After 170,000 USDT was stolen, the perpetrators asked him to transfer money again to unlock it.
A video dated October 5 claimed that on June 10, he downloaded a fake wallet from Huawei’s official store, exposing his recovery phrase, and 177,473 USDT was stolen. The address permissions were subsequently changed to multisig.
The next step deserves closer attention: in a second scam, they asked him to transfer money under the pretext of “paying to unlock” the funds. After he transferred it, all the USDT in the address was moved out.
No specific address or transaction hash is available at present, so it is impossible to verify which transaction involved the multisig change or whether the recipient of the second transfer was part of the same group that stole the funds.
If the address is identified later, check these three things: the time of the permissions-change transaction, the amount received in the unlock transfer, and the interval between the final USDT outflow and the previous one.
This involved an additional layer beyond simply losing a recovery phrase: a second contact in which the perpetrators posed as helpers.