According to the inference, the input method saved the mnemonic input and stored it in a certain file on the phone. A certain software on Android phones carries a virus that has permission to scan all files on your phone and took your mnemonic.
The thief monitors the wallet assets of this mnemonic but does not transfer them directly. Instead, they remain lurking and wait. When your sAID token arrives, it just triggers the asset to exceed the threshold of 500 or 600U, and the hacker's program automatically transfers all assets.
