Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
There is no verified evidence in the sources cited here that Trust Wallet has announced a wallet migration or that a documented fake-migration campaign specifically targeted its users. A similar scam was reported against Coinbase in March 2025: attackers supplied a recovery phrase they already controlled and urged recipients to move funds into the resulting wallet. Trust Wallet users should watch for the same tactic—but should not mistake the reported Coinbase incident for a confirmed Trust Wallet campaign.
The safest rule is simple: never use a recovery phrase sent by email, and never transfer funds because an unsolicited message says migration is mandatory. Trust Wallet says it will not ask for your 12-word secret phrase or require you to verify your self-custody wallet.
What is verified—and what is not
BleepingComputer reported on March 14, 2025, that phishing emails impersonated Coinbase and pushed a fake wallet migration. The material cited here does not establish that the same campaign targeted Trust Wallet users. Treat a message using Trust Wallet branding as suspicious unless you can verify the claim through Trust Wallet’s official app, website, or support channels—not through links, phone numbers, or addresses in the email.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Trust Wallet describes its product as self-custodial: it does not hold users’ private keys. Its anti-scam guidance says support will not ask for a 12-word secret phrase or require wallet verification, and that Trust Wallet cannot suspend a user’s self-custody wallet. An email threatening suspension unless you migrate, validate a phrase, or send funds is a major warning sign.
#1 Best Overall
- Proven security at scale: Over 9 years and millions of cards issued with no known remote hacks, while military‑grade EAL6+ security keeps your private keys locked inside the chip. Your cryptocurrencies stay strongly protected from online attackers.
- Tap once to manage your entire crypto wallet across 90 blockchains - no USB cables or Bluetooth, no batteries, no setup. Access 14,100+ coins & tokens, DeFi, NFTs, and staking instantly from your phone
- Smart backup: Use your second Tangem Wallet as your Backup keys with end‑to‑end encryption; no more papers, pictures. If one card is lost, the remaining can still restore full access, with an optional seed phrase available for advanced users.
- Engineered to last up to 25 years: Waterproof (IP69K), shockproof and tested for extreme temperatures from −25°C to 50°C. A durable cold wallet with long‑term protection and independently audited security.
- Trusted by 6 million users worldwide - buy, sell, swap, stake, and spend cryptocurrency directly. The secure offline storage wallet designed for how people actually use crypto wallets
Not every legitimate crypto change is a scam. Wallet software, networks, and address formats can change, and Trust Wallet has published chain-specific updates—for example, an explanation of TON address-format changes. That is different from an unsolicited demand to enter a phrase supplied by someone else or transfer assets to an unknown address.
How the fake migration tactic works
The reported Coinbase campaign used a less familiar twist on seed-phrase theft. Instead of asking directly for the recipient’s existing phrase, the email provided one controlled by the attackers and told the recipient to create or restore a wallet with it, then move assets there. Because the attackers already knew the phrase, they could access the same wallet and take assets deposited into it.
- An email impersonates a known crypto company and claims a migration is required.
- It supplies a recovery phrase or directs the recipient to import one.
- The recipient creates or restores a wallet using that phrase.
- The recipient transfers assets into the wallet, believing it is theirs.
- The attackers use their copy of the phrase to access the wallet and move the assets.
That is why “I didn’t give them my phrase; they gave it to me” is not a safety test. A recovery phrase is a master credential. Anyone who knows it can generally recreate and control the wallet. Generate a new wallet only within official wallet software or a hardware wallet, and keep the new phrase private.
Rank #2
- Proven security at scale: Over 9 years and millions of cards issued with no known remote hacks, while military‑grade EAL6+ security keeps your private keys locked inside the chip. Your cryptocurrencies stay strongly protected from online attackers.
- Tap once to manage your entire crypto wallet across 90 blockchains - no USB cables or Bluetooth, no batteries, no setup. Access 14,100+ coins & tokens, DeFi, NFTs, and staking instantly from your phone
- Smart backup: Use your second Tangem Wallet as your Backup keys with end‑to‑end encryption; no more papers, pictures. If one card is lost, the remaining can still restore full access, with an optional seed phrase available for advanced users.
- Engineered to last up to 25 years: Waterproof (IP69K), shockproof and tested for extreme temperatures from −25°C to 50°C. A durable cold wallet with long‑term protection and independently audited security.
- Trusted by 6 million users worldwide (4.9 App Store, 4.8 Google Play) - buy, sell, swap, stake, and spend cryptocurrency directly. The secure offline storage wallet designed for how people actually use crypto wallets
Red flags to look for
- “Mandatory wallet migration,” “wallet synchronization,” or “validation” language.
- Threats that your wallet will be suspended, frozen, or restricted unless you act quickly.
- A request to import a phrase, disclose your existing phrase, or send assets to a “safe” or “migration” address.
- Urgency such as a 24-hour deadline, or claims about regulators, courts, or legal action requiring a transfer.
- A request to contact support through an email address, phone number, social account, or website supplied in the message.
- An attachment or app download offered as part of the migration.
Judge the requested action, not just the branding. A polished message, familiar logo, or plausible sender name does not prove it is genuine. BleepingComputer reported that the Coinbase phishing emails used legitimate Coinbase Wallet links and appeared to pass SPF, DKIM, and DMARC email-authentication checks. Those checks concern aspects of message delivery; they do not establish that the email’s instructions are legitimate. A real app link does not make an attacker-controlled phrase safe.
Verify a claim without following the email
- Do not click links, open attachments, reply, or call numbers in the message.
- Open the Trust Wallet app directly, or type the official website address yourself.
- Check Trust Wallet’s official announcements, security information, and support site. Its official press resources link to product and company information.
- If you need help, navigate to Trust Wallet support independently. Never give support—or anyone else—your recovery phrase or private key.
- Report the email as phishing or spam, then delete it. Do not publish any phrase shown in the message, even when asking others to investigate it.
Keep the full sender and reply-to addresses, subject line, headers, screenshots, and copied links as evidence if you need to report the message. Do not open copied links to inspect them.
What to do based on what you did
If you only opened the email
If you did not click, open an attachment, enter information, install software, sign a transaction, or transfer funds, the immediate wallet risk is generally lower. Do not reply or interact further. Report and delete the message, then check your wallet only through the official app or a site you entered yourself.
Rank #3
- Unparalleled Security: Protect your assets NDA-free EAL 6+ Secure Element, offering robust defense and complete transparency
- Simple & Secure Interface: Manage your digital assets easily with a clear OLED screen for secure on-device confirmations
- Supports 1000s of Coins & Tokens: Securely handle thousands of assets, including Bitcoin, Ethereum, and more, all in one wallet
- Effortless Asset Management: Monitor and transact seamlessly with Trezor Suite, our intuitive desktop and mobile app
- Enhanced Backup Solution: Rest assured with Multi-share Backup, eliminating single points of failure for secure cold wallet recovery
If you clicked a link but entered nothing
Close the page and do not connect your wallet, sign a message or transaction, download anything, or enter credentials. If you downloaded or installed an app or browser extension, stop using it and remove it; use a trusted device and official wallet software to check your assets. Clicking alone is not the same as disclosing a recovery phrase, but what you did on the page matters. If you entered a password, phrase, or payment information, follow the relevant steps below.
If you entered an account password
Change that password using the service’s official app or website—not the email link—and change it anywhere else you reused it. Enable available account protections and review recent sign-ins. A wallet-app password change does not protect a wallet whose recovery phrase has been exposed.
If you entered your existing recovery phrase
Assume that wallet is compromised. Reinstalling Trust Wallet, deleting the email, or changing an app password does not invalidate a phrase an attacker has copied.
Rank #4
- Secure element (EAL6+ certified) and passphrase protection for bullet-proof physical security
- Two-button pad device interface, designed for user-friendly operation
- Bright OLED display for easy & secure hands-on verification
- PIN & passphrase enabled for on-device protection
- Fully open-source design for transparent security
- Stop using the exposed wallet for new deposits.
- Using official wallet software or a hardware wallet, create a completely new wallet and generate a new phrase privately. Do not reuse any phrase shown in the email or used by the exposed wallet.
- Move remaining assets to the new wallet as soon as you can do so safely. You may need native currency on each network to pay transaction fees; do not send funds to an address supplied by the message or a supposed support agent.
- Review connected decentralized applications and token approvals. If you suspect a malicious approval or transaction, stop signing from the affected wallet and review what was authorized. Disconnecting a site does not necessarily revoke an on-chain token approval.
- Save wallet addresses, transaction hashes, timestamps, and screenshots. Contact Trust Wallet through its official support route, but never provide the phrase or private key.
Trust Wallet’s recovery-phrase guidance says that someone with the phrase can access the wallet and recommends creating a new wallet and moving remaining assets. A new app password or security scanner cannot make the exposed phrase secret again.
If you used the phrase supplied in the email
Do not deposit or transfer funds into that wallet. The sender already knows the phrase, so changing the app password or reinstalling the wallet does not secure it. If you already placed your own assets there, treat the wallet as compromised and move any assets that remain to a newly generated wallet, taking network fees and transaction safety into account.
Recommended Free Tools
If you signed a suspicious transaction or approved a DApp
A signed transaction or token approval can put assets at risk even if you never disclosed your recovery phrase. Stop signing from the affected wallet until you understand what you approved. Review the transaction and any token approvals using a reputable tool reached independently, and revoke suspicious approvals where possible. Disconnecting a DApp from the wallet does not necessarily revoke an on-chain approval. If your phrase or private key was also exposed, approval revocation is not enough: move remaining assets to a new wallet.
Best Value
- Simple, Secure Bitcoin Storage for Anyone: Create a safe, offline place to hold Bitcoin without needing an app, account, seed phrase, or technical setup. Perfect for beginners, casual users, and anyone who wants a stress-free cold storage option.
- Easy to Load with Bitcoin in Seconds: Each card includes a unique deposit address so you can add Bitcoin quickly from any exchange or wallet. Designed to make storing and gifting Bitcoin intuitive, even for people who are new to crypto.
- Keeps Your Bitcoin Offline and Protected: Funds are stored in cold storage, keeping them completely offline and isolated from online threats. A durable, printed wallet format ensures long-term security whether you store it at home, in a safe, or on the go.
- Great for Gifting Bitcoin to Family & Friends: A fun, thoughtful way to introduce others to Bitcoin. Perfect as a birthday gift, stocking stuffer, party favor, graduation present, or starter wallet for someone learning how digital assets work.
- High-Quality Card Built for Everyday Use: Printed on premium materials and sealed for security and durability. Slim, credit-card style design fits easily into a wallet, gifting envelope, or safe deposit box for long-term use and convenience.
If you transferred funds
Check the wallet address and relevant transaction on the appropriate blockchain explorer. If assets remain in a wallet whose phrase an attacker knows, move them to a new wallet generated privately by you. If the funds have already been moved, preserve the transaction hashes, destination addresses, token or asset details, timestamps, and screenshots. Report the incident to Trust Wallet through its official support channel and to any exchange or platform involved. A confirmed blockchain transfer may not be reversible; do not trust anyone promising guaranteed recovery for an upfront fee or asking for your phrase.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.A separate Trust Wallet incident is not proof of a migration-email campaign
Trust Wallet separately reported a browser-extension incident involving version 2.68 in December 2025. In its incident update, the company said the affected scope was limited to users who opened and logged into that extension version during December 24–26, 2025; it said mobile-app users were not affected by that incident. Trust Wallet reported 2,520 affected wallet addresses, approximately $8.5 million in associated assets, and a voluntary reimbursement plan. This separate, later incident does not verify that a fake-migration email targeted Trust Wallet users. If you used the specified extension version during that period, consult Trust Wallet’s official incident update for details.
Quick Recap
Keep these rules in mind
- Never enter a recovery phrase into an email form, website, or support chat.
- Never use a recovery phrase supplied by another person or organization.
- Never transfer assets because an unsolicited message demands a migration.
- Never trust a support account that contacts you first and asks for your phrase, private key, or a payment to recover funds.
- Never post an exposed phrase while asking for help. Treat it as compromised and move remaining assets to a new wallet.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minute

