Need help? Support
BITCOIN
Tether Dominance USDT.D

What caused Trust Wallet extension hack?

Published 479 words 3 min read

TLDR

The Trust Wallet browser extension hack was caused by a malicious update to version 2.68 that inserted code to exfiltrate seed phrases, consistent with a supply chain attack, per a confirmed incident report and security analysis on a malicious v2.68 update.

  1. Only the browser extension v2.68 was affected; users were told to disable it and upgrade to v2.69, while mobile was not impacted (company update).
  2. Losses total about $7 million, and Trust Wallet says affected users will be reimbursed (compensation assurance).
  3. Investigators are probing insider involvement and a compromised release pipeline; an API key leak was suspected but remains unconfirmed (insider role discussion, API key leak claim).

Deep Dive

1. Cause and Scope

The incident was tied to a malicious Chrome extension update (v2.68) that executed stealth code to capture mnemonic phrases when users imported seeds, then sent data to attacker?controlled servers. A patched v2.69 was released and users were urged to upgrade promptly (technical cause summary, upgrade instruction noted).

Affected scope was limited to the extension version 2.68. Reports consistently state mobile users and other extension versions were not impacted, narrowing the blast radius to one compromised release (scope confirmation).

What this means

Browser extensions carry supply chain risk. Treat any wallet where a seed was imported on v2.68 as exposed and follow official guidance to secure funds.

2. Impact and Refunds

Estimated losses range from $67 million, with funds drained across multiple chains within hours of installation. Trust Wallet and leadership pledged full reimbursement to affected users and began organizing the refund process (losses and reimbursement, compensation assurance).

Guidance from the team focused on disabling v2.68, upgrading to v2.69, and avoiding unofficial messages to prevent secondary scams during the refund period (company guidance).

What this means

If you interacted with v2.68 (Dec 2426), prepare documentation and follow the official refund instructions highlighted in the notices above. Be cautious of impersonation scams.

3. Investigation Status

Analysis points to a compromised release pipeline for the Chrome extension. Discussion includes possible insider involvement and claims that a leak of API keys used to publish the plugin may have enabled malicious code injectionthough this remains unconfirmed and under investigation (insider role discussion, API key leak claim).

Security researchers described the attack pattern as classic supply chain: a legitimate update channel delivering hidden data?exfiltration logic under the guise of analytics, triggering mnemonic requests and draining funds shortly after seed import (technical cause summary).

What this means

Root cause is still being finalized. Monitor official Trust Wallet posts and the notice above for technical updates and any changes to remediation steps.

Conclusion

A single compromised Chrome extension build (v2.68) introduced malicious code that harvested seed phrases, leading to rapid multi?chain fund drains. The team limited impact by isolating the affected version, shipping v2.69, and committing reimbursements. The investigation is probing insider or release pipeline compromise scenarios; until confirmed, assume any seed imported on v2.68 is compromised and rely on official instructions from the notice above.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top