TLDR: Malicious code in Trust Wallet Chrome extension version 2.68 stole seed phrases and drained $7 million total. Individual victims lost between $50,000 and $TLDR: Malicious code in Trust Wallet Chrome extension version 2.68 stole seed phrases and drained $7 million total. Individual victims lost between $50,000 and $

Trust Wallet Chrome Extension Hacked: $7M Stolen in Christmas Day Supply-Chain Attack

TLDR:

  • Malicious code in Trust Wallet Chrome extension version 2.68 stole seed phrases and drained $7 million total.
  • Individual victims lost between $50,000 and $800,000 across Bitcoin, Ethereum, and Solana blockchain networks.
  • Binance co-founder CZ confirmed Trust Wallet will reimburse all affected users and cover the complete $7M loss.
  • Users must avoid version 2.68 and upgrade to version 2.69 immediately; mobile wallets remained unaffected.

Trust Wallet suffered a major security breach on December 25 when malicious code infiltrated version 2.68 of its Chrome browser extension. 

The attack compromised user seed phrases and resulted in approximately $7 million in cryptocurrency losses across Bitcoin, Ethereum, and Solana networks. 

Binance co-founder Changpeng Zhao confirmed that affected users would receive full reimbursement for their losses.

Supply Chain Attack Targets Browser Extension Users

The breach occurred through a supply-chain attack that specifically targeted Trust Wallet’s Chrome extension update. Malicious actors injected code designed to steal seed phrases, which are crucial security elements that grant access to cryptocurrency holdings. 

Once compromised, these phrases allowed hackers to authorize transfers and drain funds from affected wallets.

On-chain investigators ZachXBT and Lookonchain tracked the stolen funds and confirmed their movement to various cryptocurrency exchanges. Individual losses ranged from $50,000 to $800,000 per victim. 

The timing of the attack, coinciding with the Christmas holiday, raised concerns about the coordinated nature of the breach.

Trust Wallet’s development team acted quickly upon discovering the compromise. The company released version 2.69 of the extension within hours and urged all users to upgrade immediately. 

Mobile wallet users and those using other browser extensions remained unaffected by the security incident.

Binance Pledges Full Coverage of User Losses

Changpeng Zhao, commonly known as CZ, addressed the incident through social media platforms. He stated that Trust Wallet would cover all losses incurred by affected users. His message emphasized that user funds remained secure despite the breach. 

CZ acknowledged the inconvenience caused while investigations continued into how the compromised version gained approval.

The wallet team issued urgent warnings advising users to avoid opening version 2.68 entirely. Instead, users should download and install version 2.69 immediately to protect their holdings. 

The company stressed that only Chrome extension users who updated to the compromised version faced potential exposure.

This incident reflects broader trends in cryptocurrency security challenges. According to Chainalysis, crypto theft reached $6.75 billion in 2024. 

Personal wallet compromises increased dramatically from 64,000 incidents in the previous year to 158,000 cases. However, the proportion of total stolen funds from personal wallets decreased from 44% to 20%.

Investigations remain ongoing to determine how hackers successfully submitted the malicious update through official channels. 

The breach highlights vulnerabilities in software distribution systems that cryptocurrency platforms must address. Trust Wallet continues working with security experts to prevent similar attacks in the future.

The post Trust Wallet Chrome Extension Hacked: $7M Stolen in Christmas Day Supply-Chain Attack appeared first on Blockonomi.

Market Opportunity
Intuition Logo
Intuition Price(TRUST)
$0.1111
$0.1111$0.1111
+2.02%
USD
Intuition (TRUST) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Gold continues to hit new highs. How to invest in gold in the crypto market?

Gold continues to hit new highs. How to invest in gold in the crypto market?

As Bitcoin encounters a "value winter", real-world gold is recasting the iron curtain of value on the blockchain.
Share
PANews2025/04/14 17:12
UK crypto holders brace for FCA’s expanded regulatory reach

UK crypto holders brace for FCA’s expanded regulatory reach

The post UK crypto holders brace for FCA’s expanded regulatory reach appeared on BitcoinEthereumNews.com. British crypto holders may soon face a very different landscape as the Financial Conduct Authority (FCA) moves to expand its regulatory reach in the industry. A new consultation paper outlines how the watchdog intends to apply its rulebook to crypto firms, shaping everything from asset safeguarding to trading platform operation. According to the financial regulator, these proposals would translate into clearer protections for retail investors and stricter oversight of crypto firms. UK FCA plans Until now, UK crypto users mostly encountered the FCA through rules on promotions and anti-money laundering checks. The consultation paper goes much further. It proposes direct oversight of stablecoin issuers, custodians, and crypto-asset trading platforms (CATPs). For investors, that means the wallets, exchanges, and coins they rely on could soon be subject to the same governance and resilience standards as traditional financial institutions. The regulator has also clarified that firms need official authorization before serving customers. This condition should, in theory, reduce the risk of sudden platform failures or unclear accountability. David Geale, the FCA’s executive director of payments and digital finance, said the proposals are designed to strike a balance between innovation and protection. He explained: “We want to develop a sustainable and competitive crypto sector – balancing innovation, market integrity and trust.” Geale noted that while the rules will not eliminate investment risks, they will create consistent standards, helping consumers understand what to expect from registered firms. Why does this matter for crypto holders? The UK regulatory framework shift would provide safer custody of assets, better disclosure of risks, and clearer recourse if something goes wrong. However, the regulator was also frank in its submission, arguing that no rulebook can eliminate the volatility or inherent risks of holding digital assets. Instead, the focus is on ensuring that when consumers choose to invest, they do…
Share
BitcoinEthereumNews2025/09/17 23:52
MicroStrategy Bitcoin Strategy Faces Dilution Risks Amid Stock Decline, MSCI Review

MicroStrategy Bitcoin Strategy Faces Dilution Risks Amid Stock Decline, MSCI Review

The post MicroStrategy Bitcoin Strategy Faces Dilution Risks Amid Stock Decline, MSCI Review appeared on BitcoinEthereumNews.com. MicroStrategy stock dilution arises
Share
BitcoinEthereumNews2025/12/27 05:01