Need help? Support
BITCOIN
Tether Dominance USDT.D

What caused Trust Wallet breach?

Published 445 words 3 min read

TLDR

It was caused by a malicious update to Trust Wallets Chrome extension (v2.68) that exfiltrated seed phrases (a supply?chain attack), likely enabled by a leaked Chrome Web Store publishing key per reports from investigators and media (analysis, compensation report).

  1. Impact was limited to Browser Extension v2.68; mobile users were not affected (breach confirmation).
  2. Injected code disguised as analytics harvested seed phrases and drained funds after import (technical details).
  3. The issue was fixed in v2.69 and a reimbursement process for losses around $7 million was launched (compensation update).

Deep Dive

1. Scope and Version

Trust Wallet confirmed the breach affected only its Chrome Browser Extension version 2.68, while mobile and other versions were not impacted. This concentrated the risk to users who updated or used that specific build around 2426 Dec (breach confirmation).

  • Early reports pegged initial losses at over $6 million across hundreds of users, with outflows shortly after the extension update (media summary).
  • Public posts noted exchanges receiving part of the flows as investigators mapped theft addresses (tweet roundup).
What this means

If you did not use v2.68, your exposure was minimal. If you did, treat those wallets as compromised and rotate to new ones.

2. Attack Mechanism

Investigators describe a supply?chain style compromise in which malicious JavaScript, presented as analytics, captured seed phrases when users imported or accessed mnemonics using the extension. Funds were then drained rapidly without further user approvals (technical details).

  • Coverage explains the malicious update to v2.68 and the seed?harvesting behavior consistent with a supply?chain exploit (analysis).
  • Some reports suggest the publishing path was abused via leaked keys tied to the Chrome Web Store API, enabling the rogue update to be distributed (compensation report).
What this means

Browser extensions increase attack surface. Avoid entering seed phrases into hot software and prefer hardware wallets or multisig for larger balances.

3. Fix and Compensation

Trust Wallet shipped a fixed extension (v2.69) and opened a compensation workflow. Public statements put losses at roughly $7 million, with guidance to update and submit claims through official channels (compensation update).

  • A detailed victim process and security cautions were shared, emphasizing no seeds or passwords should be requested in legitimate claims (technical details).
  • Coverage noted the patch release and ongoing investigation into how a malicious version was submitted (media summary).
What this means

The immediate operational risk is mitigated in v2.69, but best practice is to rotate to a fresh wallet and re?establish approvals from a clean environment.

Conclusion

The breach stemmed from a compromised Chrome extension release that captured seed phrases and drained funds. The fix and reimbursement are in motion, yet the episode underscores a broader trade?off: browser convenience versus security. For sizable holdings, lean toward hardware wallets and avoid entering seeds into extensions.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top