Need help? Support
BITCOIN
Tether Dominance USDT.D

Which extension breach hit Trust Wallet?

Published 343 words 2 min read

TLDR

It was the Trust Wallet Chrome browser extension version 2.68, compromised by a malicious update; mobile apps and other extension versions were not affected.

  1. Only v2.68 was impacted; users were told to disable it and upgrade to v2.69 via the official Chrome Web Store per a security update.
  2. The breach was a supply?chain style update attack that harvested seed phrases, with details pointing to a leaked Web Store key in a post?incident report.
  3. Losses were about $67 million and reimbursement was pledged by leadership per a compensation update.

Deep Dive

1. Version Impact

Trust Wallet confirmed the issue affected only the Chrome browser extension v2.68 and advised upgrading to v2.69. Mobile users and other extension versions were explicitly stated as unaffected in a security update.

What this means

If you used the extension recently, verify the version number and update through the official store before doing anything with your wallet.

2. Attack Mechanism

Reports describe a supply?chain style malicious update that exfiltrated seed phrases when users unlocked or imported them, consistent with code injection in the extensions update path per a compensation and forensic summary. Additional coverage noted the injected code masqueraded as analytics and was fixed in v2.69 shortly after discovery in a technical recap.

What this means

The weak point was the software distribution pipeline, not the blockchain itself. Treat browser extensions as high?risk for seed handling.

3. Losses and Response

Initial losses were tallied at $67 million across BTC, ETH, BNB, and SOL wallets, with a pledge to reimburse verified victims in a leadership statement. A formal claims process was opened for affected users to submit details for review per the compensation update.

What this means

If you were impacted, document addresses and transactions and follow the official claims flow; avoid third?party forms or DMs posing as support.

Conclusion

The breach hit the Trust Wallet Chrome extension v2.68 via a malicious update, making seed phrases the immediate attack surface. The team directed users to upgrade to v2.69 and opened reimbursement claims. For future safety, keep significant balances off hot extensions and verify update sources before importing any secrets.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top