Chaincatcher
$282 Million Stolen in Trezor Impersonation Scam via Social Engineering
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On August 2, 2026, a Bitcoin and Litecoin holder fell victim to a scam involving attackers impersonating Trezor support staff. The victim provided a 12-word mnemonic phrase, leading to the theft of approximately $282 million in assets, including $139 million in Bitcoin and $153 million in Litecoin. The incident was confirmed by blockchain forensic firm ZeroShadow, which stated that it was a social engineering attack rather than a breach of wallet software. The stolen funds were quickly split using the THORChain cross-chain bridge and converted into Monero through instant exchanges. ZeroShadow's monitoring team managed to freeze around $700,000 of the stolen funds within 20 minutes. This incident highlights the risks associated with sharing mnemonic phrases and the potential for significant financial loss. Chainalysis estimates that a large portion of mined Bitcoin may be permanently inaccessible due to lost keys and poor inheritance planning.
Key Points: • Attackers impersonated Trezor support to steal $282 million in cryptocurrency. • The incident was a social engineering attack, not a software breach. • Approximately $700,000 of the stolen funds were frozen shortly after the theft.