Chaincatcher $282 Million Stolen in Trezor Impersonation Scam via Social Engineering
Article Content
- •Attackers impersonated Trezor support to steal $282 million in cryptocurrency.
- •The incident was a social engineering attack, not a software breach.
- •Approximately $700,000 of the stolen funds were frozen shortly after the theft.
On August 2, 2026, a Bitcoin and Litecoin holder fell victim to a scam involving attackers impersonating Trezor support staff. The victim provided a 12-word mnemonic phrase, leading to the theft of approximately $282 million in assets, including $139 million in Bitcoin and $153 million in Litecoin. The incident was confirmed by blockchain forensic firm ZeroShadow, which stated that it was a social engineering attack rather than a breach of wallet software. The stolen funds were quickly split using the THORChain cross-chain bridge and converted into Monero through instant exchanges. ZeroShadow's monitoring team managed to freeze around $700,000 of the stolen funds within 20 minutes. This incident highlights the risks associated with sharing mnemonic phrases and the potential for significant financial loss. Chainalysis estimates that a large portion of mined Bitcoin may be permanently inaccessible due to lost keys and poor inheritance planning.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Litecoin in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…