Fri. Sep 11th, 2026

Trust Wallet User Says 0.150509 BTC Was Moved Without Authorization, Funds Traced to MEXC

ByShane Neagle

September 11, 2026 #Trust Wallet
Trust Wallet Browser Extension Incident What the $6–7 Million Hack RevealsTrust Wallet Browser Extension Incident What the $6–7 Million Hack RevealsTrust Wallet Browser Extension Incident What the $6–7 Million Hack Reveals

User Says MEXC Temporarily Restricted Account Receiving the Bitcoin

A Trust Wallet user says approximately 0.150509 BTC was transferred from their self-custody wallet without authorization, with the funds subsequently traced to an account associated with crypto exchange MEXC.

The allegation was published on Sept. 11 in Trust Wallet’s Reddit community. The user provided the full Bitcoin transaction ID, sending address and receiving address, making the on-chain transfer itself independently traceable even though the circumstances surrounding how it was authorized remain unverified.

According to the post, the transaction occurred on Sept. 1 and moved 0.150509 BTC from address bc1qq6n58khnywyehpsjpck3wpx2jc3mz3z0qykvrl to bc1qq6nha5gzfn38qgfrnsk26u06scdd3dupgjmkpt.

The transaction ID supplied by the user is e1ed588959e5791f3830f288e24aa9729913b9c725b49a32e3d42aa9843498f0.

The poster said they did not initiate or knowingly sign the transfer and subsequently contacted Trust Wallet for assistance. According to their account, Trust Wallet raised possible exposure of the wallet’s recovery phrase as an explanation but did not provide evidence showing when or where the phrase might have been compromised or precisely how the disputed transaction was signed.

The user stressed that they were not accusing Trust Wallet of causing the loss and were seeking a technical explanation of how signing authority was obtained.

That distinction is important because Trust Wallet is a self-custody wallet. Trust Wallet says users retain control of their private keys and secret phrases and that the company itself does not have access to those credentials. Its support documentation says an unauthorized transfer can generally indicate that a wallet has been compromised or, for assets supporting smart-contract permissions, that a malicious approval may have been granted.

Native Bitcoin does not use the token-approval mechanism common on networks such as Ethereum or Tron. A valid Bitcoin spend requires control of the private key necessary to produce the required signature, but blockchain data alone normally cannot identify how that signing capability was obtained.

That means the transaction itself cannot establish whether the seed phrase was exposed, a device was compromised, credentials were restored into another wallet, the user was tricked into signing something, or another attack vector was involved.

The user said Trust Wallet’s tracing work subsequently connected the funds to MEXC.

According to the post, MEXC temporarily restricted the associated account after receiving the user’s report but told the victim that a law-enforcement request would be necessary to maintain the restriction. The user, who said they attempted to report the theft to authorities in Vietnam, claimed they were unable to obtain the required police acceptance document.

That description is consistent with MEXC’s published process for handling allegedly stolen assets.

MEXC says users can submit transaction IDs, compromised wallet addresses, receiving addresses and evidence of ownership through its abnormal-funds reporting process. When the evidence is considered sufficient, the exchange may temporarily freeze suspected assets, but the victim must generally provide proof of a police report and arrange for a formal law-enforcement request within 48 hours if they want the restriction maintained.

MEXC’s broader legal guidelines state that account freezes and disclosure of user information are ultimately handled through requests from authorized law-enforcement or judicial bodies. The exchange says asset recovery itself requires an appropriate decision from a competent judicial body rather than simply a request from the alleged victim.

There is currently no public evidence tying the Sept. 1 transfer to a vulnerability in Trust Wallet.

Trust Wallet’s public status page shows no platform incidents reported for September and currently lists its app, browser and supporting services as operational.

However, the allegation arrives amid other recent social-media claims involving unexplained Trust Wallet transfers.

On Sept. 9, another Reddit user alleged that two separately created Trust Wallet wallets using different recovery phrases were drained weeks apart while both had been used on the same iPhone. That poster claimed the transfers involved direct owner-authorized transactions on Tron rather than token approvals. That account is also unverified, involves a different blockchain and has not been technically connected to the current Bitcoin case.

The Sept. 1 Bitcoin incident therefore remains a single-user allegation rather than evidence of a broader Trust Wallet security failure. But unlike many wallet-loss claims posted online, the publication of the transaction ID and the alleged movement of funds into a centralized exchange gives investigators a potential path to determine where the Bitcoin ultimately went.

Why the MEXC Trail Matters More Than the Wallet Allegation

The most interesting part of this case is not that somebody says Bitcoin disappeared from a wallet. Those reports appear constantly across crypto forums.

It is that the money may have reached a regulated point of control.

Once stolen cryptocurrency remains entirely in self-custody, recovery can become extremely difficult. Bitcoin transactions are irreversible, and there is no network administrator that can cancel a valid transfer simply because its owner says the transaction was unauthorized.

A centralized exchange changes that equation.

If the destination really belongs to MEXC and the funds remain under the exchange’s control, there may be an identifiable account behind the deposit. That can potentially mean KYC information, login records, withdrawal records and subsequent transaction history exist somewhere off-chain.

That does not guarantee recovery. It does, however, turn what might otherwise be an anonymous blockchain trail into a possible legal and forensic process.

The frustrating part for the victim is the gap between those two systems.

MEXC can temporarily restrict funds when presented with credible evidence, but it cannot permanently confiscate a customer’s assets simply because another person claims they were stolen. Exchanges need formal law-enforcement or judicial documentation to protect themselves from freezing legitimate users based on false or disputed allegations.

The victim therefore may have reached the point where the blockchain investigation is easier than the legal one.

The technical question surrounding Trust Wallet is also narrower than it initially sounds.

A Bitcoin transaction containing a valid signature proves that the necessary private-key authority existed somewhere when the transaction was created. It does not prove that the Trust Wallet application itself signed it.

If somebody obtained the recovery phrase, they could reconstruct the same Bitcoin wallet in completely different software and create the transaction without interacting with Trust Wallet again.

That is why the user’s demand for a precise explanation may be difficult for Trust Wallet to satisfy. A self-custody wallet provider generally cannot observe every use of a private key once the seed exists outside its infrastructure.

At the same time, simply telling a customer that their seed phrase was probably compromised is not a forensic conclusion.

There is a meaningful difference between saying key compromise is the most likely explanation and demonstrating how that compromise occurred. Device logs, backup methods, application history, phishing exposure and the exact movement of funds all matter.

The separate recent report involving two wallets on the same device makes continued monitoring worthwhile, but it still does not justify claiming a Trust Wallet vulnerability. Similar symptoms can emerge from completely different causes, including malware, compromised cloud backups, reused devices, social engineering or insecure seed storage.

What would make this story materially stronger is additional evidence: correspondence from MEXC confirming the destination attribution, Trust Wallet’s actual support responses, device and backup details, and any indication that other unrelated users experienced comparable unauthorized Bitcoin signatures.

For now, this is best treated as a forensic lead rather than a security incident.

But if the receiving exchange really has identified and restricted the beneficiary account, the case has something most wallet-drain complaints do not: a potentially reachable endpoint.

Financial Markets Analyst and Digital Assets Journalist at  |  More Posts

Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms.

He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments.

Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

Leave a Reply

Your email address will not be published. Required fields are marked *