Need help? Support
BITCOIN
Tether Dominance USDT.D

Which wallets faced breaches this week?

Published 462 words 3 min read

TLDR

Two high?profile wallet issues reported this week: Trust Wallets Chrome extension incident (with a post?mortem and reimbursements underway) and an ongoing cross?chain campaign draining small sums from many EVM wallets.

  1. Trust Wallet (extension v2.68): supply?chain compromise confirmed; about $7 million impacted, with a post?mortem and user updates this week (post?mortem details).
  2. EVM wallets drained: hundreds of self?custody wallets on Ethereum?compatible chains hit for under $2,000 each, losses >$107,000 and rising (investigator alert).

Deep Dive

1. Trust Wallet Extension

Trust Wallet (a self?custody wallet) traced its December browser?extension breach to a supply?chain incident and published a post?mortem update this week.

  1. The breach involved a malicious Chrome extension release (v2.68) following a Sha1?Hulud npm compromise that exposed developer secrets and allowed a rogue upload. Affected users were those who logged in Dec 2426 (post?mortem).
  2. Reported impact is about $7 million. The team has been verifying claims and coordinating reimbursements, with process and status updates continuing this week (see the notice above).
  3. Only the Chrome extension was affected; the mobile app was not. Investigators noted the attackers deep familiarity with the code, and the firm continues forensic work (see the post?mortem above).
What this means

If you used the Chrome extension around the affected window, rotate to a new wallet, and follow the official reimbursement instructions only via the page above.

2. Cross?Chain EVM Wallet Drains

A separate, active campaign is draining many small balances from self?custody wallets across EVM chains (EVM means Ethereum?compatible networks).

  1. Investigators reported hundreds of wallets hit across Ethereum, BNB Chain, Base and others, typically under $2,000 each, with cumulative losses already above $107,000 and growing (ongoing report).
  2. The root cause is still unconfirmed. Hypotheses include malicious approvals, deceptive signature prompts, or extension?layer issues. A consolidation address has been flagged in multiple reports (supplemental analysis).
  3. This pattern mirrors recent wallet?layer incidents and highlights operational risks in hot wallets and browser extensions, even without a single protocol exploit (see the report above).
What this means

For any EVM wallet with recent dapp interactions, review and revoke token approvals, rotate to fresh keys on a clean device, and monitor for unusual small transfers.

Risk note: Low per?wallet thefts can slip past detection, and thin liquidity pairs can make recovery harder. Small persistent drains often add up before users notice.

Conclusion

This weeks wallet headlines point to two vectors: a confirmed supply?chain compromise at a major wallet extension and an unresolved cross?chain drainer targeting many small EVM wallets. The immediate takeaway is operational. Browser?extension hot wallets carry elevated risk, and broad approval surfaces on EVM chains create attack paths. Tighten wallet hygiene now (fresh keys, approval revokes, clean extensions) and rely only on the official pages linked above for updates and any reimbursement pathways.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top