My Trust Wallet was drained after clicking a fake Binance email link, is my crypto gone?

asked 21d ago15 views50 answers
0

I'm so upset right now, I don't even know where to start. I received an email that looked super legit from Binance yesterday afternoon, saying my account had some suspicious activity and I needed to verify immediately. I clicked the link, logged in with my Trust Wallet (I use it for most of my crypto) and it just... spun for a bit. I didn't think much of it until this morning when I woke up and checked my wallet – literally everything is gone. My ETH, USDT, some BNB, all of it. The transactions are there on Etherscan, shows it went out pretty much immediately after I clicked. I feel so dumb. Is there *any* way to get it back? I've reported it to Binance but they said they can't do anything about transactions from an external wallet. Please, any advice helps. This was a significant amount for me.

Mentioned in this discussion
Binance· neutralTrust Wallet· neutralEtherscan· neutral

50 Answers

29

Ugh, this is a classic phishing attack, Aisha, and I'm really sorry it happened to you. When you clicked that link and connected your Trust Wallet, you essentially gave the scammers permission to access and drain your assets. It's not about logging in with a password, but rather approving a malicious smart contract or signing a malicious transaction under the guise of 'verification.' That's why Binance can't help directly – the funds weren't on their exchange, they were in your self-custody wallet, and *you* authorized the outgoing transaction, even if unknowingly.

Recovery in these cases is extremely difficult, almost impossible for most people. Once the crypto leaves your wallet and goes to the scammer's address, it's typically moved through mixers or laundered through multiple addresses very quickly, often across different blockchains, to obscure the trail. Blockchain analytics firms like Chainalysis or TRM Labs *can* trace these funds, but they primarily work with law enforcement for high-value cases or for compliance for big exchanges, not individual victims. Your best bet is to report it to your local police and any relevant cybercrime units. They might look into it if the amount is significant enough and there's a pattern, but don't hold out too much hope for direct recovery.

Ciara Doyle · Limerick, Irelandanswered 21d ago
47

Ngh, Aisha, that's just terrible news. I'm so sorry you're going through this. It's not your fault, these scammers are getting incredibly sophisticated with their phishing emails; they look so real. It's easy to make a mistake, especially when something seems urgent. Take a deep breath. While direct recovery is incredibly tough, as others have said, there are still steps you should take. File a police report, make sure to include all transaction IDs from Etherscan, wallet addresses, and screenshots of the email if you still have it. Also, report the phishing email itself to Binance (if you haven't) so they can try to block similar ones. It helps to raise awareness, even if it doesn't get your funds back. Stay safe from recovery scammers now, okay? Don't let them trick you further.

Sipho Ndlovu · Cape Town, South Africaanswered 21d ago
18

Ah man, I know that feeling all too well. I got hit by something similar last year, except mine was a fake 'firmware update' for my Ledger. Lost some low five figures, all my ETH and a bit of Solana. The sheer helplessness is just crushing. I reported it everywhere – IC3 here in Singapore, my bank, even tried some of those sketchy 'recovery' services (which are scams themselves, btw, avoid them like the plague). Nothing. The funds were gone within minutes, bounced around a few wallets and then disappeared. It's a harsh lesson, and I still kick myself. The only thing you can do now is learn from it, inform others, and tighten up your security for anything else you have left. Never, ever click links from emails, even if they look legitimate. Always go directly to the official website.

Hao Ong · Singapore, Singaporeanswered 21d ago
12

Honestly, Aisha? It's highly, highly unlikely you're getting that crypto back. Phishing hacks are brutal because the scammer doesn't need to break into anything; you essentially handed them the keys (or permission to use them). Once the assets are off your Trust Wallet and on the blockchain, moving to their address, traditional financial rules don't apply. There's no bank to call and reverse a transaction or credit it back. It's a really harsh reality of unregulated crypto. I get that it sucks, but anyone promising you recovery at this point, especially for an upfront fee, is almost certainly another scammer trying to hit you a second time. Be wary of DMs too, you'll be swamped by 'recovery agents.'

Joshua Jackson · Portland, USAanswered 21d ago
22

My cousin in Ajman got caught in a similar thing, but it was with a fake 'USDT Stablecoin update' notice for her MetaMask. She lost everything, about 4k. She was so ashamed and didn't tell us for ages. What I learned from her situation, and what others are saying here, is that the moment you 'approve' that malicious link, it's like signing away ownership. The funds literally walk out the door. The only possible, and I mean *possible*, path is if the amount was massive, like hundreds of thousands, then maybe law enforcement with blockchain analysis firms could track it and freeze it on an exchange *if* the scammer moves it to a centralized exchange. For smaller amounts, it's just very unlikely. I'm so sorry, habibti.

Layla Al Hashemi · Ajman, UAEanswered 21d ago
34

This whole 'wallet drainer' tactic is rampant, and it's particularly nasty because it often targets people new to crypto or caught off guard. That instant connection from a phishing link gives them total control. One *massive* red flag for everyone reading: *never* click links in emails for crypto-related activities. Always navigate directly to the official website. If you receive an email from Binance, or any other exchange/wallet provider, open a new browser tab and type in the URL yourself. There's no urgency that overrides this security step. Also, enable 2FA on EVERYTHING, and for self-custody wallets, consider a hardware wallet for anything significant. It's a hard lesson, Aisha, but an important one for future digital safety.

Noor Sheikh · Ras Al Khaimah, UAEanswered 21d ago
31

From a technical perspective, what likely happened is that the malicious website performed a permit approval or a signed message on your Trust Wallet through WalletConnect, which you unknowingly authorized. This grants the scammer continuous access to spend specific tokens (like USDT or ETH) from your wallet without needing your explicit approval for each transaction. This is super insidious because it bypasses typical transaction confirmations. Because these are on-chain, irreversible transactions signed by *your* key, there's no technical mechanism for reversal. Even advanced forensic tools like those from TRM Labs can only trace the path of the funds, not recall them. The only chance at recovery is if the scammer eventually sends the funds to an identified, regulated exchange and law enforcement has a warrant to freeze it. This is a very rare outcome for individual small-to-medium value victims. My advice: revoke all approvals immediately on Etherscan for your compromised wallet address, even if it's drained, to prevent any further damage if you accidentally send crypto to it in the future. Better safe than sorry.

Thomas Schmidt · Dresden, Germanyanswered 21d ago
15

Crikey, that's truly awful. I almost fell for a similar trick last year when I got a text about 're-authenticating' my Kraken account. It was a fake URL, obviously, but for a second, I nearly clicked. These guys are pros at making things look legit. Just like everyone else has said, this kind of scam is incredibly difficult to recover from. The best thing you can do now is switch gears from 'how do I get it back?' to 'how do I never let this happen again?'. Two-factor authentication (2FA) is a must, and if you're holding significant amounts, a hardware wallet is non-negotiable. Don't beat yourself up too much, these scams are designed to exploit human psychology and urgency. It happens to the best of us.

Charlie Wright · Sheffield, United Kingdomanswered 21d ago
10

Mate, I'm really sorry to hear this. Went through something similar myself with a fake MetaMask update. Lost about $3k worth of various altcoins last year. The gut punch feeling is real. I actually reached out to a group called Nethertrace after a friend recommended them – they don't do 'recovery' in the sense of guaranteeing your money back, but they do forensic tracing and can help compile a report for police, which makes it easier for them to understand what happened. They were really upfront about the chances being slim, but at least I felt like I was *doing something* concrete. They shared the tracing report with me, showing how quickly my funds moved through about 7 different wallets before hitting a known mixer. It didn't get my money back, but it helped me understand the process and provided some closure. Might be something to consider if you want to know exactly where your funds went, but again, manage expectations.

William Johnson · Darwin, Australiaanswered 21d ago
7

Ugh, another one. This is exactly what happened to my uncle last month, only his was a WhatsApp message link for 'claiming Airdrop'. Lost pretty much his whole life savings too. I took him to the police here in Sydney, and they were sympathetic but pretty much said the hands of law enforcement are tied once it's on the blockchain like that. They open a case number, sure, but the chances are like 0.001%. It's a truly sickening scam. All the advice about not clicking links and using hardware wallets is sound, but it's too late for you now, I hate to say. Just try and compartmentalise it and move forward. You're not alone, unfortunately.

Jack Williams · Sydney, Australiaanswered 21d ago
5

This is a classic phishing attack, unfortunately. The email wasn't from Binance, even if it looked that way. They impersonated a trusted source to get you to give up your wallet access details or, more likely, directly interact with a malicious site that drained your funds. Once crypto leaves a self-custody wallet like Trust Wallet, it's exceptionally difficult to recover. Think of it like cash — once it's gone from your pocket, it's gone. The key here is that you connected your wallet to an unknown, malicious site. The transactions on Etherscan confirm the outflow. Reporting to Binance is good for their awareness, but they genuinely can't reverse these types of external wallet actions.

Eva van Dijk · Utrecht, Netherlandsanswered 21d ago
3

Oh wow, that's absolutely devastating. I'm so sorry you're going through this right now. It's easy to get caught in these scams, they look so real sometimes. Don't beat yourself up too much. The most important thing is that you're safe and still have your wits about you. We all make mistakes, especially when they're designed to trick us. Sending you a lot of support.

Grace Wilson · Canberra, Australiaanswered 21d ago
4

A fake Binance email? That's rough. These scammers are getting bolder. Always, always, *always* go directly to the official website or app. Never click links in emails for financial matters, especially crypto. If you think there's an issue, open your browser, type in binance.com yourself, and log in there. This is how they steal. Don't let this happen to anyone else you know. Educate your friends and family about this specific method. It's a wake-up call for everyone in crypto.

William Martin · Brisbane, Australiaanswered 21d ago
2

Wait — did you actually type your seed phrase into that site or connect your wallet using WalletConnect directly? Because if you just *logged in* using your Trust Wallet credentials (which aren't a thing separate from your seed phrase/private keys), that implies something else. Usually, these scams ask for your seed phrase or try to get you to sign a malicious transaction. It's weird that just 'logging in' drained it. Are you sure you didn't authorize a transaction you didn't understand?

Chloe Kruger · Pretoria, South Africaanswered 21d ago
3

I'm really sorry to hear about your loss. It’s a painful lesson, but one that many in the crypto space learn the hard way. The security of your private keys and seed phrase is paramount. When you interact with a site, even for verification, you're essentially trusting that contract. Scammers exploit that trust. Keep your head up, and if you venture back into crypto, be extra vigilant about never sharing your seed phrase or signing unknown transactions. Reporting it to relevant bodies like IC3 (in the US) or your local cybercrime unit is always recommended, even if recovery is unlikely.

Omar Al Marri · Al Ain, UAEanswered 21d ago
6

This is exactly what happened to me last year. I got that same Binance email. Felt so stupid afterwards. Lost almost 2 ETH. I tried everything, contacted all the exchanges, even some 'recovery' services you see advertised... they're all scams too, btw. The funds are basically untraceable once they hit certain mixers. I still haven't recovered anything and I’m afraid I won’t ever. It's so disheartening. The feeling of helplessness is the worst part. Just wanted to say you're not alone.

Noor Al Falasi · Dubai, UAEanswered 21d ago
3

I understand your distress. It's a harsh reality of digital assets; decentralization means you bear the ultimate responsibility for security. These phishing emails are sophisticated and preying on users' concerns about account security. The best defense moving forward is education and extreme caution. Never click links directly from emails for financial services. Always navigate to the official site by typing the URL yourself. Double-checking the URL is critical. Keep your seed phrase offline and never enter it on any website.

Maryam Al Nahyan · Ras Al Khaimah, UAEanswered 21d ago
2

Hmm, you said you clicked the link and it just 'spun'? That's odd for a direct wallet drain unless it was a MetaMask-style pop-up asking you to approve a transaction. Trust Wallet normally generates a deep link that takes you to the app itself to sign. Did you see any prompts within Trust Wallet to approve anything, even a tiny 'gas fee' transaction? Phishers sometimes trick you with a small approval that's actually permission for them to move your funds. Just trying to understand the technical side.

Noah Bouchard · Halifax, Canadaanswered 21d ago
4

This scenario is unfortunately common. When you're prompted to 'verify' your wallet via a link, it's almost always a malicious site designed to harvest credentials or trick you into signing a malicious transaction. Trust Wallet, like other non-custodial wallets, gives you *control*, but also *responsibility*. If that link led to a site that requested you re-enter your seed phrase or connect your wallet and approve transactions, that's likely how it happened. For future reference, always use official DApp browsers within your wallet or go to known, reputable sites directly. Reporting it to Chainalysis or TRM Labs might help them track the flow, but recovery is unlikely.

Jessica Garcia · Phoenix, USAanswered 21d ago
5

I've been there. Lost a fair bit two years ago to a fake OpenSea link. It felt like the world ended. I spent weeks scrolling through Etherscan, watching my coins go from one wallet to another. It's a horrible feeling. What helped me eventually move on was two things: 1. Accepting it was gone. Fighting that denial was key. 2. Focusing on learning. I went deep into security best practices, hardware wallets, multisig, etc. I'm back in it now, much more cautiously. You will get there too. Nethertrace.co has some decent free guides on wallet security that might help you when you're ready.

Camille Richard · Marseille, Franceanswered 21d ago
4

The key takeaway here is 'external wallet'. Binance, Kraken, etc., have their own security teams and insurance for funds *on their platform*. Once funds are in your self-custody wallet (Trust Wallet, MetaMask, etc.), you are solely responsible. Phishing emails spoofing major exchanges are a primary vector. They create fake login pages or DApps that request wallet interactions. The crucial step you missed was verifying the legitimacy *before* clicking and definitely before connecting your wallet or signing anything. Consider using a hardware wallet in the future and only interacting with DApps through your wallet's built-in browser or a direct connection while verifying the URL.

Noah Taylor · Newcastle, Australiaanswered 21d ago
3

Ugh, another Binance scam email. I swear I get one of those weekly. They are getting SO good at making them look real. Did you get a confirmation email saying the funds were *sent* from your wallet? Sometimes they trick you into signing a 'low gas' transaction that actually allows them to drain *everything*. It’s awful. I've never lost funds myself but my mate lost like $5k last month this way. He’s still gutted.

Sophie Williams · Liverpool, United Kingdomanswered 21d ago
3

Okay, deep breaths. I know it feels like the absolute end of the world, but please try not to blame yourself too much. These scams are designed to be convincing. The fact that you're asking questions and seeking advice now shows you're smart and resilient. The money might be gone, but your knowledge has increased tenfold. Forward-thinking: Always bookmark your exchanges and go directly to them. Never trust an email link, no matter how professional it looks. Verify any supposed 'suspicious activity' by logging in manually. I hope you can find some peace with this.

Jacob Gagne · Calgary, Canadaanswered 21d ago
4

This is so incredibly sad to read. It's a terrible feeling when you realize you’ve been tricked, and losing your crypto makes it so much worse. I had a similar scare last year with a fake ZG.com email – luckily I didn't lose funds but it shook me badly. I learned then that the only safe way to interact with any crypto service is to go directly to their official site through a bookmark or by typing the URL yourself. Never click links in emails or messages. It’s a hard lesson. Look into resources like Nethertrace.co; they have some good info on phishing red flags.

Amelia Thompson · Canberra, Australiaanswered 21d ago
3

The feeling of dread when you see those transactions… I know it well. My first time connecting my wallet to a DApp, I accidentally approved a malicious contract that almost emptied me. Luckily, it was only a small amount, and I managed to revoke permissions quickly enough. The key is immediate action if you suspect something. But for you, it sounds like the funds are already gone through standard transactions. Reporting to law enforcement is your best bet for an official record, even if recovery is a long shot. Don't fall for any recovery scams that promise guaranteed returns.

Louise David · Nice, Franceanswered 21d ago
3

Binance phishing emails are rampant. It’s painful. Did the link lead you to a site that asked you to enter your seed phrase? Or did it prompt you to connect your wallet using WalletConnect? If it was the latter, you might have signed a malicious transaction without realizing it. Many scam sites present a fake 'login' that's actually a transaction request. The best practice is to only ever use the DApp browser *within* Trust Wallet or on a known, trusted site like Uniswap, PancakeSwap, etc. Never click external links.

Joshua Pillay · Port Elizabeth, South Africaanswered 21d ago
4

This is precisely how many people lose funds. Scammers create very convincing fake emails, often with urgent language to pressure you. They know people are worried about account security. The link leads to a fake website that mimics the real one, and when you 'log in' or 'verify,' you’re either giving away your private keys (seed phrase) or signing malicious transactions. Once funds are moved from a self-custody wallet, the blockchain is irreversible. The best defense is awareness: question everything, verify URLs, and never enter your seed phrase online.

Layla Iqbal · Ras Al Khaimah, UAEanswered 21d ago
3

Oh no, that’s terrible. I am so, so sorry. That sinking feeling is the worst. They really do make those emails look legitimate, don’t they? I got one from Kraken last month that made me pause for a second. My husband told me, 'Never click it, just go to the app.' That’s the golden rule, I guess. Always go to the official app or website. Seriously, don't beat yourself up. Learn from it and put up those defenses for next time.

Emma Khumalo · Johannesburg, South Africaanswered 21d ago
3

This is horrible. I've also been targeted by fake emails. The key thing is that Binance, like most exchanges, will *not* ask you to click a link to verify your account for security reasons. They will tell you to log in directly to your account on their platform. If you suspect anything, always go to the official website yourself. The funds are likely gone, but please, please be careful with any messages you receive going forward. Tracking these funds is incredibly difficult.

Olivia MacDonald · Montreal, Canadaanswered 21d ago
4

This hurts to read because it's so familiar. That knot in your stomach when you see the zeros... I lost a good chunk of change last year to a similar scam, except mine was disguised as a lottery win notification. They had me click a link to 'claim my prize'. It looked so real. I've learned the hard way that any email asking you to interact with your wallet is 99.9% a scam. I now use a hardware wallet and double-check everything thrice. Reporting to IC3 is a good step, but don't expect miracles. You are not alone in this.

Ahmed Al Nahyan · Abu Dhabi, UAEanswered 20d ago
5

Oh no, that's an absolutely brutal lesson. That email sounds like a classic phishing attempt. The key here is that they *never* ask you to log in via email, especially for something as sensitive as your wallet. Always go directly to the official Binance site yourself, don't click emails. Sadly, once crypto is moved out of a hot wallet like Trust Wallet, especially to a wallet controlled by the scammer, recovery is extremely difficult, bordering on impossible. The blockchain is irreversible. Your funds are likely gone. There are services that *claim* recovery, but be *super* wary – many are scams themselves, like that Funds Recovery Group. tbh, your best bet is to change all passwords, enable 2FA everywhere else, and consider a hardware wallet for future safekeeping. I'd also report this on chain analysis sites, not just to Binance.

Grace Botha · Cape Town, South Africaanswered 20d ago
4

Man, I feel this so hard. I got hit with something similar about 8 months ago, lost a good chunk of my SOL. It was a fake Ledger update email. Clicked, entered my recovery phrase (idiot, I know, NEVER do that). Woke up to an empty wallet. It's soul-crushing. Binance is right, they can't claw it back once it's out. The *only* thing I found that helped, psychologically more than anything, was realizing how common this is. You’re not alone in this. Keep reporting it to tracing firms like Chainalysis or TRM Labs – they track these wallets. It won't get your money back, but it helps identify the bad guys.

Levi van Dijk · Utrecht, Netherlandsanswered 20d ago
3

This is exactly how the scammers work. They impersonate legitimate exchanges or services and wait for people to click. The Binance email? Phishing 101. Even if it LOOKS perfect, always verify the URL yourself. Type 'binance.com' directly into your browser. NEVER click links in emails like that. The funds are likely lost, sadly. The speed at which they move it means it's going through mixers immediately. The best advice anyone can give you now is vigilance. Report it to IC3.gov in the US, or the equivalent cybercrime unit in your country. Take this as a very expensive lesson in security.

Andreas Klein · Dresden, Germanyanswered 20d ago
4

Hmm, clicked a link, logged into Trust Wallet... that doesn't sound right. Trust Wallet doesn't use traditional logins like that for wallet interactions. Usually, it's a sign or approve transaction prompt *within* the app or via a deep link that doesn't ask for your main password/seed phrase via a website. Are you absolutely sure you didn't accidentally input your seed phrase on that fake site? Because if you did, that's game over. If not, maybe there's a *tiny* chance it was a different kind of exploit, but still highly unlikely. Etherscan is great to see the trail, but it won't help you get it back.

Jonathan Tan · Singapore, Singaporeanswered 20d ago
5

I'm so sorry this happened to you. Reading this brought back my own horrible experience last year. Fell for a fake NFT minting site. Lost about half my holdings. It feels like such a personal failure, doesn't it? Like you're stupid. But these scammers are masters of deception. They build these fake sites so well. Binance is correct; external wallet transactions are final. There's no 'undo' button. My best advice? Take a break from crypto for a bit. Let it sink in. Then, when you come back, get a hardware wallet. Seriously. Store minimal amounts in hot wallets like Trust Wallet. Keep the bulk offline.

Lucas Martin · Hobart, Australiaanswered 20d ago
4

Ugh, the Binance email trap. Been there. For me, it was a fake Kraken one. Looked *so* real. The 'suspicious activity' alert always gets you. I clicked, put in my username and password. Then it asked for my 2FA code. Next thing I know, my account is frozen and funds are being moved. Kraken support was useless too, basically said 'tough luck'. It took me MONTHS to get back on my feet. The key lesson learned: Never, EVER enter credentials or 2FA codes on a page you reached through an email link. Always type the URL yourself. Hope you can rebuild.

Lucas Mulder · Breda, Netherlandsanswered 20d ago
6

This is heartbreaking. I had a similar scare a few months ago. It wasn't my main wallet, thankfully, just a small amount I was experimenting with. Got a text message about a supposed NFT airdrop, link looked legit. I clicked it and it asked to connect my wallet. I got a weird feeling, though, and *before* I approved anything, I backed out and checked the actual project website on a separate tab. Turns out, the real site had a big warning about this phishing link. So, my tip: If anything ever asks you to connect your wallet or sign a transaction, always open a new tab and navigate directly to the official site to double-check the source or any alerts. Glad I caught mine, but my heart goes out to you.

Emily Johnson · Minneapolis, USAanswered 20d ago
3

Wait, you logged *into* Trust Wallet via a website link from an email? That's not how Trust Wallet works, is it? Trust Wallet is a self-custodial wallet. You connect it to dApps, but you don't 'log in' to Trust Wallet itself from a website. You connect *your* wallet *to* a website. If that website asked for your username/password for Trust Wallet, it was fake. If it asked for your seed phrase, it was a scam. Binance is useless here. The transactions are on Etherscan, meaning they're confirmed. It's gone. File a police report anyway, and report it to the exchanges that the funds might have been sent to, if you can trace them.

Rachel Brown · San Antonio, USAanswered 20d ago
4

Oh, OP, I'm so sorry this happened. It's a truly awful feeling. I know someone who lost a significant amount in a similar way with a fake ZG.com email. They were devastated. Don't beat yourself up too much; these scammers are incredibly sophisticated. The best thing you can do now is to learn from it and protect yourself going forward. Always double-check URLs. Use a hardware wallet for anything substantial. And maybe look into reporting the wallet addresses involved to TRM Labs or Chainalysis. They track this stuff, and while it won't get your funds back, it contributes to the ecosystem's security.

Noor Khan · Dubai, UAEanswered 20d ago
3

Did the email ask for your seed phrase? Because that's the ultimate red flag. If you gave up your seed phrase on that page, then yes, technically *you* gave them the keys to your kingdom. No getting around that. Binance can't help because the transaction wasn't *on* Binance, it was initiated from your Trust Wallet. These types of scams are common. Just saw a post about someone losing funds after connecting to a fake DeFi site. They claimed they used a service called Nethertrace and actually got some back, though. Might be worth a look, but be careful.

Brian Hall · Los Angeles, USAanswered 20d ago
5

What a nightmare. I experienced something similar a while back, different story though – I clicked a dodgy link in a Telegram group that supposedly offered 'free BNB'. It prompted me to connect my MetaMask (I wasn't using Trust Wallet then). I connected, and it immediately drained my wallet. My mistake was approving a transaction I didn't fully understand. The lesson? Always scrutinize the transaction details *in* your wallet app before signing. It'll tell you what token you're sending, to where, and how much. If it looks weird or unintended, reject it. It’s too late for you now, but for others reading, that's the critical step.

Aoife Smith · Cork, Irelandanswered 20d ago
4

This is a tough situation, and I'm really sorry you're going through it. The email phishing tactic is incredibly common. The key takeaway for you and anyone reading: *never* click links in emails to access financial services. Always type the URL directly into your browser. For Binance, it's binance.com. For your bank, it's your bank's official site. The funds themselves are likely lost forever due to the nature of blockchain transactions. However, you should still report it to your local cybercrime unit. They might not recover funds, but they do track these activities, and reporting helps them build cases. And *never* give out your seed phrase or private keys.

Amelia Clark · Liverpool, United Kingdomanswered 20d ago
5

Oh OP, I feel your pain. I lost a fair bit a year ago to a fake NFT marketplace site I found through Twitter. The site looked polished, but it was a trap. Asked me to connect my wallet. I did, and then my assets started moving. It was a blur. Binance and Trust Wallet support were no help, just like you said. It was a brutal financial and emotional hit. For anyone reading this: A hardware wallet is non-negotiable if you hold any significant amount. Keep your Trust Wallet for small, everyday stuff only. And for recovery, I know people who've had success with Nethertrace (nethertrace.co), but tread very carefully, as many recovery outfits are also scams.

Aisha Khan · Dubai, UAEanswered 20d ago
3

That Binance email is a classic social engineering attack. They play on your fear of losing your account. The link took you to a fake login page designed to steal your credentials or, worse, prompt you to approve malicious transactions that drain your wallet. Trust Wallet itself is secure, but the connection you allowed it to make via that fake site was compromised. Binance can't help because it wasn't their platform that was breached, but your wallet. This is precisely why regulation is discussed. It's unlikely you'll recover the funds. Report it to the FBI's IC3.gov portal if you're in the US.

Noah Cote · Victoria, Canadaanswered 20d ago
4

I'm so, so sorry. This is a devastating experience. I went through something similar with a fake ICO website that seemed legit. Lost £5k. It felt like a punch to the gut. You feel so foolish, but honestly, these scams are designed to fool anyone. The critical mistake was clicking the link and interacting with that site. Trust Wallet, by design, doesn’t have a 'login' via email. That should have been your first clue. The transactions are irreversible. Reporting to Binance is good, but they can't do anything. Focus on securing your other accounts and learning from this expensive lesson. Set up 2FA on everything non-crypto related.

Fatima Al Marri · Al Ain, UAEanswered 20d ago
3

Heartbreaking. This sounds exactly like the type of scam that targets crypto users. The fake email is a lure. Once you clicked and 'logged in' (which technically you didn't do *to* Trust Wallet, but rather connected your wallet *to* a malicious site), they had permission to drain it. Binance is right – they have no control over external wallet actions. The crypto is gone. The sad reality is that with decentralized systems like this, once validated on the blockchain, the transaction is final. Your best course of action is to report this to local law enforcement and possibly agencies that track crypto crime, like Chainalysis, though they primarily work with institutions.

Layla Al Mansoori · Sharjah, UAEanswered 20d ago
4

This is precisely the kind of attack I warn my family about constantly. That Binance email is a perfect example of a phishing attempt. They craft these emails to look identical to the real thing, including logos and sender details sometimes. The crucial error was clicking the link and entering *any* information. Trust Wallet is a self-custodial wallet, meaning *you* hold the keys. If a website tricks you into signing a transaction or revealing information, the responsibility falls on the user's interaction. It's gone. There's no undo. The only practical advice is never click links from emails for financial services. Period. Always go to the site directly.

Hannah Botha · Johannesburg, South Africaanswered 20d ago
3

Wow, that's rough. I've heard stories like this from friends who fell for fake Kraken phishing emails. The key is that you never log into your hot wallet (like Trust Wallet) FROM AN EMAIL LINK. You log into exchanges/platforms directly. If Trust Wallet had a login mechanism on a website, it would be a different story, but it doesn't work that way. The coins are gone. On the plus side, lots of people are getting scammed. Maybe we can crowd-source info. Does anyone know if services like Nethertrace (nethertrace.co) are legit for tracking? Seems like a long shot but desperate times...

Hassan Ahmed · Al Ain, UAEanswered 20d ago
4

I'm terribly sorry to hear this. This exact scenario is a common attack vector. The email looked official, creating a sense of urgency, and directed you to a fake portal. When you connected Trust Wallet, you were essentially giving the scammer permission to move assets. Binance cannot help because the transfer originated from your wallet, not their exchange infrastructure. The transactions on Etherscan confirm the movement. The funds are almost certainly irretrievable. Moving forward, consider using a hardware wallet for significant holdings and never interact with links from unsolicited emails.

Rachel Lau · Singapore, Singaporeanswered 20d ago
3

Ugh, that sounds horrendous. The fake email is the oldest trick in the book yet still unbelievably effective. Many people are still falling for it. The fact that Binance can't do anything is standard; they only control activity *on* their platform. Your Trust Wallet is your responsibility. Once you authorize a transaction, it's final. I've seen people try to use recovery services advertised online, but be EXTREMELY careful, as many are just another layer of scam, like that Funds Recovery Group. Your crypto is most likely gone forever. Learn from this; use hardware wallets.

Oliver Wood · Birmingham, United Kingdomanswered 20d ago

Your answer

You'll be asked to sign in to post.