The incident in one minute
- A Thai woman said nearly THB 17 million in her husband's savings was transferred out of Bitget Wallet on August 25, 2026.
- The phone remained with its owner, but physical possession of a phone does not guarantee that its seed phrase or private key is still secure.
- The victim said the case had been reported to Thailand's cyber police and other relevant parties.
- No technical investigation has yet established whether the cause involved Bitget Wallet, the phone, another application, or a different point of compromise.
- Anyone facing a similar incident should preserve evidence, move any remaining assets from a trusted device, and contact the cyber police without delay.
A Thai woman has reported that nearly THB 17 million in her husband's savings was transferred out of Bitget Wallet even though the phone never left its owner. The case has raised an obvious question among crypto users: how could someone move the funds without stealing the device?
Keeping the phone in your hand is not the same as keeping the wallet's signing keys secure. If a seed phrase or private key has been exposed, or if a dangerous smart-contract approval remains active, an attacker may be able to control the assets from a completely different device.
The incident is still under investigation. There is currently no basis for concluding that the cause was a flaw in Bitget Wallet, the victim's phone, another application, or a particular user action.
What happened to the nearly THB 17 million?
According to an account shared on social media, the operator of the “Khawtoom ดูแลประกันคนไทย” page was told that the husband's savings had been transferred out of Bitget Wallet during the evening of August 25, 2026. The total value was reported to be close to THB 17 million.
The victim said the phone remained in the owner's possession. After discovering the loss, the parties reviewed the on-chain transactions and saw the assets being forwarded to several wallets. A police report was subsequently filed, Thailand's cyber police were contacted, and relevant companies were asked to assist with tracing the movement of the assets.
The post also mentioned concerns about unusual behaviour on the phone and noted that an electric-vehicle charging application had previously been installed. The poster stressed that nobody yet knows whether the application had any connection to the loss. At this stage, that detail is only a question and should not be used to accuse any developer or service provider.
What is known, and what remains unconfirmed?
It is important to separate reported facts from possible explanations. An unauthorised transaction alone does not identify the system or action that made it possible.
| Issue | Current status |
|---|---|
| Nearly THB 17 million was reportedly transferred out | This comes from the victim's account in a public video |
| The phone remained with its owner | Reported by the victim |
| The blockchain transactions were followed | The victim said the assets were seen moving to additional wallets |
| The phone was compromised | No technical finding has confirmed this |
| An EV charging application caused the incident | This remains speculation |
| Bitget Wallet contained a vulnerability | No evidence has established this |
| The funds will be recovered | No outcome has been confirmed |
Until the forensic review is complete, it would be premature to blame an application, individual, or service provider. Assets can leave a self-custody wallet through several very different paths.
How can funds move while the owner still has the phone?
Crypto assets are recorded on a blockchain, not stored inside the phone itself. The phone and wallet application help the owner use a key to authorise transactions. If an attacker obtains enough information to reproduce that key elsewhere, possession of the original phone does not stop the attacker from signing on another device.
1. The seed phrase or private key was exposed
A seed phrase can recreate the wallet's keys. Anyone who obtains it may restore the same wallet on another device and transfer the assets. Exposure can happen through photographs, phone notes, email, cloud storage, information-stealing malware, or another person seeing the backup.
2. A dangerous smart-contract approval remained active
Decentralised finance applications often ask users to approve a smart contract. If that approval is granted to a fake website or malicious contract, an attacker may later use the permission to transfer tokens from the wallet.
3. Malware was present on a phone or computer
Malicious software may capture the screen, read copied information, replace a destination address, or intercept data while a seed phrase is being viewed. Installing applications from unofficial sources and granting unnecessary device permissions both increase the risk.
4. The wallet had previously been restored on another device
An owner may have imported the seed phrase into an older phone, tablet, or computer and forgotten that the device still had access. If that device was sold, lost, repaired, or shared, the weak point may have nothing to do with the current phone.
5. The owner was deceived into revealing information or signing
Scammers may impersonate customer support, a project team, or a recovery specialist. They then try to obtain the seed phrase, persuade the victim to install remote-control software, or secure a signature for a transaction the victim does not understand.
What this means in practice
- An app password can stop someone who picks up the phone, but it cannot protect a wallet after the seed phrase has leaked.
- Connecting a wallet to a website does not usually move funds by itself, but signing a message or granting token permissions can create risk.
- Revoking approvals only helps in some cases. If the key itself is compromised, the assets must move to a new wallet.
- There is no evidence yet that any one of these scenarios caused this particular incident.
How is Bitget Wallet different from the Bitget exchange?
Despite the similar names, a self-custody wallet and an exchange account work differently. Bitget Wallet describes itself as a self-custody wallet, meaning the user controls the keys rather than the provider holding the assets in the same way an exchange account does. Transactions are submitted to and recorded on the blockchain.
If a transaction carries a valid signature, the blockchain treats it as authorised even when the real owner did not intend it. A proper investigation therefore needs to examine how the keys were created and backed up, which devices previously restored the wallet, which websites were connected, and whether the disputed movement was a direct transfer or relied on an earlier token approval.
What to do if funds are leaving your wallet
1. Stop using the device you suspect
Disconnect the potentially affected device from the internet, but do not immediately erase it, remove applications, or perform a factory reset. Those actions could destroy evidence needed for the investigation.
2. Move remaining assets from a trusted device
Create a new wallet with a new seed phrase on a device you trust, then move any assets that remain. If the original seed phrase may have leaked, never reuse it in the new wallet.
3. Preserve a complete record
Save transaction hashes, source and destination addresses, networks, asset types, dates and times, notification screenshots, connected websites, and device details. Keep the original files and avoid editing or overwriting them.
4. Contact Thailand's cyber police promptly
Victims can file a report through Thai Police Online or call the cyber police hotline at 1441. Transaction hashes and supporting evidence should be prepared in advance. Speed matters when assets reach an exchange that performs customer identity checks.
5. Use only official support channels
Send the details to the wallet and exchanges involved through their verified support channels. Be wary of anyone who approaches you after the incident and promises to recover the money. A person asking for an advance fee, a seed phrase, or remote access to a device may be attempting a second scam.
Can transferred funds be recovered?
A blockchain transfer generally cannot be reversed like a bank transfer. That does not make tracing pointless. If the assets reach an exchange with identity verification, investigators may be able to request account information or seek a freeze. Some stablecoin issuers may also have the ability to freeze specific assets under an established process.
The chance of recovery depends on the route taken, the number of networks involved, the type of asset, cooperation from service providers, and how quickly the incident is reported. Nobody should promise recovery, but victims should not abandon the process before taking the available steps.
Reducing risk when holding a large crypto balance
Separate wallets by purpose
Do not use one wallet to hold long-term savings, connect to websites, test new projects, and claim rewards. Keep separate wallets for long-term storage, regular transactions, and website connections.
Keep the seed phrase offline
Do not photograph it, send it through chat, save it in email, or place it in online storage. Record it on a suitable physical medium and keep backups in locations with controlled access.
Use a dedicated device for substantial holdings
The device used to store or approve a large balance should not be the same device regularly used to open social-media links or test new applications. A hardware wallet helps isolate the keys from a phone or computer, although users must still verify transaction details and secure the seed phrase.
Review token approvals
Wallets used with decentralised applications should have their approvals reviewed periodically. Remove permissions that are no longer needed, especially unlimited token allowances.
The safest current option for long-term storage is a hardware wallet
For most people holding crypto for the long term, the safest current approach is a properly configured hardware wallet backed by a securely stored seed phrase. The key advantage is that private keys are generated and retained inside the device rather than being stored on an internet-connected phone or computer.
When funds are sent, the hardware wallet signs the transaction inside the device. The user can review the destination address, amount, and other important details on the wallet's own screen before confirming. This provides stronger protection against malware, information stealers, and applications with access to the phone than relying on a software wallet alone for a substantial balance.
A hardware wallet is not automatic protection. An attacker can still steal funds if the seed phrase is photographed, saved online, entered into a website, or if the owner approves a malicious transaction. Safe use requires a few non-negotiable habits:
- Buy from the manufacturer or a verifiable authorised seller.
- Generate the wallet and seed phrase yourself on your own device.
- Never use a seed phrase prepared by another person.
- Keep the seed phrase offline and never photograph it.
- Read the details on the hardware wallet screen before every approval.
- Keep long-term storage separate from wallets used to connect to websites.
Choosing a hardware wallet
All four brands below isolate private keys from phones and computers, but they offer different backup methods, connections, and screens. Choose the design that fits your workflow rather than making the decision on price alone.
Tangem Wallet 3 Cards: NFC convenience with two backup cards
Tangem suits users who want a card-sized, battery-free device that works with a phone over NFC. The three-card set makes it possible to keep backups in separate locations.
Tangem
฿2,590
- CC EAL6+ Secure Element
- Battery-free operation over NFC
- Three cards for daily use and separate backups
Adds the Black set. White is also available on the product page.
Trezor Safe 3: Open-source design with a Secure Element
Trezor Safe 3 is suited to users who want open-source firmware and prefer to review transaction details on the device before confirming. It connects over USB-C and uses a Secure Element for additional physical protection.
Trezor
฿3,790
- Open-source core firmware and software
- Certified Secure Element
- PIN, passphrase, and standard backup support
Adds Cosmic Black. Other colours and the Bitcoin-only Edition are available on the product page.
Ledger Nano Gen5: A touchscreen for clear-signing checks
Ledger Nano Gen5 is designed for users who want a touchscreen E Ink display and several connection options. The display makes it easier to review transaction details on the device before approval.
Ledger
฿7,540
- CC EAL6+ Secure Element
- Touchscreen E Ink display
- USB-C, Bluetooth, and NFC support
Adds Jet Black. Other colours are available on the product page.
OneKey Classic 1S Pure: Battery-free USB-C operation
OneKey Classic 1S Pure suits users looking for a slim device without a battery or wireless connections. It operates over USB-C and combines open-source firmware with a Secure Element.
OneKey
฿2,990
- No battery or wireless connection
- Open-source firmware with a Secure Element
- Slim body with USB-C connectivity
Prices and stock levels may change. Check the product page for current information before ordering. The add-to-cart button selects the model or colour noted beneath it.
Frequently asked questions
Can funds really move while the owner still has the phone?
Yes. This can happen if a seed phrase or private key is restored on another device, or if the wallet previously granted a contract permission that can transfer tokens.
Does this report prove that Bitget Wallet was hacked?
No. No published technical finding has established whether the cause was Bitget Wallet's systems, the victim's device, or another route.
Was the EV charging application responsible?
There is no evidence confirming that. It was raised as a concern by the victim and would require a forensic review of the device.
If a seed phrase leaks, will changing the app password help?
Not enough. A seed phrase can recreate the same keys on another device. The assets need to be moved to a new wallet generated from a different seed phrase.
Can a hardware wallet prevent every incident of this kind?
No. It reduces the chance of keys leaking from a phone or computer, but it cannot protect someone who reveals the seed phrase or personally approves a malicious transaction.
Summary
The report that nearly THB 17 million was transferred out of Bitget Wallet deserves attention, but it is too early to attribute the loss to a breach of any particular provider or application. The underlying cause remains under investigation.
The central lesson is not simply to keep hold of the phone. Wallet owners need to know where their keys are stored, how backups were made, which other devices have restored the wallet, and which websites or contracts have received permissions.
For people holding substantial crypto assets, separating wallets by purpose, keeping seed phrases offline, using a dedicated device for large balances, and preparing an incident-response plan provide stronger protection than relying on a single safeguard.
This article reflects information checked through August 28, 2026. No official investigation result has been released. It is intended for security education and does not determine the cause of the incident or the responsibility of any person or service provider.





Share:
Thailand Cabinet Backs Four Capital-Market Bills: What the SEC's Proposed Crypto Investigation Role Could Mean