and Bitget ($387.5 million). No theft from a single private holder has been reported as larger.
Trezor's customers have become a steady target since. In August 2026 Trezor disclosed that ShipMonk, the company that shipped its orders, had been breached, exposing the names and addresses of more than 13,000 buyers, a count later widened by another 67,000 US customers. In September hackers took over accounts at Brevo, the email service Trezor used for newsletters, and sent about 347,000 phishing emails to Trezor customers. One carried the subject line "Critical Security Alert: STM32 Entropy Vulnerability" and linked to an app that asked for the wallet backup. Trezor said none of its products, wallets or account systems were affected. The trick was the same as in January: the only way to rob a hardware wallet that works is to persuade its owner to read out the words.
The case that set the previous mark is further along. Malone Lam, the Singaporean who led the crew behind the August 2024 theft, pleaded guilty to RICO conspiracy in September 2026 before US District Judge Colleen Kollar-Kotelly in Washington, D.C., with a status hearing set for 8 December 2026.
What this teaches
- No wallet maker, exchange, bank or government agency ever needs a recovery phrase. Anyone who asks for it is stealing.
- A hardware wallet protects the key from computers, not from its owner. Social engineering skips the device entirely.
- Blockchain transfers cannot be reversed. Once the words are out, the only hope is that a firm freezes some of the funds within minutes.
- Converting to Monero through no-ID instant exchanges left almost nothing to trace, so a $282 million theft ended with $700,000 frozen.
- Real support staff start conversations through channels the customer opened. Unsolicited calls or emails claiming to be support should be treated as hostile.
- Very large holdings kept by one person under one phrase are a single point of failure. Splitting funds, or using setups that need several keys, limits what one mistake can cost.

COMMENTS