TRON Multisig Scam: How to Check a TRC20 Wallet's Permissions and Avoid the Second Scam
The wallet holds USDT, yet you can't move it, and the TRX you sent "for the fee" disappears. Here is how scammers abuse TRON multisig, how to check a TRC20 wallet on Tronscan in a minute, and why "multisig removal services" are a second scam.
Short answer: you can check a TRC20 wallet for a multisig trap in about a minute. Open the address on Tronscan and look at the Permissions tab. If the Owner section lists an address that isn't yours, the wallet isn't yours either, even if you hold the seed phrase and the app shows a USDT balance. Two schemes are built on this: a "leaked" seed phrase for a wallet full of USDT, and a quiet takeover of your own wallet. Whatever you send to such an address goes to whoever holds the owner key, and there is no technical way to restore control without that key's signature.

What multisig is in TRON and where it lives
Every TRON account has a set of permissions. The owner permission is the master one: it allows any operation, including changing the permissions themselves. Active permissions cover specific actions, such as transfers only. Each permission has a list of key addresses with weights and a threshold: a transaction goes through once the combined weight of the signing keys reaches the threshold.
A new wallet is simple: the owner permission holds one key, yours, and its weight equals the threshold. Multisig is any setup where a permission holds more than one key, or holds someone else's key. For companies it's a normal tool: a treasury can require two signatures out of three so no single employee can move funds alone. The trouble starts when the permissions are configured by a scammer instead of the owner.
Changing permissions is a separate paid transaction, and its cost is set by network parameters. Owner, active and thresholds are explained in the TRON multi-signature documentation. We showed where to find this section in our Tronscan guide.
Scheme 1: the "leaked" seed phrase for a wallet with USDT
In a chat, a comment thread or a DM, someone "accidentally" posts a seed phrase or asks for help: "I have USDT in this wallet and can't figure out how to withdraw, here's the phrase." You import the wallet and see thousands of USDT and zero TRX. Sending USDT needs energy or TRX for the fee, so you send a little TRX there.
Then the USDT transfer fails with a signature or permission error. The owner permission of that address was rewritten to the scammer's key long ago, and your seed phrase only controls the old key, which no longer carries any weight. The scammer sweeps the TRX you sent, because his owner key works. The USDT is a shop window you will never be able to withdraw from.
- A wallet with a large balance and no TRX whose phrase landed in your hands "by chance" is almost always bait.
- Nobody hands strangers access to real money just to get help with a fee.
- Renting energy for such an address is pointless too: the energy arrives, but you still can't sign the transfer.
Scheme 2: a quiet takeover of your TRC20 wallet
If your seed phrase leaked through a phishing site, a fake wallet app or fake "support" on Telegram, the attacker doesn't always drain the wallet right away. Sometimes he switches the owner permission to his own key and waits. The app still shows your address and balance, incoming transfers keep arriving, but you can no longer send anything.
The worst part is that money keeps coming in: an exchange, a client or a partner sends USDT to the saved address, and all of it is now controlled by someone else's key. Sometimes the scammer adds his key to an active permission with transfer rights instead of the owner one, and then funds can leave at any moment without your involvement.
A leaked seed phrase isn't the only way to lose USDT. A similar trick with fake tokens is covered in our article on flash USDT TRC20, and recipient address swapping in the piece on address poisoning.
How to check a TRC20 wallet for multisig on Tronscan
- Copy the wallet address from the app instead of typing it.
- Open tronscan.org, paste the address into search and go to the account page.
- Find the Permissions tab.
- Check Owner Permission: a normal wallet shows one key, your address, with a weight at least equal to the threshold.
- Check Active Permissions: every key should be yours, and the allowed operations should make sense to you.
- Compare addresses character by character: scammers generate keys that match yours in the first and last characters.
Red flags: an unknown address in owner; a threshold higher than your key's weight; an unfamiliar address in active with transfer rights. Any of these means you can't control the wallet on your own.
To check many addresses, the API is more convenient: the getaccount method on a TRON node returns owner_permission and active_permission fields with keys and thresholds. Services that accept USDT on hundreds of addresses can run this check automatically before crediting deposits or sending payouts.
"We'll remove the multisig": the second scam
After a loss, people search for how to remove TRON multisig and run into "recovery specialists." The pitches vary: an upfront fee, a request for your seed phrase, an "unlocking" tool, or a promise to deal with network support. It's technically impossible: permissions can only be changed by a transaction signed by keys from the current owner permission with enough weight to meet the threshold. The scammer holds that key, and TRON has no support desk that can roll back a transaction.
- Never send your seed phrase or private key to anyone, whether "support," an "expert" or a bot.
- Don't pay for "multisig removal": without the owner key it can't be done.
- Don't send TRX to a hijacked address hoping to move the USDT out first.
What to do if your TRC20 wallet has already been taken over
- Create a new wallet with a new seed phrase on a clean device, and don't import the old phrase into it.
- Replace your deposit address everywhere it's saved: exchanges, clients, payout services, withdrawal whitelists.
- If your key is still in owner with enough weight, remove the foreign keys with a permission update transaction, but assume the phrase is compromised and move your funds.
- Save the transaction hashes and the scammer's address: you'll need them for a police report and for a request to the exchange where the funds went.
Energy rental and multisig: where the line is
Legitimate energy rental never touches your wallet's permissions. The provider delegates energy to your address with its own transaction: it only needs the address, not your signature, seed phrase or a permission change. If a service asks you to add its address to owner or active, stop and figure out exactly which operations you'd be allowing and whether you can do without it.
How delegation works without access to your keys is explained in our article on renting TRON energy without private keys. Once the wallet is checked and its permissions are clean, you can buy TRON energy for your next transfer: the amount depends on whether the recipient already holds USDT, and the price depends on the market and the rental term.
A seed phrase gives you a key, not a wallet. The wallet belongs to whoever holds the key in owner, so check Permissions before you trust a balance or send TRX.
Need energy for a wallet you've verified? In the Telegram bot @overtronbot you only enter the address and the amount: energy arrives by delegation, with no access to keys and no permission changes.
Read also
How do I check a TRC20 wallet for multisig?
Open the address on Tronscan and go to the Permissions tab. Owner Permission should list one key, your address, with a weight at least equal to the threshold. Someone else's address in owner, or an unknown key in active with transfer rights, means another party controls the wallet.
Someone sent me a seed phrase for a wallet with USDT. Is it a scam?
Almost certainly. It's classic bait: the wallet holds USDT but no TRX, and its owner permission points to the scammer's key. You send TRX for the fee, the USDT transfer fails, and the real key holder takes the TRX.
Can TRON multisig be removed without the owner key?
No. Permissions change only through a transaction signed by keys from the current owner permission with enough weight. Neither the network, a wallet app nor a "recovery service" can do it on the key holder's behalf.
Why can I see USDT in my balance but can't send it?
If signing fails with a permission error, your key is most likely no longer in owner, or its weight is below the threshold. The app shows the balance of the address, not your right to spend it.
What should I do if my TRC20 wallet was hijacked through multisig?
Create a new wallet with a new seed phrase, update your deposit address on exchanges and with counterparties, and stop sending anything to the old address. Keep the transaction hashes for a report.
Is multisig always a scam?
No. Companies and OTC desks use it legitimately, for example by requiring two of three signatures for payouts. The dangerous kind is a multisig you didn't set up that contains someone else's keys.
Does TRON energy rental need access to my wallet permissions?
No. The provider delegates energy to your address, and the address is all it needs. No seed phrase, signature or permission change is required.
Will renting energy help me withdraw USDT from a hijacked wallet?
No. Energy pays for executing the transfer but doesn't replace the signature. If your key has no rights, the transaction fails no matter how much energy you have.


