Market
Investor Loses $284 Million to Phishing Scam as January Crypto Theft Nears $400 Million
16 Jan 2026, 08:00
8 views
Admin
A single phishing attack impersonating Trezor support drained $284 million from one investor, accounting for the bulk of a nearly $400 million month for crypto theft.
A single social engineering scam accounted for the vast majority of crypto losses in January, after a lone investor lost $284 million on January 16 to a phishing campaign that impersonated Trezor customer support. The attacker convinced the victim to reveal a hardware wallet recovery seed phrase, at which point the funds were drained in what security researchers describe as one of the largest single-victim thefts on record. The incident alone represented roughly 71% of the month's total adjusted losses.
Across the full month, 40 recorded incidents cost the crypto industry approximately $370.3 million, a figure that climbed to more than $400.3 million once a separate $30 million exploit of the Solana-based platform Step Finance on January 31 was factored in. Taken together, January's losses represented a nearly fourfold increase from the same month a year earlier, when attackers made off with roughly $98 million, and more than triple December 2025's total of $117.8 million.
What distinguished January from many prior months of crypto theft was the shift in attack methodology. Rather than complex smart-contract exploits or protocol-level vulnerabilities, the month's headline loss came down to a straightforward, if devastatingly effective, social engineering scam targeting an individual rather than an exchange or DeFi protocol. Security researchers have noted a broader trend toward this kind of attack, which requires no technical breach of any platform's code, only the ability to convincingly impersonate a trusted support channel and manipulate a victim into handing over credentials directly.
The incident renewed warnings from hardware wallet manufacturers and security firms alike that even the most secure storage methods remain vulnerable to human error, and that no amount of on-device security can protect a user who is convinced to voluntarily reveal a recovery phrase to an attacker posing as legitimate support staff.
Hardware wallet makers have since introduced additional in-app warnings designed to flag unsolicited support contact as a likely scam, though security researchers caution that no software prompt can fully substitute for user awareness when attackers are willing to invest weeks building a convincing impersonation.
Across the full month, 40 recorded incidents cost the crypto industry approximately $370.3 million, a figure that climbed to more than $400.3 million once a separate $30 million exploit of the Solana-based platform Step Finance on January 31 was factored in. Taken together, January's losses represented a nearly fourfold increase from the same month a year earlier, when attackers made off with roughly $98 million, and more than triple December 2025's total of $117.8 million.
What distinguished January from many prior months of crypto theft was the shift in attack methodology. Rather than complex smart-contract exploits or protocol-level vulnerabilities, the month's headline loss came down to a straightforward, if devastatingly effective, social engineering scam targeting an individual rather than an exchange or DeFi protocol. Security researchers have noted a broader trend toward this kind of attack, which requires no technical breach of any platform's code, only the ability to convincingly impersonate a trusted support channel and manipulate a victim into handing over credentials directly.
The incident renewed warnings from hardware wallet manufacturers and security firms alike that even the most secure storage methods remain vulnerable to human error, and that no amount of on-device security can protect a user who is convinced to voluntarily reveal a recovery phrase to an attacker posing as legitimate support staff.
Hardware wallet makers have since introduced additional in-app warnings designed to flag unsolicited support contact as a likely scam, though security researchers caution that no software prompt can fully substitute for user awareness when attackers are willing to invest weeks building a convincing impersonation.