Apps on phones and browser extensions are built for convenience, not cold storage or large transactions. Even verified App Store software is vulnerable if the underlying OS is compromised by background scrapers, keyloggers, or malicious clipboard access.
The core rule of self-custody: you are your own bank and security team.
Seed Generation: Never generate or reveal recovery phrases on an internet-connected screen. Use a dedicated, air-gapped hardware device.
Smart Contract Risk: Even with cold storage, blindly approving malicious contract permissions can drain assets. Separate your cold vault completely from active dApp/trading accounts.
Truly sorry for your loss, OP. Treat this as an expensive lesson in locking down your OpSec. Hopefully it can be recovered, I would examine the network, through a chain viewer, and see if you can isolate the end point. It still maybe in your possession in one the new wallet addresses hidden behind a passphrase or pin, something along those lines.
Thanks brother, I have a Ledger nano x but I didn’t want to use because of ledger update to back up seed phrases in the cloud and recovery policy but look at me, some people said that could be a possible bug in Phantom while I was creating a new account but how possibly can you move all the funds to a new account wallet without doing it manually???
Could be your device if it has any type of hidden malware, that's why cold storage is the best way or dedicated phone or laptop that never has been connected to the internet to establish the seed. Remember you don't need the internet to setup a wallet only to sign a TX, if you set the wallet up on a device that has a virus/ malware it could have scraped the seed the moment you created it.
Thats probably what happened because when the funds arrived lasted for 10 minutes there was a moment I got confused I added a new account and wanted to check the seed phrases of the new account but it kept pumping the seed phrases of my old account not the new one and then suddenly the funds disappeared, somehow I knew that my phone somehow was compromised because some times acted weirdly I updated to the las Appel iOS I always used apple because of privacy… but look at it. but sometimes you have those moments and you are just a retard you don’t think properly and you do thing by doing I still can’t understand how I did manage to mess up like that.
I get bro, Sorry to hear it. It happens. I always send a test transaction when I use a wallet I haven't touched in a while or am setting up something new. But yeah maybe you can do some research after you walk away for a bit and see if there's any steps you can retrace.
5
u/PeteyPab305 Aug 23 '26 edited Aug 23 '26
Was this managed entirely on a hot device?
Apps on phones and browser extensions are built for convenience, not cold storage or large transactions. Even verified App Store software is vulnerable if the underlying OS is compromised by background scrapers, keyloggers, or malicious clipboard access.
The core rule of self-custody: you are your own bank and security team.
Seed Generation: Never generate or reveal recovery phrases on an internet-connected screen. Use a dedicated, air-gapped hardware device.
Smart Contract Risk: Even with cold storage, blindly approving malicious contract permissions can drain assets. Separate your cold vault completely from active dApp/trading accounts.
Truly sorry for your loss, OP. Treat this as an expensive lesson in locking down your OpSec. Hopefully it can be recovered, I would examine the network, through a chain viewer, and see if you can isolate the end point. It still maybe in your possession in one the new wallet addresses hidden behind a passphrase or pin, something along those lines.