Need help? Support
BITCOIN
Tether Dominance USDT.D

What caused Trust Wallet exploit?

Published Updated 454 words 3 min read

TLDR

It was caused by a malicious update to the Trust Wallet Chrome extension (v2.68) pushed via a supply?chain compromise that exfiltrated seed phrases; roughly $7 million was drained and reimbursements are underway per a security report.

  1. Injected code in v2.68 enumerated wallets and secretly sent mnemonics to attacker servers, according to a forensic analysis.
  2. The root vector was a leaked Chrome Web Store API key and GitHub secrets, linked to the Sha1?Hulud supply chain incident, per a post?mortem update.
  3. Impact was limited to desktop extension users; Trust Wallet identified 2,596 affected addresses and is verifying claims to reimburse victims as noted in a verification update.

Deep Dive

1. Attack Vector

The exploit centered on Trust Wallets browser extension v2.68, where malicious changes enabled seed phrase theft during normal use.

  1. Investigators compared v2.67 vs v2.68 and found injected logic that iterated through stored wallets and requested mnemonics, then relayed them via analytics scripts to attacker infrastructure, per a forensic analysis.
  2. Mobile wallets and other extension versions were not impacted; users were instructed to disable v2.68 and update to a fixed v2.69, as covered in a security notice.
What this means

If you used the affected extension version, the safest course is to treat those seed phrases as compromised and use a fresh wallet, then monitor official guidance.

2. Root Cause

Evidence indicates a supply?chain compromise of the publishing pipeline rather than an on?chain or protocol bug.

  1. Trust Wallets report ties the breach to Sha1?Hulud, where leaked GitHub development secrets and the Chrome Web Store API key allowed uploading a malicious extension build, per a post?mortem update.
  2. SlowMist noted the attackers deep familiarity with the extension code, suggesting preparation and insider?level knowledge of the source, as summarized in industry coverage by Finance Magnates.
What this means

Wallet security depends not only on cryptography but also on software distribution and update integrity. Supply?chain hardening and verifiable builds matter.

3. Impact and Response

Losses were about $7 million, with Trust Wallet pledging compensation and moving into a claims verification phase.

  1. The company reported 2,596 affected addresses but nearly 5,000 submissions, requiring careful filtering of false or duplicate claims, per a verification update.
  2. Leadership publicly committed to covering losses while the forensic investigation continues, as confirmed in a security report and echoed in broader coverage by Finance Magnates.
What this means

Expect reimbursement but also delays due to strict ownership verification. Stay vigilant against phishing that imitates official support.

Conclusion

The Trust Wallet exploit was a software supply?chain breach of the Chrome extension release path, enabling seed phrase exfiltration from v2.68 and draining roughly $7 million. The incident highlights operational security around distribution channels as a critical attack surface, with compensation processes underway and a broader post?mortem pointing to leaked credentials and publishing keys.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top