Points of Focus
- A Reddit user lost 83.80 SOL from a Phantom wallet and asked the community why.
- Their own detailed account rules out a signed transaction, per their own claim.
- Community theories converge on malware capturing a seed phrase on screen.
A Reddit post asking for help understanding a Phantom wallet loss drew more than 270 replies in a day.
The original poster’s own account, given across several comments, is unusually specific. It is also, by the community’s own repeated assessment, still not enough to identify what actually happened.
What the poster says happened, in their own words
The account, pieced together across the thread: the poster downloaded Phantom from the official App Store, restored an existing wallet using a seed phrase they had kept written in a notebook, then sent SOL from Revolut into that wallet.

Separately, while trying to create a new wallet without using Google sign-in, they clicked to view that new wallet’s seed phrase and private key. Immediately after, the funds were gone. The poster stated twice in the thread that they had not signed any transaction.
That last detail matters more than it might first appear. Most documented Solana wallet-draining techniques, from standard approval phishing to more advanced tricks involving Solana’s account-ownership model, require the victim to sign something. If the poster’s account is accurate, the mechanism behind this loss sits outside that usual pattern.
Where the thread’s own diagnosis actually lands
Commenters spent most of the thread pushing back on the account rather than accepting it.
One user, MakCapital, laid out a detailed diagnostic checklist, asking the poster to identify which seed generated the receiving address, check that address in a block explorer, and share the specific wallet involved. The poster never answered those questions or provided the address, and that exchange ended unresolved.

The theory that gained the most traction, from a user posting as WestQ, was that a keylogger or clipboard-monitoring program on the poster’s device captured the seed phrase the moment it was displayed on screen, then used it to drain the wallet within seconds.
That theory fits the poster’s own timeline better than a signed-transaction exploit would: view the phrase, lose the funds, no signature required.
Another commenter linked a separate Reddit thread describing iOS App Store apps with screenshot-reading malware as a possible related pattern, though that link alone does not confirm malware caused this specific loss.
A third commenter, MycoHost01, pointed to the poster’s mention of avoiding Google sign-in as evidence the original wallet may have been tied to an email account that was itself compromised, a different theory again, and one the thread also left untested.
What this incident actually demonstrates
No single explanation in the thread was confirmed, including by the poster’s own admission that key details remain unclear even to them.
What the thread does demonstrate clearly is a real, common failure point: displaying or restoring a seed phrase on an internet-connected device creates a window where that phrase can potentially be captured, regardless of which specific technique does the capturing. A hardware wallet or an air-gapped device removes that window entirely. A notebook and a phone screen do not.
Unlock premium content
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share


