• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
CoinLaw LogoCoinLaw

Bringing Crypto and Finance Closer to You

  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
CoinLaw Logo
  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
Home » Cryptocurrency

Trust Wallet Hack Hits Hundreds, $7 Million Stolen in Browser Extension Breach

Published on: December 26, 2025
Kelvin Scott
Written By
Kelvin Scott
Kelvin Scott
Finance News Analyst • 484 Articles
Kelvin Scott, with over 8 years of experience, covers the latest trends in digital assets, financial markets, and regulatory developments. W... See full bio
LATEST POSTS:
SK Hynix Becomes Korea’s Most Valuable Company in AI Era
South Korea Seeks Tougher FATF Crypto Travel Rules
UK Stablecoin Market Gets Boost as BoE Drops Holding Caps
Trust Wallet Hacked Through Vulnerable Chrome Extension
As Featured In
Bloomberg LogoForbes LogoFortune LogoCoinDesk LogoCoinMarketCap Logo
Share on LinkedIn ChatGPT Perplexity Share on X Share on Facebook

Hundreds of Trust Wallet users have been hit by a devastating security breach that drained a total of $7 million in crypto assets due to a compromised browser extension update.

Key Takeaways

  • Version 2.68 of the Trust Wallet Chrome extension was infected with malicious code that stole users’ seed phrases.
  • The exploit resulted in losses of over $7 million, mostly in SOL, EVM tokens, and BTC.
  • Trust Wallet urged users to upgrade to version 2.69 immediately to prevent further losses.
  • Binance founder Changpeng Zhao confirmed all affected users will be fully compensated.

What Happened?

A supply chain attack on Trust Wallet’s browser extension version 2.68 allowed hackers to siphon millions in digital assets by tricking users into entering their seed phrases into a compromised interface. Once entered, funds were swiftly transferred to unknown wallets. The breach impacted hundreds of users and occurred during the holiday season, intensifying frustration and losses.

We’ve identified a security incident affecting Trust Wallet Browser Extension version 2.68 only. Users with Browser Extension 2.68 should disable and upgrade to 2.69.

Please refer to the official Chrome Webstore link here: https://t.co/V3vMq31TKb

Please note: Mobile-only users…

— Trust Wallet (@TrustWallet) December 25, 2025

A Coordinated Supply Chain Attack

The attack was first flagged by blockchain investigator ZachXBT, who identified a sudden wave of wallet drains. Cybersecurity researcher Akinator traced the source to malicious code hidden in the latest Chrome extension update. This code secretly redirected seed phrase data to a phishing domain, metrics-trustwallet․com, which has since been taken offline.

  • The rogue version, 2.68, was released on December 24, 2025.
  • Once a seed phrase was entered, funds were automatically stolen in minutes.
  • Over 40% of stolen funds were in SOL, followed by 35% in EVM tokens and 25% in BTC.

Only users of the affected browser extension were impacted. Trust Wallet mobile apps remained secure.

Binance and Trust Wallet Respond

Trust Wallet developers quickly issued version 2.69 and advised all users to immediately disable the compromised version. A guide was published to help users update safely. Binance founder and Trust Wallet owner Changpeng Zhao (CZ) posted on X:

So far, $7m affected by this hack. @TrustWallet will cover. User funds are SAFU. Appreciate your understanding for any inconveniences caused. 🙏

The team is still investigating how hackers were able to submit a new version. https://t.co/xdPGwwDU8b

— CZ 🔶 BNB (@cz_binance) December 26, 2025

He also confirmed that all affected users will be fully reimbursed.

Meanwhile, analytics group Lookonchain tracked $4.2 million of the stolen funds already moving through crypto exchanges including ChangeNOW, FixedFloat, KuCoin, and HTX.

Newsletter Img
Don't chase the news. Let us curate it.

You get one weekly briefing with only the stories that matter. If the market is quiet, we skip it.

✅ Join readers from Visa, Vanguard, and the FDIC.

Larger Security Concerns in Crypto

This breach arrives in the wake of several crypto security issues:

  • Earlier this month, Polymarket faced account breaches due to a third-party vulnerability.
  • On Christmas Day, Binance saw a flash crash of BTC-USD1 to $24,000 due to issues with the USD1 stablecoin, tied to World Liberty Financial, which has links to the Trump family.
  • Chainalysis reports that hackers have stolen over $3.4 billion in crypto so far in 2025.

Experts like Vladimir S. described the Trust Wallet incident as a supply chain attack, stressing the need for wallet developers to maintain tighter control over software updates.

CoinLaw’s Takeaway

Honestly, this kind of exploit makes me double down on my own crypto security habits. In my experience, browser extensions are a weak link in crypto custody. This breach is a wake-up call. I’ve always recommended using hardware wallets for storing significant amounts, and this only reinforces that. Trust Wallet’s fast response and CZ’s commitment to compensation are good signs, but it doesn’t undo the damage done to user trust. If you’re in crypto, never type your seed phrase unless you’re 100 percent sure the environment is secure.

Definition of EVM. Link to full glossary entry follows the description.EVM

The Ethereum Virtual Machine is the runtime environment that executes smart-contract bytecode across every Ethereum node, using a 256-bit stack architecture and gas-metered computation.

Read more

CoinLaw follows strict Publishing Principles and a documented Fact-Check Policy to ensure accuracy, transparency, and editorial independence across all content.

Add CoinLaw as a Preferred Source on Google for instant updates! Follow on Google News
Share ChatGPT Perplexity
Kelvin Scott

Kelvin Scott

Finance News Analyst


Kelvin Scott, with over 8 years of experience, covers the latest trends in digital assets, financial markets, and regulatory developments. With a strong focus on accuracy and clarity, he delivers timely updates to help readers navigate the fast-changing world of crypto and finance. An avid football fan, he never misses a chance to watch a good match, whether it’s Premier League drama or a local game.

Related Posts

Multi-Chain Exploit Drains $48M from Turkish Exchange BtcTurk
Cryptocurrency

Multi-Chain Exploit Drains $48M from Turkish Exchange BtcTurk

BNB Chain’s X Account Hacked to Promote Phishing Airdrop and Meme Coin
Cryptocurrency

BNB Chain’s X Account Hacked to Promote Phishing Airdrop and Meme Coin

DxSale Hack Drains $7.3M as Insider Access Claims Surface
Cryptocurrency

DxSale Hack Drains $7.3M as Insider Access Claims Surface

Disclaimer: The content published on CoinLaw is intended solely for informational and educational purposes. It does not constitute financial, legal, or investment advice, nor does it reflect the views or recommendations of CoinLaw regarding the buying, selling, or holding of any assets. All investments carry risk, and you should conduct your own research or consult with a qualified advisor before making any financial decisions. You use the information on this website entirely at your own risk.

Reader Interactions

Leave a Comment Cancel reply

Primary Sidebar

Connect With Us

facebook x linkedin google-news telegram pinterest whatsapp email
google-preferred-source-badge Add as a preferred source on Google

You Should Also Read

CZ Urges Wallet Providers to Block Poison Addresses After $50M USDT Theft
Trust Wallet and Binance Wallet Glitches Stir User Concerns During Market Turmoil
Trust Wallet Launches Address Poisoning Scam Protection

Table of Contents

  • Key Takeaways
  • What Happened?
  • A Coordinated Supply Chain Attack
  • Binance and Trust Wallet Respond
  • Larger Security Concerns in Crypto
  • CoinLaw’s Takeaway
Connect on Telegram

Footer

CoinLaw Logo

Bringing Finance Closer to You.

Connect With Us

Follow Us on Google News

Editorial & Trust

  • About
  • Publishing Principles
  • Fact-Check Policy
  • Corrections Policy
  • Ethics Policy
  • Disclaimer
  • Cookie Policy

Worth Checking

  • Best Cloud Mining Platforms
  • Millennial vs. Gen Z Banking
  • Ethereum Gas Fees Statistics
  • Binance vs. Coinbase Statistics
  • Zelle vs. Venmo Statistics
  • Traditional Banks vs. Neobanks
  • Crypto Exchange Hack Statistics
Contact Us
13570 Grove Dr #189,
Maple Grove, MN 55311,
United States
10 a.m. – 6 p.m. | Every day

Copyright © 2024–2026 CoinLaw. All Rights Reserved. Powered by the HODL Force ❤️

  • Privacy Policy
  • Terms
Manage your privacy

To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.

Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.

Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Statistics

Marketing

Features
Always active

Always active
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
Manage options
  • {title}
  • {title}
  • {title}
Manage your privacy
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Statistics

Marketing

Features
Always active

Always active
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
Manage options
  • {title}
  • {title}
  • {title}
Company
  • About Us
  • Our Team
  • Our Mission
  • Core Values
Discover
  • glossary icon
    Glossary
  • Stats
    Stats Research Process
  • Brand Guide Icon
    Brand Assets
Categories
  • Cryptocurrency
  • Payments
  • Finance
  • Banking
  • Insurance
Cryptocurrency
Coinbase vs Kraken Statistics 2026: Volume, Fees, Licenses
Coinbase vs Kraken Statistics 2026: Volume, Fees, Licenses
Solana vs Ethereum Statistics 2026: TVL, Fees, Validators, ETFs
Solana vs Ethereum Statistics 2026: TVL, Fees, Validators, ETFs
Uniswap vs PancakeSwap Statistics 2026: Head-to-Head DEX Data
Uniswap vs PancakeSwap Statistics 2026: Head-to-Head DEX Data
Cryptojacking Statistics 2026: 80+ Cloud, Cost & Threat Numbers
Cryptojacking Statistics 2026: 80+ Cloud, Cost & Threat Numbers
MetaMask vs Phantom Wallet Statistics 2026: Big Growth Data
MetaMask vs Phantom Wallet Statistics 2026: Big Growth Data
Crypto Wallet Ecosystem Statistics 2026: Addresses, Security, Adoption
Crypto Wallet Ecosystem Statistics 2026: Addresses, Security, Adoption
Payments
Venmo vs PayPal Statistics 2026: Users, Fees and Volume
Venmo vs PayPal Statistics 2026: Users, Fees and Volume
Toast Statistics 2026: ARR, GPV & Revenue Data
Toast Statistics 2026: ARR, GPV & Revenue Data
Rapyd Statistics 2026: TPV, Valuation & Licences
Rapyd Statistics 2026: TPV, Valuation & Licences
Marqeta Statistics 2026: TPV, Revenue and Customer Mix
Marqeta Statistics 2026: TPV, Revenue and Customer Mix
Digital Payments Statistics 2026: Market Size, Users, and Growth
Digital Payments Statistics 2026: Market Size, Users, and Growth
Cash App vs Venmo vs Zelle Statistics 2026: What You Must Know Now
Cash App vs Venmo vs Zelle Statistics 2026: What You Must Know Now
Finance
Emergency Fund Statistics 2026: How Much Americans Have Saved (and How Much They Should)
Emergency Fund Statistics 2026: How Much Americans Have Saved (and How Much They Should)
Financial Advisor Statistics 2026: Headcount, AUM, and Demographics
Financial Advisor Statistics 2026: Headcount, AUM, and Demographics
Wealth Inequality Statistics 2026: Hidden Wealth Divide
Wealth Inequality Statistics 2026: Hidden Wealth Divide
Blockchain in Supply Chain Finance Statistics 2026: Trade Breakthrough
Blockchain in Supply Chain Finance Statistics 2026: Trade Breakthrough
Blockchain in Healthcare Finance Statistics 2026: Cost Breakthrough
Blockchain in Healthcare Finance Statistics 2026: Cost Breakthrough
AI-Powered Robo Trading Statistics 2026: Big Insights
AI-Powered Robo Trading Statistics 2026: Big Insights
Banking
N26 Statistics 2026: Customers, Deposits, Revenue and the BaFin Growth Cap
N26 Statistics 2026: Customers, Deposits, Revenue and the BaFin Growth Cap
Revolut vs Monzo Statistics 2026: Customers & Profit
Revolut vs Monzo Statistics 2026: Customers & Profit
Islamic Banking Statistics 2026: Assets, Growth, and Top Markets
Islamic Banking Statistics 2026: Assets, Growth, and Top Markets
Credit Union Statistics 2026: Assets, Members, Loans
Credit Union Statistics 2026: Assets, Members, Loans
Banking API Statistics 2026: Market Size, Adoption, and Growth
Banking API Statistics 2026: Market Size, Adoption, and Growth
Citigroup Statistics 2026: Growth Secrets Inside
Citigroup Statistics 2026: Growth Secrets Inside
Insurance
Lemonade Insurance Statistics 2026: Customers, In-Force Premium, Loss Ratio, Pet & Auto Segments
Lemonade Insurance Statistics 2026: Customers, In-Force Premium, Loss Ratio, Pet & Auto Segments
Chubb Statistics 2026: Powerful Data Insights
Chubb Statistics 2026: Powerful Data Insights
Virtual Reality In Insurance Statistics 2026: Innovations, Risks, and Opportunities
Virtual Reality In Insurance Statistics 2026: Innovations, Risks, and Opportunities
US Life Insurance Industry Statistics 2026: Growth Facts
US Life Insurance Industry Statistics 2026: Growth Facts
US Auto Insurance Industry Statistics 2026: What You Must Know Now
US Auto Insurance Industry Statistics 2026: What You Must Know Now
UK Insurance Industry Statistics 2026: Growth Data
UK Insurance Industry Statistics 2026: Growth Data
Categories
  • Cryptocurrency
  • Investments
  • Compliance
  • Fintech
  • Finance
Cryptocurrency
Strategy Acquires 520 BTC After Raising $335M From Stock Sale
Strategy Acquires 520 BTC After Raising $335M From Stock Sale
Baillie Gifford Rolls Out First Public UK Tokenized Fund on Solana
Baillie Gifford Rolls Out First Public UK Tokenized Fund on Solana
UK Stablecoin Market Gets Boost as BoE Drops Holding Caps
UK Stablecoin Market Gets Boost as BoE Drops Holding Caps
Solana Lands Major Toss Bank Deal for Stablecoin Payments Test
Solana Lands Major Toss Bank Deal for Stablecoin Payments Test
Taiko Hack Sparks Emergency Bridge Exit After $1.7M Loss
Taiko Hack Sparks Emergency Bridge Exit After $1.7M Loss
Secret Network Suffers $4.67M Loss in Bridge Exploit
Secret Network Suffers $4.67M Loss in Bridge Exploit
Investments
SK Hynix Becomes Korea’s Most Valuable Company in AI Era
SK Hynix Becomes Korea’s Most Valuable Company in AI Era
Ark Invest Buys $18M Coinbase Shares, Dumps Robinhood
Ark Invest Buys $18M Coinbase Shares, Dumps Robinhood
Nvidia Unveils Huge $20B Bond Raise to Power AI Growth
Nvidia Unveils Huge $20B Bond Raise to Power AI Growth
Binance SpaceX IPO Offer Attracts Massive $557M Demand
Binance SpaceX IPO Offer Attracts Massive $557M Demand
Metaplanet Acquires Siiibo in Major Bitcoin Expansion Move
Metaplanet Acquires Siiibo in Major Bitcoin Expansion Move
Morpho Raises $175M at $2B Value as MORPHO Token Jumps
Morpho Raises $175M at $2B Value as MORPHO Token Jumps
Compliance
South Korea Seeks Tougher FATF Crypto Travel Rules
South Korea Seeks Tougher FATF Crypto Travel Rules
Europe Tightens Crypto Rules With New €10K Cash Ban
Europe Tightens Crypto Rules With New €10K Cash Ban
WhiteBIT Wins Key MiCA License in Austria for EU Growth
WhiteBIT Wins Key MiCA License in Austria for EU Growth
CFTC Slaps Lifetime Trading Ban on Celsius Founder Mashinsky
CFTC Slaps Lifetime Trading Ban on Celsius Founder Mashinsky
Kentucky Sues Kalshi and Polymarket Over Illegal Sports Bets
Kentucky Sues Kalshi and Polymarket Over Illegal Sports Bets
Judge Deals Blow to Michelle Bond in FTX Campaign Case
Judge Deals Blow to Michelle Bond in FTX Campaign Case
Fintech
Cardano AI Strategy Expands as Hoskinson Backs Midnight City
Cardano AI Strategy Expands as Hoskinson Backs Midnight City
South Korea Weighs Big Crypto Transfer Boost for Fintechs
South Korea Weighs Big Crypto Transfer Boost for Fintechs
Calais Makes History With UBS uMINT Collateral on Bybit
Calais Makes History With UBS uMINT Collateral on Bybit
Bybit Unveils Powerful Broker API With Ultra Low Latency Access
Bybit Unveils Powerful Broker API With Ultra Low Latency Access
Bitget and xStocks Bring SpaceX IPO Access Onchain
Bitget and xStocks Bring SpaceX IPO Access Onchain
Bybit Launches IPO Express With Tokenized SpaceX Access
Bybit Launches IPO Express With Tokenized SpaceX Access
Finance
Kalshi Targets IPO After Massive Growth and $22B Valuation
Kalshi Targets IPO After Massive Growth and $22B Valuation
Coinbase Sparks New Race With 1:1 Backed Tokenized Stocks
Coinbase Sparks New Race With 1:1 Backed Tokenized Stocks
Bitmine Launches $300M Preferred Stock to Buy More ETH
Bitmine Launches $300M Preferred Stock to Buy More ETH
Coinbase Lists SpaceX Pre IPO Perpetual Futures
Coinbase Lists SpaceX Pre IPO Perpetual Futures
Binance Expands Into US Stocks With New bStocks Service
Binance Expands Into US Stocks With New bStocks Service
SEC Clears Paxos to Settle U.S. Stocks on Blockchain
SEC Clears Paxos to Settle U.S. Stocks on Blockchain
Newsletter Img

Too much noise in crypto?

We respect your time. You get one high-impact briefing a week. If the market is quiet, so are we.

✅ Join readers from Visa, Vanguard, and the FDIC.
Newsletter Img

The Weekly Briefing

We track the market 24/7. You get a 5-minute summary. If it’s quiet, we skip it.

✅ Read by pros at Visa, Vanguard, and the FDIC.