Trust Wallet browser extension vulnerability reported, user funds stolen over $6 million

robot
Abstract generation in progress

On December 25, on-chain detective ZachXBT reported that multiple Trust Wallet users have reported unauthorized fund outflows from their wallet addresses within a few hours. According to preliminary monitoring and comprehensive reports, on-chain tracking shows that hundreds of victims have been affected, with stolen funds totaling at least $6 million so far.

We’ve identified a security incident affecting Trust Wallet Browser Extension version 2.68 only. Users with Browser Extension 2.68 should disable and upgrade to 2.69.

Please refer to the official Chrome Webstore link here: https://t.co/V3vMq31TKb

Please note: Mobile-only users…

— Trust Wallet (@TrustWallet) December 25, 2025

Trust Wallet posted an emergency notice on its official X account, indicating that version 2.68 of its browser extension has a security vulnerability. It is recommended that affected users disable version 2.68 and upgrade to 2.69 via the official Chrome Web Store, and refrain from opening the affected version until the update is complete. Trust Wallet stated that mobile applications and other extension versions are unaffected, and the team is actively investigating. As of the 26th, no compensation details have been announced by the official channels.

Public blockchain analysis by on-chain monitoring agencies shows that funds from many affected addresses are rapidly being transferred to a wallet controlled by the attacker. This pattern is common in cases of compromised extensions or front-end events, where malicious updates or vulnerabilities may lead to unauthorized signature requests or private key leaks. Trust Wallet issued a consultation only after the extension update, which has heightened community concerns about whether version 2.68 introduced or exposed vulnerabilities. During the ongoing investigation, users can take the following practical measures: if you have installed version 2.68, disable the Chrome extension and only upgrade through the official Trust Wallet Chrome Web Store link; transfer remaining funds to a hardware (cold) wallet or create a new wallet through a secure process; check your address’s on-chain activity and report suspicious thefts to Trust Wallet support for investigators to trace the fund flow. Cybersecurity teams note that quick mitigation, careful preservation of evidence (transaction hashes, timestamps, extension version), and coordination with exchanges and blockchain analysts can improve the chances of tracking and potentially freezing stolen assets.

TWT2.38%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)