A post showed up on the r/CryptoScams subreddit from a user named Difficult-Branch-53 who lost a six-figure amount in crypto and still can't figure out exactly how his wallet got drained. The post went up about 16 hours ago, and the author is straight up asking anyone who knows their way around on-chain data to take a look at the transaction history and share their thoughts.
Here's the gist. A massive amount of funds disappeared from the wallet TLDEq4zqKBihxGGmn6wjmiqsqPUjz13Dgu, and in the same minute, some token called Chuduoquian got deployed from that same address, which the author describes as a trash Chinese coin. After that, the wallet permissions were switched to multisig or fully handed over to other addresses, and the deployment happened in batches.
The victim describes his setup like this: seed phrase is safe, Trust Wallet, strictly iOS, no dApps or smart contracts, didn't sign or approve anything. No computer, just an iPhone running iOS 26 or higher.
The top-voted reply came from snuggly_cobra. According to him, this is a classic scenario: some random person messaged the victim, the conversation moved to WhatsApp or Telegram, they showed fake screenshots of growing profits, the money went to a sketchy wallet, and the seed phrase was handed over voluntarily, which is basically like giving away your bank card PIN.
OP disagreed and replied that none of that happened and he never interacted with anything. User Few_Mention8426 even pointed out that this reply was off-topic. snuggly_cobra didn't back down and shot back that you can't just steal coins from a legit exchange, but if you hand over your seed, consider the money gone, and if the author could figure out the mechanics of the hack himself, he wouldn't have fallen for it in the first place.
Another line of reasoning came from Calamero. He thinks the Chinese token is a secondary scam triggered by the permission change, and the real drain is a private key leak, because without it, switching the wallet to multisig would be impossible. He offered to have the author DM him the address to take a closer look, to which BudgetPresent2089 reasonably replied that the address is already posted in the thread. Calamero clarified that he meant the separate spam token address, not the main wallet.
Other commenters chipped in. intelw1zard guessed there are too many variables, but most likely the person installed a fake Trust Wallet or landed on a drainer site instead of the real one. bl4zed_N_C0nfus3d summed it up briefly: this is definitely user error. webbinatorr added some sarcasm: asking for help after the drain is like calling the vet when your pet is already dead. spicybright asked the uncomfortable question: was that six-figure deposit even real money from the victim, or just a fake profit number on a screen. DefiThrowaway asked for specifics: which coins exactly and the tx IDs.
Meanwhile, OP keeps watching Tronscan and sharing details in the comments. According to him, Trust Wallet had been installed for a long time and was definitely from an official source. He sees that the attack is hitting wallets with balances starting at 2 million, and every victim gets the same token. During the discussion, he noted that about 10 minutes ago another wallet with 100k got switched to multisig, and 20 minutes ago, another one. He completely rules out social engineering and leans toward either malware, which is unlikely on a clean iOS setup with no computer, or some exploit he calls "darksword." He specifically emphasizes the goal of the post: not to get the money back, but to understand the mechanics and warn anyone who notices similar activity in their balance.
The bottom line is simple and grim. Based on the thread's reaction, getting the funds back is highly unlikely, and there's still no consensus on the attack vector: one camp is convinced this is standard social engineering with a leaked seed phrase, while another allows for a private key leak or an iOS vulnerability. The original source is the post on r/CryptoScams, and the full on-chain history is open for inspection on Tronscan at address TLDEq4zqKBihxGGmn6wjmiqsqPUjz13Dgu.
crypto address
source
https://www.reddit.com/r/CryptoScams/comments/1wtc9dg/wallet_drained_need_help_in/
Trust Rating
related to the category