
TRON Multisig Scam · What to Do When Your Wallet Has Been Hijacked
This is one of the rare pieces in this museum with no happy ending, so let me put the cruellest sentence at the top: once a wallet has been maliciously multisigged, it is essentially unrecoverable — not "difficult," but very nearly impossible to get back. The weight of this piece therefore sits not on how to rescue it, but on how not to be caught in the first place, and on how to cut your losses and avoid being farmed a second time if you have been. If you are searching for what to do when your wallet has been multisigged, take a breath and read on.
After a wallet has been maliciously multisigged it is almost impossible to undo; the consensus in the industry is that control is unrecoverable in 99% of cases. There are only three correct moves: (1) stop sending any coin at all to that address immediately, including network fees; (2) move whatever assets are still moveable in your other, unaffected wallets to a safe address as fast as you can; (3) abandon the multisigged address, create a new wallet and keep the seed phrase properly. Do not believe anybody who offers to "remove the multisig for a fee" — that is the second harvest.
I. What multisig is, and how it steals
Multi-signature is not a bad thing in itself. Its intent is that an account requires several people to sign together before money moves, much like a company vault needing two keys turned at once — commonly used for team treasuries and institutional custody, a legitimate feature that raises security. What the scam exploits is that this feature, as implemented on TRON, can be turned around and used against you.
The crux is TRON's account permission model: on TRON, who can move the money in an account is not determined simply by who holds the private key, but by the account's permission configuration — every signer carries a weight, and a transfer requires enough weight to meet a threshold. Under normal conditions your own key carries enough weight and you can transfer on your own. But if an attacker obtains your private key (or tricks you into signing a malicious transaction), they can modify that configuration: add themselves as a signer, drop your own weight to 0, and set the threshold to 1, so that their signature alone suffices. The moment that change lands, the account becomes their multisig wallet — the private key is still in your hand, but its weight is no longer enough, your signature cannot meet the threshold, and the money will never move again.
Which is the most counterintuitive part of the whole scam: you assumed that holding the private key meant you were safe, but on TRON, once the permissions have been changed, whether the key is in your hands has stopped mattering.
II. The two most common plays
Play one · The honeypot: free coins are the most expensive
This is the one with the widest reach. The scammer will "accidentally" leak the private key or seed phrase of a wallet in all sorts of places — comment sections, group chats, even direct messages — usually with a line along the lines of "I can't work out how to withdraw, whoever helps me get the USDT out can keep half." You import it, and sure enough, there is a pile of USDT sitting in the address.
You go to move that USDT, and find the account has no TRX to pay the network fee. So you top the address up with a little TRX — and that one step is where you lose. The account was set to multisig long ago; the USDT will not move at all, and the TRX you sent in gets swept out within seconds by a collection bot the scammer has already deployed. What you were reaching for was USDT you could see but never take. What you paid was real TRX. This play works on exactly one thing: the flutter you feel when something looks like free money.
Play two · Signature phishing: your own wallet taken from you
This one is more dangerous, because the victim is the wallet you use every day. The scammer builds a website that looks perfectly ordinary — discounted gift cards, phone top-ups, an airdrop claim, a fake trading page — and when you "confirm" or "pay" on it, what you are actually signing is a malicious transaction that calls a permission change. You believe you are just making a payment; the signature goes through, and the permissions on your own wallet have been rewritten: the scammer is added as a multisig party, your weight is zeroed. From then on you cannot move your own money either.
Another variant is being steered into installing a fake wallet app (an imitation of imToken, TP and others); you enter the seed phrase, it leaks directly, and the scammer changes the permissions remotely. So remember this: anything that asks you to sign on an unfamiliar site, to download a wallet app from an unofficial channel, or to type in your seed phrase, should be treated as phishing.
III. Can it be undone once it has happened?
Bluntly: almost never. On this point wallet providers such as SafePal, CoinEx and imToken and the security researchers are closely aligned — once the attacker has completed the permission change and dropped your weight below what is required, you have no unilateral way to change the permissions back, because changing permissions is itself now an operation that has to meet the new signing threshold, and that threshold is in the scammer's hands. The phrasing used in the industry is "essentially unrecoverable" and "control cannot be regained in 99% of cases."
Which is why the weight of this piece is on prevention rather than rescue. Unlike a single phished approval (which can still be revoked with a tool such as Revoke.cash), a multisig takeover rewrites the ownership structure of the account outright; it is not as simple as cancelling an allowance. Do not pin your hopes on there being some way to unlock it — there is not. Accepting that is what frees your attention for the parts that can actually save you: cutting losses, and prevention.
IV. Prevention that actually works
- Guard the seed phrase and the private key, and never type them anywhere outside your own wallet app. This is the root. In 99% of multisig scams the precondition is either that the attacker obtained your private key or that you signed a malicious transaction. A seed phrase is written down once, by you, when the official app asks you to during wallet creation or recovery — anything else asking you to enter it is fraud, without exception.
- Never import a private key or seed phrase handed to you by a stranger. There is no such thing as helping someone withdraw for half the proceeds; that address is a trap laid for you. When you see free coins, ask yourself one question first: why did this fall to me?
- Do not sign on unfamiliar sites. Discounted gift cards, airdrop claims, unexplained top-up pages — these are where signature phishing concentrates. Look at what you are actually authorising before you sign; if you cannot read it, do not sign it.
- Download wallet apps only from official channels. Counterfeit wallets are the worst source of leaked seed phrases; verify the official domain and the official developer in the app store.
- Check your account permissions periodically. In your TRON wallet, look at the account permissions (Owner / Active) and confirm that you are the only party, with normal weight and threshold. An unfamiliar signer in that list means it has already happened.
- For large, long-term holdings, consider a hardware wallet or simply custody at a large compliant venue. Keep everyday small amounts separate from long-term large amounts; do not let a single hot wallet hold everything you own.
V. What to do if it has already happened to you
If you have already found your wallet multisigged — the USDT will not move, there is an unfamiliar signer in the permissions — work through this in order:
- Stop immediately. Do not send any more coin to that address, and above all do not top up more TRX "to see whether it will transfer now" — that is simply continuing to feed the scammer.
- Rescue your other wallets. If you suspect the seed phrase has leaked, then every address derived from that phrase — across different chains and different accounts — may already be exposed. Move whatever is still moveable at those addresses to a safe wallet that is newly generated, with a seed phrase that has never been entered anywhere.
- Abandon the multisigged address. It is no longer yours. Stop using it.
- Preserve evidence and consider filing a report. Keep the screenshots, the transaction IDs, the counterparty's accounts. Where a significant sum is involved, go through the reporting channels where you live.
- Watch for secondary fraud. This is the most important line here — after the event a crowd of "technicians / lawyers / hackers" will appear, claiming they can remove the multisig or recover your assets. The moment they want you to pay first, top up first, or post a deposit first, it is the second scam. As already said: a multisig takeover is essentially unrecoverable, and nobody can "unlock it for a fee."
The core cost of a self-custodied wallet is that you are the bank — safety rests 100% on your ability to keep a seed phrase and to not sign a phishing transaction. This whole multisig scam works precisely because it attacks that most fragile human link. "Not your keys, not your coins" is true, but so is the reverse: your keys, your entire responsibility.
If you will admit that you are not good at managing private keys and cannot always tell which signatures are safe, then keeping your everyday and long-term holdings in custody at a transparent, compliant centralised exchange genuinely removes the entire attack surface of leaked seed phrases and multisig takeovers — because you are no longer holding that string of characters yourself. The cost is that you now have to trust that venue, which is why the earlier files in this archive spend so long on how to pick one. This is not to say custody beats self-custody outright; it is to say that for someone with no confidence in managing keys, forcing self-custody may carry the greater risk. For the selection criteria, see Lesson Three; if you do choose custody, choose a large venue with self-verifiable reserve attestations published on a regular cadence and an insurance fund behind it.
- SafePal, "TRON multi-signature fraud: what it is and how to guard against it."
- CoinEx Wallet, "Holding the private key means you can move the assets? Beware the TRON multisig trap."
- imToken monthly security reports, warnings on the TRX multi-signature scam and the unfreezing-memo script.
- BlockBeats, "What is really behind the multisig scam targeting TRON wallets, and how can users protect their assets?"
- TRON official documentation on account permissions (Owner / Active Permission), weights and thresholds.
If you spot a factual error in this piece, please write to [email protected] — I will issue a public correction and credit you by name. The full correction history lives at /corrections.html. Editorial standards are at /editorial.html.