TLDR
Trust Wallets Chrome extension (version 2.68) was breached this week, with about $67 million drained and 2,596 addresses impacted; mobile users were not affected and reimbursements were pledged (Trust Wallet update, verification note).
- Trust Wallet extension v2.68 was compromised by malicious code; users were told to upgrade to v2.69 (security coverage).
- Turkish exchange BtcTurk reported a hot?wallet breach on Jan 1, with about $48 million stolen (incident summary).
- Ongoing wallet drains tied to the 2022 LastPass breach continued to surface, highlighting persistent risk to personal wallets (analysis).
Deep Dive
1. Trust Wallet Extension Breach
Trust Wallets desktop Chrome extension v2.68 was compromised via a supply?chain style update that harvested seed phrases and drained funds across BTC, ETH, BNB, and SOL. Trust Wallet confirmed ~$7 million impacted and promised reimbursement for verified victims, while advising users to disable v2.68 and upgrade to v2.69 (update and reimbursement, technical details). Trust Wallet later said 2,596 addresses were affected and flagged nearly 5,000%%CKPROTECTED7%% claims as many were false or duplicates, prioritizing accurate verification before payouts (verification note).
Prefer hardware or multisig storage for meaningful funds, and only install wallet updates from verified links after the team confirms integrity.
2. BtcTurk Hot?Wallet Breach
BtcTurk disclosed a New Years Day hot?wallet compromise, reporting about $48 million stolen. It marks the exchanges third breach since mid?2024, raising questions about recurring security weaknesses and incident response readiness (incident summary).
Exchange hot wallets are operational and inherently exposed. Keep only working capital on exchanges and monitor official incident notices before moving assets.
3. Persistent Drains Linked to LastPass
Investigations this week revisited the LastPass breachs long tail: attackers downloaded vaults and have been cracking weak master passwords over time, leading to ongoing wallet drains and coordinated laundering patterns across high?risk venues (analysis). This underscores non?code risks: seed storage, password hygiene, and off?ramp behavior.
Even without a current wallet software exploit, old vault exposure can still lead to loss. Rotate compromised wallets, strengthen passwords, and avoid reusing recovery phrases.
Conclusion
This weeks breaches centered on Trust Wallets Chrome extension and an exchange hot?wallet incident at BtcTurk, with continuing personal?wallet drains tied to the LastPass fallout. The common thread is operational exposure. If you prioritize self?custody, harden update discipline, favor hardware/multisig for core holdings, and verify official notices before acting.
