Share
Subscribe to the AlphaWire Newsletter
A Reddit post asking for help understanding a Phantom wallet loss drew more than 270 replies in a day.
The original poster’s own account, given across several comments, is unusually specific. It is also, by the community’s own repeated assessment, still not enough to identify what actually happened.
The account, pieced together across the thread: the poster downloaded Phantom from the official App Store, restored an existing wallet using a seed phrase they had kept written in a notebook, then sent SOL from Revolut into that wallet.

Separately, while trying to create a new wallet without using Google sign-in, they clicked to view that new wallet’s seed phrase and private key. Immediately after, the funds were gone. The poster stated twice in the thread that they had not signed any transaction.
That last detail matters more than it might first appear. Most documented Solana wallet-draining techniques, from standard approval phishing to more advanced tricks involving Solana’s account-ownership model, require the victim to sign something. If the poster’s account is accurate, the mechanism behind this loss sits outside that usual pattern.
Commenters spent most of the thread pushing back on the account rather than accepting it.
One user, MakCapital, laid out a detailed diagnostic checklist, asking the poster to identify which seed generated the receiving address, check that address in a block explorer, and share the specific wallet involved. The poster never answered those questions or provided the address, and that exchange ended unresolved.

The theory that gained the most traction, from a user posting as WestQ, was that a keylogger or clipboard-monitoring program on the poster’s device captured the seed phrase the moment it was displayed on screen, then used it to drain the wallet within seconds.
That theory fits the poster’s own timeline better than a signed-transaction exploit would: view the phrase, lose the funds, no signature required.
Another commenter linked a separate Reddit thread describing iOS App Store apps with screenshot-reading malware as a possible related pattern, though that link alone does not confirm malware caused this specific loss.
A third commenter, MycoHost01, pointed to the poster’s mention of avoiding Google sign-in as evidence the original wallet may have been tied to an email account that was itself compromised, a different theory again, and one the thread also left untested.
No single explanation in the thread was confirmed, including by the poster’s own admission that key details remain unclear even to them.
What the thread does demonstrate clearly is a real, common failure point: displaying or restoring a seed phrase on an internet-connected device creates a window where that phrase can potentially be captured, regardless of which specific technique does the capturing. A hardware wallet or an air-gapped device removes that window entirely. A notebook and a phone screen do not.
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share