A Bitcoin and Litecoin holder handed 12 seed words to attackers posing as Trezor support on January 10, leading to about $282 million in assets being moved, including about $139 million in Bitcoin and $153 million in Litecoin. According to Odaily, blockchain forensics firm ZeroShadow said the incident resulted from a social engineering attack, not a breach of wallet software or private-key infrastructure.
The stolen funds were split through the THORChain cross-chain bridge within minutes and converted into Monero through instant exchange services. ZeroShadow's monitoring team flagged and froze about $700,000 within 20 minutes. Under the BIP39 standard, a 12-word seed phrase contains about 128 bits of entropy, while a 24-word seed phrase contains 256 bits of entropy. Chainalysis estimates that up to 23% of mined Bitcoin is permanently inaccessible because of lost keys, affecting millions of BTC due to forgotten seed phrases, damaged backups, and the absence of inheritance plans.