{"id":9508,"date":"2025-12-27T10:03:38","date_gmt":"2025-12-27T10:03:38","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/27\/trustwallet-chrome-extension-hacked-users-reporting-millions-in-losses\/"},"modified":"2025-12-27T10:03:38","modified_gmt":"2025-12-27T10:03:38","slug":"trustwallet-chrome-extension-hacked-users-reporting-millions-in-losses","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/27\/trustwallet-chrome-extension-hacked-users-reporting-millions-in-losses\/","title":{"rendered":"TrustWallet Chrome Extension Hacked \u2013 Users Reporting Millions in Losses"},"content":{"rendered":"<p>    TrustWallet Chrome Extension Hacked \u2013 Users Reporting Millions in Losses<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Many Trust Wallet users saw their wallets drained of over $7 million after a security breach in the Chrome browser extension version 2.68.0, released on December 24, 2025.<\/p>\n<p>Blockchain investigator ZachXBT first <a href=\"https:\/\/x.com\/Cointelegraph\/status\/2004341548784177364\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">flagged<\/a> the incident on X, noting a surge in unauthorized outflows from affected addresses shortly after users interacted with the extension.\u200b<\/p>\n<p>Reports emerged on Christmas Eve, with victims sharing screenshots of emptied portfolios, including significant holdings in ETH, BTC, SOL, and BNB.<\/p>\n<p>One user claimed a $300,000 loss in minutes after simple authorization, with transactions funneled to multiple attacker-controlled addresses. PeckShield estimated initial losses at $6 million; Trust Wallet later confirmed approximately $7 million across hundreds of wallets.\u200b<\/p>\n<p>The attack coincided with the Chrome Web Store extension update, affecting desktop users but sparing the mobile app. Security firm SlowMist issued an alert, describing a potential\u00a0<a href=\"https:\/\/cybersecuritynews.com\/supply-chain-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">supply-chain\u00a0compromise<\/a> in which malicious code was injected upstream.\u200b<\/p>\n<h2 class=\"wp-block-heading\" id=\"malicious-code-exposed\"><strong>Malicious Code Exposed<\/strong><\/h2>\n<p>Researchers examined a compromised bundle and found a JavaScript file named 4482.js that was masquerading as PostHog analytics. The obfuscated script activated on seed phrase import, silently exfiltrating sensitive wallet data, including recovery phrases, to api.metrics-trustwallet.com, a domain registered days earlier and mimicking official branding.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">So here\u2019s what\u2019s happening  :<\/p>\n<p>In the Trust Wallet browser extension code 4482.js<br \/>a recent update added hidden code that silently sends wallet data outside<br \/>It pretends to be analytics, but it tracks wallet activity and triggers when a seed phrase is imported<br \/>The data was sent to\u2026 <a href=\"https:\/\/t.co\/8kkMUkDYql\">pic.twitter.com\/8kkMUkDYql<\/a><\/p>\n<p>\u2014 Akinator | Testnet Arc (@0xakinator) <a href=\"https:\/\/twitter.com\/0xakinator\/status\/2004297673067704651?ref_src=twsrc%5Etfw\">December 25, 2025<\/a>\n<\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div>\n<\/div>\n<\/figure>\n<p>Public WHOIS records confirmed its novelty, with no ties to legitimate Trust Wallet infrastructure.\u200b<\/p>\n<p>Attacker sophistication extended to parallel phishing: domains like fix-trustwallet.com lured panicked users with fake \u201cvulnerability fixes,\u201d prompting seed phrase entry for instant drains. The shared registrar across phishing sites suggests coordinated operations.\u200b<\/p>\n<p>Trust Wallet acknowledged the breach on December 25 via X, isolated it to version 2.68.0, and urged immediate disablement. Users must navigate to chrome:\/\/extensions\/?id=egjidjbpglichdcondbcbdnbeeppgdph, toggle off, enable developer mode, and update to v2.69, the sole safe iteration.\u200b<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">We\u2019ve identified a security incident affecting Trust Wallet Browser Extension version 2.68 only. Users with Browser Extension 2.68 should disable and upgrade to 2.69.<\/p>\n<p>Please refer to the official Chrome Webstore link here: <a href=\"https:\/\/t.co\/V3vMq31TKb\">https:\/\/t.co\/V3vMq31TKb<\/a><\/p>\n<p>Please note: Mobile-only users\u2026<\/p>\n<p>\u2014 Trust Wallet (@TrustWallet) <a href=\"https:\/\/twitter.com\/TrustWallet\/status\/2004316503701958786?ref_src=twsrc%5Etfw\">December 25, 2025<\/a>\n<\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div>\n<\/div>\n<\/figure>\n<p>The team pledged full refunds to affected users, prioritized support outreach, and warned against unofficial DMs. Binance co-founder Changpeng Zhao hinted at possible insider involvement, amplifying scrutiny on the <a href=\"https:\/\/cybersecuritynews.com\/category\/acquisition\/\" target=\"_blank\" rel=\"noreferrer noopener\">acquisition<\/a>-owned wallet.\u200b<\/p>\n<p>This breach underscores supply-chain perils in crypto extensions, where auto-updates bypass user scrutiny. Affected chains span EVM, Bitcoin, and Solana, with stolen funds laundered via mixers.<\/p>\n<p>Cybersecurity experts recommend using new wallets for potentially exposed seeds and verifying updates vigilantly. As investigations continue, Trust Wallet\u2019s refund process will test user trust amid 2025\u2019s $3 billion in hacking losses.\u200b<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/trustwallet-chrome-extension-hacked\/\">TrustWallet Chrome Extension Hacked \u2013 Users Reporting Millions in Losses<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/trustwallet-chrome-extension-hacked\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>TrustWallet Chrome Extension Hacked \u2013 Users Reporting Millions in Losses Many Trust Wallet users saw their wallets drained of over $7 million after a security breach in the Chrome browser extension version 2.68.0, released on December 24, 2025. Blockchain investigator ZachXBT first flagged the incident on X, noting a surge in unauthorized outflows from affected [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1636,129,63],"tags":[130],"class_list":["post-9508","post","type-post","status-publish","format-standard","hentry","category-cyber-attack-news","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9508"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9508"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9508\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9508"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9508"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9508"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}