hello,
On 28feb2022 I get hacked, 2.4bitcoin from coinomi android wallet got stolen.
It's an old Android 7, Samsung Galaxy s6edge (no root).
In 2017-2019 I use Coinomi wallet to store my bitcoin because was simple easy to use.
In summer 2019 I decide to use that phone only like a "cold storage" I have coinomi app, windscribe vpn and google apps. I choose that because was simple , once a month I power the phone do the update on coinomi and the other apps checking the wallet and shut it down.
The Coinomi wallet do not have the BIP39 passphrase implement ate at that time but I secure the wallet with a passowrd , with a pin number in case somebody had the phone to be hard to unlock it.
At the end of February2022 I update the coinomi wallet to version 1.25.2 build 430 core 220 all work fine update done, I check the wallet the bitcoin was there (I also choose the feature " Mark do-not-spend " in case somebody open the wallet no amount was display ) but today I check the address of my wallet (I have it saved in tor browser to be simple to check the utxo ) and I see the coins were moved
https://oxt.me/transaction/812f73d94bc1eb029e72930427ea27bee4e668accaad4d3fc167a24f1de364a5 how can this happen ? since nobody have access to the phone.
The seed was stored on paper ,nobody see it ,plus I wrote the words in other order so only I can know the right order.
I'm sure something was wrong with the update since is noot an open source wallet nobody knows what that wallet can send out butt I think the wallet send the seed out to somebody because passed 3 and half years and the seed was safe inside it only know happen..only after the update.
There are many misconceptions here, and a small research could have saved your money.
First of all, VPN do not increase security, but a bad VPN might even be bad for it as o_e_l_e_o pointed out. Aditionally, this is more than enough money just to buy a hardware wallet (less than 50 usd) which was designed to secure your coins
A cold wallet is just a wallet which never connects to internet.
You never had a cold wallet. Once your your was created using coinomi, that seed was already exposed to an online environment. Installing it in a new phone, downloading a VPN, etc just reduced it security.
The correct procedure would be to buy a hardware wallet (or create a paper wallet , but you lack knowledge for that) and then transfer your funds from coinomi to that new wallet