Something is draining funds from Trust Wallet mobile accounts, and nobody — including the wallet's own security team — has yet explained how. Reports surfacing from affected users describe a phenomenon that cuts deeper than a typical phishing compromise or malware infection: wallets secured by entirely separate seed phrases, generated independently, held on the same iPhone, have been emptied weeks apart. The implications for mobile-native crypto custody are serious, and they demand scrutiny the industry has not yet delivered.
The most unsettling documented case involves a single iPhone user who created two entirely distinct wallets — each with its own recovery phrase, each theoretically representing an independent cryptographic identity. The first wallet was drained on August 12, with Tether (USDT) among the assets taken. Weeks later, the second wallet followed. Two separate seeds. Two separate losses. One device. The arithmetic of that sequence is damning, because under normal assumptions about how hierarchical deterministic wallets function, compromising one seed phrase should yield precisely zero access to funds secured under a different one.
That is what makes this pattern so difficult to dismiss as user error. The standard explanations security researchers reach for first — a leaked seed phrase photographed or screenshot, a malicious clipboard app, a fake recovery prompt — struggle to account for two independently generated wallets being targeted sequentially on the same hardware. If the seed phrases were separately compromised through social engineering or phishing, the timing gap between the two drains would be an extraordinary coincidence. If a keylogger or screen-capture malware was present on the device, it would need to have captured two distinct mnemonic phrases at two different points in time, both without the user apparently noticing any suspicious behavior on the device.
The phrase "valid signing authority" sits at the center of this mystery. Blockchain transactions only move funds when signed by a private key derived from a valid seed. There is no bypass, no administrative override, no recovery backdoor baked into the protocol itself. Whatever drained these wallets possessed — or derived — the correct cryptographic credentials. That narrows the field of possible explanations considerably: the seeds were exposed through the device's software environment, through Trust Wallet's own code or data handling, through an Apple iOS-level vulnerability, or through some combination of factors that allowed an attacker to reconstruct private keys without ever seeing the raw mnemonic phrases.
None of those explanations are comfortable. An iOS-level vulnerability capable of extracting wallet seed data from secured application storage would represent one of the most serious mobile security failures in recent memory and would affect far more than Trust Wallet users. A flaw within Trust Wallet's own key storage or entropy generation — the process by which seed phrases are created — could theoretically produce predictable keys that an attacker could precompute, though this would need to be confirmed through rigorous code auditing. The possibility that seed phrases generated on the same device share some underlying entropy weakness, however slim, cannot be ruled out without a thorough forensic investigation.
Trust Wallet, which is backed by Binance and operates as one of the most widely used non-custodial mobile wallets globally, has not yet provided a definitive technical explanation for the reported incidents. As of the time of reporting, the cause remains officially unknown. That silence — or inability to speak — is itself informative. Either the engineering team has not been able to reproduce the exploit vector, which suggests the attack surface is narrow or device-specific, or the investigation is ongoing and findings have not been made public. Neither scenario reassures the hundreds of thousands of users who rely on the application to self-custody meaningful sums of digital assets.
The broader context matters here. Mobile wallets have always occupied an uncomfortable middle ground in the custody debate. They offer convenience and genuine self-custody — no exchange counterparty risk, no corporate custodian — but they run on consumer hardware managed by operating systems designed for general use, loaded with third-party applications and exposed to a constant stream of software updates and potential vulnerabilities. Security purists have long argued that mobile wallets are unsuitable for storing anything beyond spending money, with meaningful holdings reserved for hardware wallets or air-gapped devices. Cases like the ones now emerging from Trust Wallet users add empirical weight to that argument.
Until Trust Wallet or independent researchers produce a credible explanation of how two independent seed phrases on the same iPhone were compromised in succession, users holding significant balances on mobile wallets — any mobile wallet — have rational grounds for concern. The transactions were signed correctly. The funds are gone. And the mechanism that made it possible remains, for now, a black box. That is not a situation the industry can afford to let linger without a transparent, technically rigorous public accounting.
Written by the editorial team — independent journalism powered by Bitcoin News.