The popular cryptocurrency wallet, Trust Wallet, encountered a significant security crisis immediately following the transition to version 2.68.0 of its Chrome browser extension. User experiences shared on social media revealed instances where wallets entering their seed phrases on the new version were completely drained within minutes. Preliminary analyses indicate that the attack targeted Bitcoin, Ethereum, and BNB balances, potentially resulting in multi-million-dollar losses. These events have reignited discussions about the security of browser extension-based wallets.
window.lazyLoadOptions=Object.assign({},{threshold:300},window.lazyLoadOptions||{});!function(t,e){"object"==typeof exports&&"undefined"!=typeof module?module.exports=e():"function"==typeof define&&define.amd?define(e):(t="undefined"!=typeof globalThis?globalThis:t||self).LazyLoad=e()}(this,function(){"use strict";function e(){return(e=Object.assign||function(t){for(var e=1;eUnusual Blockchain Transfers Detected
Following the incident, blockchain researcher ZachXBT, known for tracking activities within the Blockchain, identified unusual transfers from many Trust Wallet addresses in a short period. Shared data revealed successive transactions post-update, transferring balances to different addresses within seconds.
Interestingly, the funds were not moved piece by piece but rather aggressively in a single motion. Bitcoin, Ethereum, and BNB assets were quickly cleared out in each instance, after which the funds were distributed to multiple intermediary addresses. Repeated redirect patterns observed within the blockchain transactions bolstered the possibility of a coordinated attack.
Claims of Losses Exceeding $4.3 Million
Current blockchain data associates at least $4.3 million worth of cryptocurrency with suspicious addresses. However, this figure is based solely on publicly available data and reported wallets, suggesting the actual losses could be higher. ZachXBT shared principal addresses where funds were compiled, emphasizing that these addresses withdrew assets from many compromised wallets and exhibited similar transaction patterns.
In response to these developments, the Trust Wallet team released an official statement on December 26, 2025, via X, highlighting that the issue stemmed from a security vulnerability affecting only the Trust Wallet Browser Extension 2.68 version. Users were advised to immediately disable the extension and upgrade to version 2.69. The team acknowledged the gravity of the situation and assured that an active investigation is ongoing.


