A post on the r/CryptoScams subreddit by user Impossible-Treacle-3, titled "Lost fund. Offer bounty for recovery" starts out looking like a technical question but ends with an offer of a reward for getting the money back — and that alone tells you how bad things got.
Here's the story: the guy was using Phantom Staked SOL (PSOL), which is the liquid staking feature inside the Phantom wallet. When he unstaked, it created a native stake account, and after the cooldown period, there was just one step left — withdrawing the "inactive stake". On September 28, 2026, he connected his Phantom wallet to a site called stakeconsole to do exactly that. The site asked him to sign a transaction labeled "unstake / withdraw / verify". He signed it — and now he's convinced it had a hidden transfer hard-coded into it, sending everything to the scammer's address. The critical part: he never gave anyone his secret recovery phrase or private keys. One single signature was all it took.
The result: 1,358.53 SOL — about $163,000 — was drained from his wallet. He noticed the funds were then moved to Jupiter (the biggest DEX aggregator on Solana) and asked the community to help freeze them.
The first reactions were skeptical. User UpbeatFix7299 said he straight up doubted the money was even real: "It's weird that this guy had $163k in liquid funds. They probably just showed him a fake balance". albensen21 shot back: maybe, but the author says the SOL was staked. When asked directly how much of his own money he put in, Impossible-Treacle-3 answered bluntly: $163k. All of it. Mine.
After that, the tone shifted. albensen21 delivered the verdict: the money was lost through a scam page, because with that kind of cash, they didn't even do basic DYOR — and he added a detail in an edit: the stakeconsole page is already down. UpbeatFix7299 doubled down with a fact: stakeconsole is a scam site registered less than two months ago. And the most important line: "The person who told you about this site is the one holding your money. Nobody here is going to get it back — especially not the scammers already sliding into your DMs".
A separate human touch to the story: amid the comments, the author wrote "I know I'm an idiot" — and even that confession got downvoted. You gotta give him credit for honesty though: he confirmed all the funds were his own and reported that he'd already filed a complaint with the regulator.
The request to freeze the funds is the central point of the post, and that's where the most substantial part of the thread unfolded. User AdventurousReserve99 (whose comment, with phrasing like "legal-via-Anthropic", looks like it was copied from an AI assistant's reply) broke down the technical side in detail. There is no mechanism to freeze stolen SOL — technical or legal. SOL is not an SPL token with freeze authority: at the Solana protocol level, there simply is no transfer freeze function.
And moving the funds to Jupiter? That's standard behavior for "drainers". According to the commenter, immediately after hitting the aggregator, the funds were most likely swapped for another asset or routed further — either in the same signed transaction or right after. It's done specifically to break the trail and, as the comment poetically put it, "freeze any hope".
The mechanics of this story are pretty much textbook: a legitimate need (withdraw inactive stake) → a phishing tool less than two months old → a trojan transaction where a harmless-looking "unstake / withdraw / verify" signature hides a full balance transfer → instant laundering through Jupiter to cover the tracks. No seed phrase leaked — the entire theft fit into a single click.
The thread's consensus is grim: the money can't be recovered, SOL can't be frozen, the trail is wiped, and the "recovery specialists" in your DMs are just round two of the same scam. A bounty format with no upfront payment is the only thing that makes sense (you want someone who works for results, not an advance fee), but even that is powerless here. What remains are reports to authorities, publicly recorded addresses — and a $163k lesson: before connecting your wallet to any service, check the domain's age, and read every transaction you're about to sign all the way through. Especially the one that just says "verify".
url
| domain | explore | registered | registrar | abuse email | score | average | |
|---|---|---|---|---|---|---|---|
| stakeconsole.com | July 30, 2026 | NameCheap, Inc | [email protected] | 5/100 | 5.0 | ||
| Blacklist: NoCoin Hexxium QuidsUp URLhaus FadeMind MetaMask Phishunt Badd-Boyz BlackBook CoinMiner OpenPhish ThreatFox TweetFeed PhishRadar Scam Block Abuse Block Phishing DB ScamSniffer PhishDestroy Malware Block Phishing Army Toxic Domains Filters Heroes GlobalAntiScam Phishing Block Pi-hole Trojan Scam Blocklist Fraud Blocklist Pi-hole Malware Crypto Blocklist Pi-hole Phishing Ransomware Block CyberHost Malware Pi-hole Malicious Pi-hole C2 Servers Thread Intelligence PhishDestroy Community | |||||||
crypto address
source
https://www.reddit.com/r/CryptoScams/comments/1wsl2qv/lost_fund_offer_bounty_for_recovery/
Trust Rating Lost ~ 163000 $
related to the category