泥潭日报 uscardforum · 每日精选

Tastytrade账号被莫名转出了50k wire

内容摘要

Tastytrade用户未开2FA,50k美元被盗转,警方介入已冻结。

1. 关键信息

  • 楼主 #1 遭遇账号入侵,黑客凭密码(无2FA)转出50k wire至Truist账户1430006402575。
  • Tastytrade客服承认无法撤销,已通过Apex Clearing提交召回请求(#1)。
  • 楼主邮箱同时被黑(#1)。
  • 多名用户反映类似问题(#2、#19),有用户开2FA仍被入侵(#19)。
  • 警方取得搜查令,冻结Truist账户资金(#70)。
  • Tastytrade要求楼主签署Hold Harmless表格,被指推卸责任(#63-#64)。
  • #84 @zjtpoa 询问楼主钱是否要回,暂无后续回复。

2. 羊毛/优惠信息

3. 最新动态

  • 警方介入后资金被冻结(#70)。
  • Tastytrade仍未发送recall,客服仅邮件回复且拖延(#63、#69)。
  • 警察协助联系Tastytrade追款(#70)。
  • 新增#84用户询问追回进展,楼主未回应。

4. 争议或不同意见

  • Tastytrade安全性受质疑:有用户2FA被绕过(#19),客服推诿,不主动担责(#63-#64)。
  • 部分用户认为Apex Clearing底层券商响应慢,不如Fidelity/IBKR(#33、#51、#55)。
  • 楼主未开2FA是主因,但Tastytrade默认不发验证码(#46)及缺乏login 2FA(#48)遭批评。

5. 行动建议

  • 立即启用2FA(用authenticator app如Authy,勿仅靠SMS)(#22、#29)。
  • 设置独立强密码、不同平台不重复,邮箱也加2FA(#1、#5)。
  • 大资金建议放在Fidelity或Charles Schwab(#55)。
  • 若遇类似情况,立即报警、联系收款行fraud部门要求freeze(#18、#21)。
  • 不要随意签署Tastytrade提供的Hold Harmless表格(#64)。
原始内容
--- 第 1 楼来自 Francis958 的回复 (2026-04-21 10:32:32 PDT) ---

今天早上莫名看到账号被转出了一笔 wire 50k现金 只收到了邮件提醒 Thank you for reaching out. Full account restrictions have been placed on your account at this time. These restrictions can be removed at any time at your request. It looks like the wire was sent to Truist Bank account number 1430006402575. Unfortunately, it is too late to reject the wire request on our end. We have requested that our clearing firm, Apex Clearing Corporation, submits a wire recall request. From what we can tell, this account intrusion was not a result of deficiencies of tastytrade systems. It appears that the intruder was in possession of your login credentials and was able to login cleanly at first try. Further, it appears that you did not have two-factor authentication enabled for your account at the time of the unauthorized withdrawal. Unfortunately, this would have likely stopped the wire withdrawal from being requested as it is usually a very effective security measure. I see that you have updated your tastytrade password and enabled two-factor authentication for sensitive actions within your account. Please be sure when updating passwords to use strong password practices. Ideally, a password should be at least 12 characters and include a mix of lower-case and capital letters, numbers, and special characters such as @, $ or *. It should be unrelated to any of your prior passwords and should be unique and not used within more than one website or app. If you are struggling to think of something, you can use a password generator (there are several free options available) or pick a short sentence or phrase to use as inspiration and replace certain letters with numbers or special characters. You may want to consider changing the password tied to your email address associated with your tastytrade account. I am not indicating that your email is compromised, but this is a common place where such leaks occur. We strongly suggest that you enable two-factor authentication for sensitive actions AND at every login within your tastytrade account. You can do so by logging into your account at https://na01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fmy.tastytrade.com%2F&data=05%7C02%7C%7C9aef250986ea4f90fde208de9fc8ff4c%7C84df9e7fe9f640afb435aaaaaaaaaaaa%7C1%7C0%7C639123882785570514%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=uqdziWsCJFXHGSLfejw%2BqW7M0Gjo0IxqsXyLtgQEjBw%3D&reserved=0and follow Manage>My Profile>Security. You will see the toggle to enable these features. If offered, you should do this for all important websites. I would also suggest to never use the “stay logged in” feature for any website and be sure to clear your cookies/cache files routinely. It is a good practice to power cycle your internet router on a routine basis. Finally, frequent and routine virus scans on your devices are highly recommended. I wanted to let you know that wire withdrawals are extremely difficult to call back as the account intruder will act quickly to try to move the funds further away from the receiving bank account. If we caught this early enough, the return of the funds can take quite a bit of time as the bank needs to complete an investigation on their end. Such investigations can take over 90 days. I will keep you posted as more information becomes available to me. Please know that I am doing all I can to return these funds to you 已报警 /uploads/short-url/wVSb4LZHhfYesaMfTedlrz9zila.jpeg?dl=1 邮箱也被黑了

--- 第 2 楼来自 zjtpoa 的回复 (2026-04-21 10:35:50 PDT) ---

昨天我也是被盗号!我突然收到短信验证码,觉得不对就立马改的密码。我的密码是苹果自动生成的这样也能被盗。这么看来应该是tastytrade数据库不知道为啥泄露了

--- 第 3 楼来自 肖老二 的回复 (2026-04-21 10:41:48 PDT) ---

我靠真吓人啊 之前$250K $10K 没赶上。真的是你图它利息它图你本金

--- 第 4 楼来自 Francis958 的回复 (2026-04-21 10:43:14 PDT) ---

现在不知道咋整了 今天早上九点wire转出的.

--- 第 5 楼来自 chioce 的回复 (2026-04-21 10:46:26 PDT) ---

有没有重复用密码?tastyworks和邮箱

--- 第 6 楼来自 divinebaboon 的回复 (2026-04-21 10:51:21 PDT) ---

两个可能性: Password recycling Email got hacked at any rate, To anyone reading this, please set up 2FA on all your financial, social, airline, and hotel accounts, PLEASE I BEG YOU

--- 第 7 楼来自 mmm3 的回复 (2026-04-21 10:56:38 PDT) ---

虾仁 我也薅了这个 赶紧加验证

--- 第 8 楼来自 LastDance 的回复 (2026-04-21 11:01:02 PDT) ---

他家app里好像没看到有加验证的地方? /uploads/short-url/siQ0JqPbgFqBjZ8Pv8VFGreZtCl.jpeg?dl=1

--- 第 9 楼来自 黑金会员 的回复 (2026-04-21 11:02:19 PDT) ---

这种能要回来吗

--- 第 10 楼来自 0-1 的回复 (2026-04-21 11:08:29 PDT) ---

去网页版设置。

--- 第 11 楼来自 Francis958 的回复 (2026-04-21 11:09:17 PDT) ---

update: 家人们能不能管管俺啊 打电话给了truist 他们说这笔钱在pending 看到这笔钱了 怎么办啊

--- 第 12 楼来自 zjtpoa 的回复 (2026-04-21 11:10:44 PDT) ---

我的没有。苹果自动产生的

--- 第 13 楼来自 wrysta 的回复 (2026-04-21 11:11:58 PDT) ---

楼主看你截图fidelity也改了密码 这是hacker改的还是你自己操作的

--- 第 14 楼来自 LastDance 的回复 (2026-04-21 11:17:04 PDT) ---

打电话给tastytrade和背后的银行让他们试下能不能拦住这笔wire有用吗(我是小白)?

--- 第 15 楼来自 divinebaboon 的回复 (2026-04-21 11:19:40 PDT) ---

gotta learn to ask gemini man, it’s free /uploads/short-url/jCWYE7wxknlxUCkSfsSPRtPrq9E.png?dl=1 /uploads/short-url/aJEInFOZzOpaKxcVRRx3Ayabzbi.png?dl=1 /uploads/short-url/GQVRmHPyxFg8dySWO0M9iAeDxk.png?dl=1 /uploads/short-url/4v85501PxYXT4qBd0Dw3XYnu6ry.png?dl=1 did you secure your email and clear any forwarding per suggestion 4? number 1’s http://ic3.gov seems pretty legit? here’s how the number 1 IC3 kill chain works: https://www.justice.gov/elderjustice/media/1364056/dl?inline

--- 第 16 楼来自 斯卡布罗 的回复 (2026-04-21 11:20:41 PDT) ---

tastytrade怎么说?如果一般的客服不给力赶快要求跟supervisor直接对话?

--- 第 17 楼来自 kobe 的回复 (2026-04-21 11:23:22 PDT) ---

这家有前科啊? https://www.google.com/search?q=tastytrade+leak+site:www.reddit.com&client=safari&hs=wakp&sca_esv=31f3bc1e9f0acfe0&hl=en-us&prmd=nvi&sxsrf=ANbL-n45N8LAux0icyXgK9twLvvUMdJWUw:1776795697467&sa=X&ved=2ahUKEwjq-Yrjx_-TAxXVnisGHZe8HVgQrQJ6BAgPEAY&biw=440&bih=742&dpr=3 https://www.google.com/search?q=tastytrade+leak+site:www.reddit.com&client=safari&hs=wakp&sca_esv=31f3bc1e9f0acfe0&hl=en-us&prmd=nvi&sxsrf=ANbL-n45N8LAux0icyXgK9twLvvUMdJWUw:1776795697467&sa=X&ved=2ahUKEwjq-Yrjx_-TAxXVnisGHZe8HVgQrQJ6BAgPEAY&biw=440&bih=742&dpr=3

--- 第 18 楼来自 Wall 的回复 (2026-04-21 11:23:59 PDT) ---

让truist freeze啊

--- 第 19 楼来自 CubeOvO 的回复 (2026-04-21 11:24:21 PDT) ---

On April 4, my brother’s account, who had a unique password and 2FA enabled, was compromised. The hackers did not withdraw money or change info and trigger 2FA. Though I have repeatedly emailed multiple divisions and Tom, Scott and Tony at Tastytrade, no one is helping me understand what happened and how to resolve. 太吓人了

--- 第 20 楼来自 chioce 的回复 (2026-04-21 11:25:02 PDT) ---

是不是没有密码也能发出来?

--- 第 21 楼来自 Wi-Fi 的回复 (2026-04-21 11:27:54 PDT) ---

附议,联系turist fraud要求freeze,这个账户的开户信息应该都是假的,用来一进一出的mule账号

--- 第 22 楼来自 LastDance 的回复 (2026-04-21 11:30:56 PDT) ---

我看网页版2FA要SMS或者Authenticator app,LZ是没有设置吗,还是2FA somehow got bypassed?

--- 第 23 楼来自 0-1 的回复 (2026-04-21 11:31:41 PDT) ---

看楼主贴的客服回复的邮件是说 2FA 完全没打开然后密码泄漏了。 顺便贴一下之前的讨论: https://www.uscardforum.com/t/topic/497875/28 /c/investment/stock-market/13 在使用一个完全隔离的设备之前个人觉得其他的一些简单容易做到的安全实践带来的收益更高: 独立的强密码并且不要存储在不安全的地方或者在不安全的环境使用。 2FA / MFA(确保你的 recovery 邮箱也加上了 MFA)。 不要过度分享隐私信息,包含用户名,账号号码等等。 高危操作开启邮件和 push notification。 网页操作使用单独的浏览器 profile 或者隐私模式。 不使用…

--- 第 24 楼来自 zjtpoa 的回复 (2026-04-21 11:37:13 PDT) ---

发出来什么?没看懂

--- 第 25 楼来自 Paul144 的回复 (2026-04-21 11:43:55 PDT) ---

他说的发出来=Wire转账给陌生人账户

--- 第 26 楼来自 dannylee 的回复 (2026-04-21 11:57:07 PDT) ---

登录app提示有login attempt。看来是有泄露。我设置了2fa

--- 第 27 楼来自 zjtpoa 的回复 (2026-04-21 12:34:05 PDT) ---

不行,得有密码才能发出来

--- 第 28 楼来自 BankOfAmerica 的回复 (2026-04-21 13:12:39 PDT) ---

TMD. 我手机貌似收不到这家的SMS. 死活收不到sms,但随便打开个打字框,能自动抓取6位数. 破案了. 需要取消iphone对垃圾短信的过滤

--- 第 29 楼来自 divinebaboon 的回复 (2026-04-21 14:08:17 PDT) ---

or use an authenticator app like authy

--- 第 30 楼来自 Francis958 的回复 (2026-04-21 14:39:21 PDT) ---

家人们 truist不让freeze 开了个case 说client info无可奉告 tastrytrade这边索性就装死 说联系了apex clearing submit了一个recall

--- 第 31 楼来自 Francis958 的回复 (2026-04-21 14:39:46 PDT) ---

他家客服一言难尽fraud只用邮件回

--- 第 32 楼来自 Wi-Fi 的回复 (2026-04-21 14:43:06 PDT) ---

那没用了,钱明天就到肯尼亚/柬埔寨了

--- 第 33 楼来自 renwoxing 的回复 (2026-04-21 14:49:30 PDT) ---

报警有用吗? 这家真是草台班子啊。Fidelity IBKR这些靠谱多了。

--- 第 34 楼来自 Mdxonly 的回复 (2026-04-21 15:03:17 PDT) ---

被盗要是追不回来那就真是不敢用了 以后我不骂Merrill了 连账户神难因为总要你手动填表发过去

--- 第 35 楼来自 mmm3 的回复 (2026-04-21 15:19:16 PDT) ---

好坑啊 我有点慌了

--- 第 36 楼来自 EVA1 的回复 (2026-04-21 15:21:44 PDT) ---

不一定,pull可能要hold一段时间

--- 第 37 楼来自 Francis958 的回复 (2026-04-21 15:24:01 PDT) ---

他是push的 不知道异地登陆也可以直接用账户密码登录上去

--- 第 38 楼来自 Francis958 的回复 (2026-04-21 15:45:52 PDT) ---

家人们 警察拿了sewrch warrent 明天去冻结了不知道来不来得及

--- 第 39 楼来自 bumblebee 的回复 (2026-04-21 16:16:30 PDT) ---

每次看到这种情况,我就感叹老牌full service brokerage能接盘大部分大客户是有道理的。几百万的账户连个客户在需要的时候都联系不上,真的有人会放心用嘛?

--- 第 40 楼来自 Francis958 的回复 (2026-04-21 16:19:55 PDT) ---

早上吓坏了 这还是一个账户 把所有saving和brokage密码都改了

--- 第 41 楼来自 Paul144 的回复 (2026-04-21 16:26:15 PDT) ---

你为什么会放置现金在Tastytrade? 如果买了SGOV,你还有反应的时间。

--- 第 42 楼来自 Francis958 的回复 (2026-04-21 16:37:58 PDT) ---

现在转头把所有的现金换成sgov了…

--- 第 43 楼来自 Wi-Fi 的回复 (2026-04-21 16:41:43 PDT) ---

你们那警察很给力啊。明早去branch可能来得及 https://www.truist.com/content/dam/truist-bank/us/en/documents/cra/truist-branches.pdf https://www.truist.com/content/dam/truist-bank/us/en/documents/cra/truist-branches.pdf https://www.truist.com/content/dam/truist-bank/us/en/documents/cra/truist-branches.pdf 找法庭开order可以让turist调开户时的监控(如果他们没有主动配合的话),看看骗子假ID的工艺。如果是online开户的就呵呵了

--- 第 44 楼来自 sofarsogood 的回复 (2026-04-21 16:55:56 PDT) ---

这太吓人了,希望lz尽快拿回来

--- 第 45 楼来自 sofarsogood 的回复 (2026-04-21 17:01:05 PDT) ---

是盗贼登录到lz账户然后发起wire transfer out?一般这种情况在submit时系统不都是要send一个验证code吗?lz账户上的电话号被改了?

--- 第 46 楼来自 zjtpoa 的回复 (2026-04-21 17:06:58 PDT) ---

他没设置2fa tasty应该默认是不发code

--- 第 47 楼来自 flywire 的回复 (2026-04-21 17:36:54 PDT) ---

能fdic赔付吗? 这是监守自盗还是系统安全性差

--- 第 48 楼来自 Francis958 的回复 (2026-04-21 17:44:19 PDT) ---

https://www.reddit.com/r/tastytrade/s/dJbKVsNy32 看看这个 tastytrade的2fa没有login 2fa 还有这个 https://www.cbsnews.com/amp/chicago/news/couple-retirement-account-hacked-tali-erez-hartal-tastytrade/ https://www.cbsnews.com/amp/chicago/news/couple-retirement-account-hacked-tali-erez-hartal-tastytrade/ A Chicago area couple logged into their retirement account only to find out it had been hacked, and a large chunk of their retirement savings was gone. The response from the online brokerage firm is only adding insult to injury.

--- 第 49 楼来自 Francis958 的回复 (2026-04-21 17:44:53 PDT) ---

fdic好像不包这个 不是很懂 但事情都发生了 心态保持平和 希望能要回来吧

--- 第 50 楼来自 flywire 的回复 (2026-04-21 17:47:53 PDT) ---

这是故意留后门?

--- 第 51 楼来自 zzz 的回复 (2026-04-21 17:52:26 PDT) ---

Fidelity客服很好,IBKR客服基本没有,只能开ticket

--- 第 52 楼来自 LastDance 的回复 (2026-04-21 18:06:16 PDT) ---

应该是去年的某个时候release了login 2FA, 可能之前出了几次这样的事故了

--- 第 53 楼来自 renwoxing 的回复 (2026-04-21 18:47:58 PDT) ---

IBKR 转钱不容易。

--- 第 54 楼来自 renwoxing 的回复 (2026-04-21 18:48:45 PDT) ---

这是哪个券商?

--- 第 55 楼来自 lulumoon 的回复 (2026-04-21 19:51:44 PDT) ---

/uploads/short-url/2sJyidv7XgasUEDekFTfmPFGB0d.png?dl=1 这个家玩期权比较便宜,其他没好处了。大钱放fidelity或者charles schwab.

--- 第 56 楼来自 Promise_5 的回复 (2026-04-21 20:17:08 PDT) ---

邮箱被黑了那是真各种账户都危险。

--- 第 57 楼来自 TrashGeGe 的回复 (2026-04-21 20:35:33 PDT) ---

我邮箱都是Yubi key保的。感觉暂时唯一安心的操作。然后基本所有其他服务都是sso,disable password

--- 第 58 楼来自 jonca 的回复 (2026-04-21 20:45:58 PDT) ---

感觉是邮箱?你有俄语邮件 应该是被黑了

--- 第 59 楼来自 chioce 的回复 (2026-04-21 21:02:46 PDT) ---

没有密码能不能让tasty发短信验证码?

--- 第 60 楼来自 IamShawnMendes 的回复 (2026-04-21 21:05:20 PDT) ---

Francis958: Further, it appears that you did not have two-factor authentication enabled for your account at the time of the unauthorized withdrawal. 这个是怎么设置。。。

--- 第 61 楼来自 harrywy 的回复 (2026-04-21 22:58:09 PDT) ---

所以撸了10k 后要把钱放多久?….

--- 第 62 楼来自 LastDance 的回复 (2026-04-22 08:20:01 PDT) ---

one year

--- 第 63 楼来自 Francis958 的回复 (2026-04-22 08:45:19 PDT) ---

truist回复 at this time we have taken the appropriate action on the Truist account. We have not received a recall from your institution and are in need of a Hold Harmless. It is recommended that the matter be reported to their financial institution if you have not already done so. 我打电话给tastytrade 看起来他们是一点事儿不办啊 想要一个unauthorized claim form, security incident form 还有 hold harmless form 问什么都是we are working this really hard and will have update soon. 还让我不要打电话了 会delay进度

--- 第 64 楼来自 Wi-Fi 的回复 (2026-04-22 08:52:17 PDT) ---

找你要hold harmless form你可不能签,是tastytrade给truist签

--- 第 65 楼来自 VFIAX 的回复 (2026-04-22 08:54:40 PDT) ---

这一堆操作搞完了钱早转走了吧

--- 第 66 楼来自 Francis958 的回复 (2026-04-22 09:09:38 PDT) ---

钱应该被hold住了 转不出去了

--- 第 67 楼来自 Francis958 的回复 (2026-04-22 09:10:06 PDT) ---

tastetrade是一点也不想担责任

--- 第 68 楼来自 LastDance 的回复 (2026-04-22 09:14:38 PDT) ---

是警察去了branch才hold住的吗?还是truist主动freeze了账户?

--- 第 69 楼来自 Wi-Fi 的回复 (2026-04-22 09:33:46 PDT) ---

先不管责任不责任的,wire recall到今天还没发出去真的是太垃圾了。 (做笔记,用各路套壳apex clearing的券商就得有觉悟,出问题没法当天联系上apex clearing的fraud部门)

--- 第 70 楼来自 Francis958 的回复 (2026-04-22 11:19:17 PDT) ---

/uploads/short-url/oTwiQeIw2a0Tb8gmeYlrZTzu9gi.jpeg?dl=1 我哭了 警察太好了 fund还在 freeze了 还帮我去tastytrade要钱了 改天我要去警察局送花!

--- 第 71 楼来自 Ava.太太太后 的回复 (2026-04-22 12:05:30 PDT) ---

这太吓人了…2FA都能被绕过?感觉Tastytrade可能有严重的security issue啊。楼主有没有报警?wire一旦发出去基本追不回来,但还是值得试试拦一下。

--- 第 72 楼来自 肖老二 的回复 (2026-04-22 12:07:04 PDT) ---

送个锦旗ZS

--- 第 73 楼来自 HoverSoul 的回复 (2026-04-22 12:11:31 PDT) ---

给老美警察见识见识中式锦旗哈哈

--- 第 74 楼来自 Wi-Fi 的回复 (2026-04-22 12:18:06 PDT) ---

支持,让敬业的警察感受一下中式感激

--- 第 75 楼来自 ze3kr 的回复 (2026-04-22 12:23:19 PDT) ---

我记得 SoFi 用的就是 Apex Clearing。查了下 WeBull、Betterment、Frec、M1 也是

--- 第 76 楼来自 TrashGeGe 的回复 (2026-04-22 12:27:34 PDT) ---

查了一下coinbase也是。神奇的是robinhood一开始用的apex,gme以后就换成自己的了。是不是这么说起来robinhood还更靠谱一点,毕竟出了事不用cross company communication。

--- 第 77 楼来自 ze3kr 的回复 (2026-04-22 12:29:27 PDT) ---

我感觉用 apex clearing 的 wire 功能不一定是用的 clearing。很多券商只是股票交易用的 apex clearing RH 比 coinbase 靠谱点吧,开始股票交易的也更早。想要最靠谱就选 Fidelity,AUM 大 /uploads/short-url/jmQhiFbgQTGieZ1uZDyNouLRVF1.jpeg?dl=1 RH 也算前十了

--- 第 78 楼来自 斯卡布罗 的回复 (2026-04-22 13:14:25 PDT) ---

警察好样的,同时tastytrade太烂了。。。

--- 第 79 楼来自 258 的回复 (2026-04-22 13:17:18 PDT) ---

谭赚我赚

--- 第 80 楼来自 TrashGeGe 的回复 (2026-04-22 15:48:32 PDT) ---

我靠,长好快

--- 第 81 楼来自 Cynthia 的回复 (2026-04-22 16:22:35 PDT) ---

/uploads/short-url/n7lJZp5xlhmizZP1gtynMTawdFU.jpeg?dl=1

--- 第 82 楼来自 zjtpoa 的回复 (2026-04-22 17:43:27 PDT) ---

楼主钱要回来一定要写个教程!

--- 第 83 楼来自 colby 的回复 (2026-04-22 17:48:25 PDT) ---

送个精致点的餐点,请在场的警察一起吃。

--- 第 84 楼来自 zjtpoa 的回复 (2026-05-02 21:52:58 PDT) ---

楼主钱要回来了吗?