12-word seed phrase led to $282M crypto heist
On Jan. 10, 2026, a scammer posing as Trezor support obtained a user’s 12-word seed phrase and emptied about $282 million in bitcoin and litecoin.
On Jan. 10, 2026, an attacker impersonating Trezor customer support obtained a user’s 12-word recovery phrase and drained roughly $282 million in bitcoin and litecoin within minutes. The thief moved about $139 million in bitcoin and $153 million in litecoin across chains and into privacy services, leaving the holder with no recoverable funds.
Blockchain-forensics firm ZeroShadow, which tracked the flow of funds, described the incident as “social engineering rather than any compromise of wallet software or private-key infrastructure.” The firm flagged and froze about $700,000 of the stolen assets within 20 minutes during its monitoring.
A BIP39 seed phrase of 12 or 24 words is not a conventional password but the cryptographic origin of a wallet. The words are drawn from a fixed list of 2,048 entries; each word represents 11 bits of entropy. A 12-word phrase carries about 128 bits of entropy after a built-in checksum, while a 24-word phrase carries about 256 bits. At an optimistic rate of one billion guesses per second, brute-forcing an unknown 12-word phrase would take on the order of 10^22 years.
The security risk comes from exposure, not brute force. If some words are known from a photo, cloud backup or a scam conversation, the number of possible combinations falls sharply. With six of 12 words known, the remaining space would still take centuries to search at high guess rates. With seven known words, the effort drops to under a year; with eight known words, to a few hours; and with ten or eleven known words, to milliseconds.
BIP39 includes a checksum that helps detect transcription errors. Part of the final word encodes checksum bits so a mistyped phrase often fails to restore, alerting a user that the backup was copied incorrectly rather than silently creating a different wallet.
After taking the words, the attacker used cross-chain services including THORChain, instant-exchange platforms, conversions into Monero and peel-chain transfers to obscure the trail and complicate recovery. ZeroShadow’s quick action recovered only a small portion of the total value.
Separate analytics estimate that a large share of mined bitcoin may already be permanently inaccessible because owners lose seed phrases, destroy backups or die without passing phrases to heirs. When a seed phrase is lost with no backup, there is no service that can restore access to the on-chain funds.
Wallet providers and security experts advise never entering a seed phrase into a website or an app and never giving it to support staff. Recommended handling measures include writing the phrase by hand on durable material stored in secure locations, using hardware wallets so the words never touch an internet-connected device, and preparing inheritance or recovery plans for heirs.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








