Trust Wallet Hack: $7 Million Stolen in Christmas Exploit

TLDR

  • Trust Wallet was hacked on Christmas Day
  • The malicious actor walked away with around $7 million.
  • All signs point toward an inside job.
  • Trust Wallet has already developed a compensation plan for victims.

On Christmas Day, as the world unwrapped gifts and celebrated with family, a nightmare scenario unfolded for hundreds of cryptocurrency investors. Trust Wallet, a major player in the digital asset storage space with over 70 million users, confirmed a security breach affecting its browser extension.

The attack, which security experts believe had been in the planning stages since early December, resulted in the theft of approximately $7 million in digital assets. The incident was contained to a specific version of the desktop browser extension.

For those new to the crypto space, incidents like this can be alarming. However, understanding exactly what happened, how the company is responding, and who was actually affected is crucial for navigating the digital asset landscape safely. Let’s get after it.

The Christmas Day Cyberattack

The incident first came to light when on-chain investigator ZachXBT issued an alert on Telegram on December 25. He warned that multiple users had reported that their funds had been drained shortly after updating their Trust Wallet extension.

Trust Wallet subsequently confirmed that their browser extension, specifically version 2.68, had been compromised. According to the company’s investigation, a malicious actor injected code into the update. This code was designed to harvest wallet seed phrases — the master keys to a user’s cryptocurrency — and send them back to the attacker’s server.

The timing has been calculated for maximum damage. By deploying the exploit during the holidays, the attackers likely hoped for a slower response time from security teams and users alike.

The Timeline of the Breach

Security firm SlowMist and Trust Wallet’s internal investigation have pieced together a timeline that suggests a patient and premeditated attack:

  • December 8: The attacker likely began preparations for the exploit.
  • December 24 (12:32 p.m. UTC): The compromised version (2.68) was published to the Chrome Web Store. The investigation revealed that a leaked Chrome Web Store API key was used to bypass Trust Wallet’s standard internal release process.
  • December 25: As users’ extensions updated automatically, the malicious code began harvesting seed phrases, and funds began moving out of victim wallets.
  • December 25: Trust Wallet identified the breach and pushed a fix (version 2.69) to stop the bleeding.

The Financial Impact

The breach resulted in a loss of approximately $7 million across multiple blockchains, including Bitcoin, Ethereum, and Solana. While this figure is significant, it is notably smaller than some of the industry’s largest hacks.

According to blockchain security firm PeckShield, the attackers wasted no time in attempting to launder the stolen funds. More than $4 million has already been moved through centralized exchanges like ChangeNOW, FixedFloat, and KuCoin. According to the latest reports, approximately $2.8 million remains in the attacker’s wallets.

Source

Who Was Affected?

It is important to clarify that the vast majority of Trust Wallet users were safe. The exploit was strictly limited to:

  • Users of the Browser Extension.
  • Specifically, those using version 2.68.
  • Users who logged into the extension between Dec 24 and Dec 26.

Users of the Trust Wallet mobile app — which constitutes the bulk of their user base — were not impacted by this vulnerability. Additionally, users running older or newer versions of the browser extension were safe from this specific attack vector.

Insider Threat Suspicions

One of the more unsettling aspects of this breach is the method of entry. The use of a valid API key to upload the compromised version directly to the Google Chrome Web Store has led industry experts to suspect insider involvement.

Changpeng Zhao (CZ), the founder of Binance (which acquired Trust Wallet in 2018), stated that an insider job was “most likely.” 

Source

The ability to bypass internal checks and push an update suggests the attacker had privileged access or had successfully compromised an employee with high-level permissions.

Trust Wallet’s Response and Compensation

In the wake of the exploit, Trust Wallet has moved to contain the damage and reassure its user base. Two days after the malicious code was discovered, the company announced a formal compensation process.

The Reimbursement Plan

Trust Wallet has pledged to cover 100% of eligible victims’ losses.

“We are working around the clock to finalize the compensation process details, and each case requires careful verification to ensure accuracy and security,” the company stated.

To support this, Changpeng Zhao confirmed Binance’s backing of the reimbursement, stating, “TrustWallet will cover,” and adding that user funds “are SAFU” — a popular crypto acronym standing for “Secure Asset Fund for Users,” implying funds are safe and backed by insurance or reserves.

Affected users have been directed to a dedicated support form where they must provide:

  • Email address
  • Country of residence
  • Compromised wallet addresses
  • Attacker’s receiving addresses
  • Transaction hashes

This verification process is a standard procedure to ensure that claims are legitimate and to prevent secondary fraud attempts.

Security Lessons for New Investors

For those new to cryptocurrency, headlines about “hacks” and “exploits” can be intimidating. However, analyzing these events provides valuable lessons on how to better secure digital assets.

Browser Extensions vs. Cold Storage

Browser extensions are “hot wallets,” meaning they are always connected to the internet. This makes them convenient for daily trading and interacting with Web3 applications, but it also increases their exposure to attacks.

For storing significant amounts of value, Dypto Crypto recommends “cold storage” or hardware wallets (like Trezor or Ledger). These devices keep your seed phrase offline, making it impossible for a remote browser exploit to harvest your keys.

The Importance of Updates

While this specific incident was triggered by a malicious update, in 99% of cases, keeping software outdated is a bigger risk. Generally, users should update their apps to benefit from the latest security patches. In this unique instance, Trust Wallet urged users to immediately upgrade to version 2.69 or higher to remove the compromised code.

Moving Forward

As the crypto industry matures, security remains a cat-and-mouse game between developers and malicious actors. The Trust Wallet hack serves as a stark reminder that even established platforms are not immune to vulnerabilities, particularly those involving supply chain attacks or insider threats.

For the victims, the promise of full compensation is a relief that is all too rare in the crypto world. For the broader community, it highlights the importance of diversifying storage methods — keeping spending money in convenient hot wallets while securing long-term savings in cold storage.

Trust Wallet has stated that it will remain in close contact with victims as it processes claims. Users are advised to only follow instructions from official Trust Wallet communication channels to avoid falling prey to phishing scams targeting victims of the hack.

Disclaimer

This article is for educational and information purposes, and should not be considered financial advice. For more information visit our disclaimer page

About the Author

Countdown to next draw

days

hours

minutes

seconds