Need help? Support
BITCOIN
Tether Dominance USDT.D

Which wallets were exploited this week?

Published 371 words 2 min read

TLDR

This weeks confirmed wallet exploits were Trust Wallets Chrome extension v2.68 and a third?party login flow affecting some Polymarket accounts.

  1. Trust Wallet browser extension v2.68 was compromised, with roughly $67 million drained across chains; users were told to update to v2.69 and reimbursements are underway per a verification phase update here.
  2. Polymarket saw a limited number of accounts drained due to a vulnerability at a third?party authentication provider; core protocol was not breached per a report here.

Deep Dive

1. Trust Wallet Extension

Trust Wallets desktop browser extension v2.68 suffered a targeted supply?chain style compromise that harvested seed phrases and drained funds. Investigators and the team put losses near $7 million and identified thousands of potentially affected addresses, with a formal reimbursement verification process now active per this update.

Forensics point to malicious JavaScript embedded in the v2.68 extension that transmitted wallet secrets, prompting an emergency v2.69 release and the request that users not use the compromised version again, as covered in a technical write?up here.

What this means

Browser extensions expand the attack surface. For meaningful balances, consider segregating storage to hardware or multisig, and avoid importing seed phrases into browser extensions after incidents.

2. Polymarket Third?Party Login

Polymarket disclosed that a third?party authentication provider was exploited, allowing unauthorized access to some user accounts and USDC drains. The platform emphasized its core smart contracts were unaffected and stated the vulnerability was isolated to the external auth layer, according to a detailed report here.

This type of incident underscores that convenience logins can become weak links, even when a protocols on?chain logic remains intact. It follows earlier phishing campaigns and highlights the need to scrutinize integrated vendors.

What this means

If you use email or magic link style logins, treat them as semi?custodial risk points. Prefer stronger isolation for funds and monitor vendor security updates closely.

Conclusion

The main wallet exploit this week was the Trust Wallet Chrome extension v2.68, with losses around $67 million and a verification?based reimbursement process in progress. A separate incident at Polymarket shows third?party authentication can be a failure point even when a protocol is sound. The shared lesson is to minimize hot?extension exposure for seed phrases and treat external integrations as material security dependencies.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top