Trust Wallet Chrome Extension Breach Drains $7M; Update Now!

Trust Wallet Chrome extension hack stole ~$7M by exfiltrating decrypted mnemonics via PostHog — users urged to update to 2.69 and will be refunded.

  • Trust Wallet Chrome extension version 2.68 contained malicious code that led to roughly $7 million in stolen crypto.
  • The extension’s developer urged users to update immediately to version 2.69 and said affected users will be refunded, according to company posts.
  • Security firm SlowMist says the attacker exfiltrated decrypted mnemonic phrases to an attacker server using the open-source analytics library PostHog.
  • About $3 million in Bitcoin and over $3 million in Ethereum were taken; substantial sums were sent to centralized exchanges and bridges, per PeckShield.

Trust Wallet told users on its official account that a security incident in its Google Chrome extension version 2.68 led to losses of about $7 million and urged an immediate update to version 2.69, per the company post on X. The extension has roughly one million users listed in the Chrome Web Store.

- Advertisement -

SlowMist analyzed the code and reported that the malicious change iterated through stored wallets, requested each wallet’s mnemonic phrase, decrypted it after wallet unlock, and sent it to the attacker server. “The encrypted mnemonic is then decrypted using the password or passkeyPassword entered during wallet unlock,” the firm wrote on X. The attacker routed data through an attacker-controlled analytics endpoint api.metrics-trustwallet[.]com and used the PostHog analytics library as the exfiltration channel.

A mnemonic phrase is a sequence of words that can restore a cryptocurrency wallet. An analytics library is a software tool that collects usage data. A cross-chain bridge is a service that moves assets between blockchains. A centralized exchange (CEX) is a crypto trading platform that holds user assets.

Stolen funds include about $3 million in Bitcoin, $431 in Solana, and more than $3 million in Ethereum. PeckShield reported that roughly $2.8 million remains in Hacker wallets while over $4 million moved to CEXs: about $3.3 million to ChangeNOW, $340,000 to FixedFloat, and $447,000 to KuCoin. The transfers were routed through exchanges and bridges, and investigators say hundreds of users were affected, as reported by blockchain investigator ZachXBT.

Trust Wallet stated on its account that it will refund impacted users and advised users not to interact with messages outside official channels. Mobile users and other browser extension versions are not affected. Binance co‑founder Changpeng Zhao hinted the exploit was “most likely” carried out by an insider.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Tudou Guarantee winds down after $12B crypto scam ties + AI.

Tudou Guarantee, a Telegram-based guarantee marketplace, has largely stopped transacting through its public groups...

Institutions Bet on Ethereum as Wall Street’s Token Hub Rise

Major institutions are launching tokenization and settlement projects on the Ethereum blockchain.Kraken launched tokenized...

Silver’s rally reignites debate: Bitcoin vs. precious metals

Silver reached a record spot price near $94 per ounce on Monday.Gold climbed to...

Satoshi-era 909 BTC wallet wakes after 13 years, moves $85M.

A Satoshi‑era wallet transferred its full balance of 909.38 BTC—about $84.6 million—after 13 years...

Cardano Volatility Fuels Comeback Hopes After Hoskinson Buzz

Cardano (ADA) trades at $0.36, up 2% in the last 24 hours, after sharp...
- Advertisement -

Must Read

Forex Trading Vs Crypto Trading: Which One Should You Choose?

So you're trying to decide between two types of trading: Forex and cryptocurrency.Forex trading is the big player in the trading world, with lots...
Bitcoin (BTC) $ 90,870.00 2.26%
Ethereum (ETH) $ 3,093.00 3.62%
XRP (XRP) $ 1.93 2.41%
Bittensor (TAO) $ 241.03 3.83%
Polkadot (DOT) $ 1.99 0.06%
Cardano (ADA) $ 0.358721 2.84%
Chainlink (LINK) $ 12.53 1.97%
Hyperliquid (HYPE) $ 23.11 3.94%
Monero (XMR) $ 587.97 8.59%
Hedera (HBAR) $ 0.107128 2.19%
Toncoin (TON) $ 1.56 3.73%