Trust Wallet
Incident posture
Linked entities
- Victim
- Trust Wallet
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Trust Wallet reported a security incident affecting its browser extension version 2.68 after attackers submitted a malicious update through the Chrome Web Store using a leaked API key, which passed review and was distributed before being detected. The malicious code silently transmitted wallet data to an external domain and activated when a seed phrase was imported, leading to the theft of approximately seven million dollars in cryptocurrency from users who opened and logged into the compromised version prior to the mitigation actions. The incident did not affect mobile app users, other extension versions, or users who accessed the extension after the malicious version was disabled. The company suspended the malicious domain, expired related release APIs, began processing reimbursement claims, and urged users to upgrade to the patched version 2.69.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On December 25, 2025, Trust Wallet posted on X that it had identified a security incident affecting Trust Wallet Browser Extension version 2.68. The post stated that only users who opened the extension and logged in were impacted, while mobile app users, other extension versions, and users who accessed version 2.68 after December 26, 2025 at 1100 UTC were not affected. On December 26, 2025, Binance founder Changpeng Zhao confirmed that the Trust Wallet security team was still investigating how hackers submitted a malicious version of the extension and that approximately $7 million in cryptocurrency had been affected at that stage of the investigation. Zhao added that user funds were covered by the Binance Secure Asset Fund for Users and that Trust Wallet would compensate any losses.
Trust Wallet explained that the malicious extension version 2.68 was not released through its internal manual process and that current findings suggested it was published externally via a Chrome Web Store API key, thereby bypassing standard release checks. The company described a working hypothesis, still under investigation, that the hacker used a leaked Chrome Web Store API key to submit the malicious version. According to Trust Wallet, the malicious extension passed Chrome Web Store's review and was released on December 24, 2025 at 12:32 UTC. Analysis by a security analyst indicated that the compromised update added code designed to silently transmit wallet data to an external domain, masquerading as analytics and triggering when a seed phrase was imported.
In response, Trust Wallet reported the malicious domain associated with the attack to registrar NiceNIC, which subsequently suspended the domain. The company expired all release application programming interfaces, preventing any new extensions from being published for the next two weeks. Trust Wallet began collecting victims' support tickets and processing reimbursements while continuing internal forensic analysis and awaiting additional logs from Google's support team to further examine the root cause. Trust Wallet announced that version 2.69 of the browser extension was released as the latest secure version.
Sources
Sources available to members: 1 source.