TLDR
Trust Wallets Chrome extension (version 2.68) was compromised this week, leading to multi?chain wallet drains; the mobile app and other versions were not affected Trust Wallet browser update coverage.
- Scope: The issue affected v2.68 only, with a recommended upgrade to v2.69 %%CKPROTECTED0%%.
- Magnitude: Losses totaled about $7 million across hundreds of users report.
- Response: The owner said affected users would be reimbursed, and investigation is ongoing (see the report above).
Deep Dive
1. Scope and Vector
The breach was tied to a malicious update in the Chrome extension v2.68, where injected code captured seed phrases when imported and sent them to attacker?controlled domains technical summary. Reports emphasize the mobile app and other extension versions were not implicated, and users were told to move to v2.69 as a fix (see the notice above).
Browser extensions broaden attack surface versus native or hardware wallets. Treat seed?phrase imports into extensions as high?risk and minimize frequency.
2. Losses and Flows
Independent estimates put stolen funds at more than $67 million, with thefts spread across Bitcoin, Ethereum, BNB and Solana addresses loss and flow details. Investigators tracked significant portions routed to centralized venues such as ChangeNOW, FixedFloat and KuCoin (see the report above).
Rapid laundering through exchange rails can complicate recovery. If you were affected, documenting transaction hashes and timelines can speed case handling.
3. Response and Mitigation
Trust Wallet urged users on v2.68 to disable the extension and install v2.69, while clarifying that mobile?only users were not impacted incident recap. The platforms owner stated users would be compensated and labeled user funds as safe while the team investigated how the malicious version passed review (see the report above).
The immediate risk window was tied to v2.68 and seed?phrase imports. Longer term, prefer hardware wallets for larger balances and keep browser extensions updated.
Conclusion
The hacked wallet this week was the Trust Wallet Chrome extension v2.68, a supply?chain style compromise that siphoned seed phrases and drained funds across multiple chains. Losses around $7 million and the upgrade to v2.69 plus reimbursements response suggest the incident was contained to a narrow version window, but it highlights the structural risk of browser?based wallets in volatile markets.
