TLDR
It was the Trust Wallet Chrome browser extension version 2.68, compromised by a malicious update; mobile apps and other extension versions were not affected.
- Only v2.68 was impacted; users were told to disable it and upgrade to v2.69 via the official Chrome Web Store per a security update.
- The breach was a supply?chain style update attack that harvested seed phrases, with details pointing to a leaked Web Store key in a post?incident report.
- Losses were about $67 million and reimbursement was pledged by leadership per a compensation update.
Deep Dive
1. Version Impact
Trust Wallet confirmed the issue affected only the Chrome browser extension v2.68 and advised upgrading to v2.69. Mobile users and other extension versions were explicitly stated as unaffected in a security update.
If you used the extension recently, verify the version number and update through the official store before doing anything with your wallet.
2. Attack Mechanism
Reports describe a supply?chain style malicious update that exfiltrated seed phrases when users unlocked or imported them, consistent with code injection in the extensions update path per a compensation and forensic summary. Additional coverage noted the injected code masqueraded as analytics and was fixed in v2.69 shortly after discovery in a technical recap.
The weak point was the software distribution pipeline, not the blockchain itself. Treat browser extensions as high?risk for seed handling.
3. Losses and Response
Initial losses were tallied at $67 million across BTC, ETH, BNB, and SOL wallets, with a pledge to reimburse verified victims in a leadership statement. A formal claims process was opened for affected users to submit details for review per the compensation update.
If you were impacted, document addresses and transactions and follow the official claims flow; avoid third?party forms or DMs posing as support.
Conclusion
The breach hit the Trust Wallet Chrome extension v2.68 via a malicious update, making seed phrases the immediate attack surface. The team directed users to upgrade to v2.69 and opened reimbursement claims. For future safety, keep significant balances off hot extensions and verify update sources before importing any secrets.
