Trust Wallet browser extension was backdoored.



v2.68.0 -> compromised. PostHog script injected. Seed phrases collected. Sent to attacker server.

Timeline:
- Dec 8: Prep started
- Dec 22: Backdoor live
- Dec 25: Funds drained

v2.69.0 is patched. If you're on 2.68.0, move everything. Now.

$6M+ gone. This is why self-custody means nothing without operational security.
post-image
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)