TLDR
Trust Wallet pushed a fixed browser extension, started reimbursements, and tightened its release process after the Chrome extension breach.
- A malicious v2.68 update was removed and a v2.69 fix shipped; mobile apps were unaffected per a report.
- A formal compensation process began, with about $7 million in losses to be reimbursed per an update.
- Security hardening included a forensic probe, Chrome audit requests, and in?product alerts to flag compromised wallets per a CEO update.
Deep Dive
1. Patch And Impact Scope
Trust Wallet identified the incident as a supply?chain style compromise in browser extension v2.68 and pushed v2.69, stating other versions and mobile were not affected. The malicious code exfiltrated seed phrases and led to rapid wallet drains, prompting an immediate upgrade advisory per a report.
If you used the affected extension, treating the wallet as compromised and migrating to a fresh seed can reduce residual risk.
2. Compensation And Verification
Trust Wallet opened a claims portal and committed to reimburse impacted users, with losses around $7 million across BTC, ETH, BNB, and SOL per an update. The team entered a verification phase to filter duplicates and false submissions before payouts, prioritizing accuracy over speed per coverage.
Reimbursement is underway but may take longer due to verification; monitor official updates and ignore unofficial claim links.
3. Security Hardening And Root Cause
Early findings pointed to a leaked Chrome Web Store API key used to publish the malicious v2.68 build and bypass internal release steps per an update. The CEO said the team requested audit logs from Google, is analyzing devices used by remote staff, and added in?product alerts to detect compromised wallets per a CEO update.
Expect more process changes around build integrity and distribution; browser extensions remain a higher?risk surface than hardware or multisig setups.
Conclusion
Post?breach, Trust Wallet contained the attack with a v2.69 fix, began reimbursing users, and moved to tighten its build and distribution controls. The episode underscores that browser extensions are a prime attack surface; operational safeguards and wallet hygiene matter as much as patches and compensation.
