Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Silver Fox targets Indian users with tax-themed emails delivering ValleyRAT malware

Can we bring American infrastructure into the modern era?

How to integrate AI into modern SOC workflows

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Trust Wallet Chrome Extension Compromise Causes $7M in Cryptocurrency Loss due to Malicious Code
Identity

Trust Wallet Chrome Extension Compromise Causes $7M in Cryptocurrency Loss due to Malicious Code

userBy userDecember 26, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

December 26, 2025Ravi LakshmananCryptocurrency/Incident Response

TrustWallet is urging users to update their Google Chrome extension to the latest version following what it calls a “security incident” that resulted in approximately $7 million in losses.

The issue affects version 2.68, according to the multichain non-custodial cryptocurrency wallet service. According to the Chrome Web Store listing, the extension has around 1 million users. We recommend users update to version 2.69 as soon as possible.

“We have confirmed that approximately $7 million has been affected and will ensure that all affected users are refunded,” Trust Wallet said in a post on X. “Supporting affected users is our top priority and we are actively finalizing refund procedures for affected users.”

Trust Wallet also urges users to refrain from interacting with messages other than those sent from official channels. Mobile-only users and all other browser extension versions are not affected.

cyber security

According to details shared by SlowMist, version 2.68 introduced malicious code designed to iterate through all wallets stored in the extension and trigger a mnemonic phrase request for each wallet.

“The encrypted mnemonic will be decrypted using the password or passkeyPassword entered when unlocking the wallet,” the blockchain security firm said. “Once decrypted, the mnemonic phrase is sent to the attacker’s server api.metrics-trustwallet.[.]com”

Domain “metrics-trustwallet”[.]com’ was registered on December 8, 2025, and the first request to ‘api.metrics-trustwallet’ was made.[.]com” will start on December 21, 2025.

Further analysis revealed that the attacker leveraged an open source full-chain analysis library named posthog-js to collect wallet user information.

The digital assets leaked so far include approximately $3 million in Bitcoin, $431 in Solana, and more than $3 million in Ethereum. The stolen funds were moved through centralized exchanges and cross-chain bridges for money laundering and swaps. According to the latest information shared by blockchain researcher ZachXBT, the incident resulted in hundreds of victims.

“Approximately $2.8 million of the stolen funds remain in the hackers’ wallets (Bitcoin/EVM/Solana), but the majority of them, over $4 million in cryptocurrencies, were transferred to CEX. [centralized exchanges]: About $3.3 million for ChangeNOW, about $340,000 for FixedFloat, and about $447,000 for KuCoin,” Peckshield said.

“This backdoor incident resulted from a malicious source code modification within Trust Wallet’s internal extension codebase (analytics logic), rather than an injected compromised third-party dependency (such as a malicious npm package),” SlowMist said.

cyber security

“The attackers directly modified the application’s own code, leveraged the legitimate PostHog analytics library as a data extraction channel, and redirected the analytics traffic to attacker-controlled servers.”

The company said the attack could be the work of a nation-state attacker, adding that the attacker may have gained control of, or permission to deploy, Trust Wallet-related developer devices before December 8, 2025.

Changpeng Chao, co-founder of the cryptocurrency exchange Binance, which owns the utility, hinted that the exploit was “most likely” carried out by an insider, although no further evidence was provided to support this theory.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous Article9 Top Cybersecurity Startups in Disrupt Startup Battlefield
Next Article Treat yourself: The best smart glasses to buy with your holiday gift money
user
  • Website

Related Posts

Silver Fox targets Indian users with tax-themed emails delivering ValleyRAT malware

December 30, 2025

How to integrate AI into modern SOC workflows

December 30, 2025

Mustang Panda uses signed kernel-mode rootkit to load TONESHELL backdoor

December 30, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Silver Fox targets Indian users with tax-themed emails delivering ValleyRAT malware

Can we bring American infrastructure into the modern era?

How to integrate AI into modern SOC workflows

The year AI moves from experimentation to execution

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.