Trust Wallet Hack
What happened
A malicious Trust Wallet Browser Extension v2.68 was published on December 24, 2025. Trust Wallet identified 2,520 drained addresses and approximately $8.5 million in affected assets. Its report limits exposure to affected extension logins during December 24-26; the mobile app was outside that scope.
The compromised publishing credential bypassed internal release controls. Trust Wallet considered the November Sha1-Hulud supply-chain incident the likely source of access, rather than a fully concluded forensic finding.
Case & protocol details
How it happened
- Trust Wallet's investigation linked the incident to exposed developer secrets and a leaked Chrome Web Store API key, while describing the initial sequence as still under investigation.
- The attacker published a tampered extension outside Trust Wallet's internal review process.
- Malicious code accessed sensitive wallet data when affected users logged in, enabling unauthorized transactions.
- Trust Wallet replaced the extension with clean version 2.69, disabled publishing credentials and opened reimbursement claims. Its July 2026 update said claim reviews continued.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
- analysis Website reference x.com
- analysis Website reference x.com
- analysis Trust Wallet Browser Extension v2.68 Incident: An Update to Our Community trustwallet.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.