TL;DR: In December 2025, a compromised version of the Trust Wallet browser extension resulted in 2,520 wallet addresses being drained and approximately $8.5 million in crypto assets being stolen.
In December 2025, version 2.68 of the Trust Wallet browser extension was compromised in a software supply-chain attack. A malicious version of the extension reached the Chrome Web Store without passing through Trust Wallet’s normal internal release process.
Trust Wallet identified 2,520 affected wallet addresses and approximately $8.5 million in stolen crypto assets. Subsequent investigations provided a clearer picture of how the compromised extension was distributed and how the attacker obtained access to users’ funds.
Timeline of the Trust Wallet Browser Extension v2.68 Incident
On December 24, 2025, an unauthorized version of the Trust Wallet browser extension – version 2.68 – was published on the Chrome Web Store. It contained malicious code designed to extract users’ decrypted seed phrases, from which the corresponding private keys could be derived.

Unlike a conventional phishing attack, which relies on tricking users into approving malicious transactions, the code operated directly inside the compromised extension. When users opened the extension and logged into their wallets between December 24 and December 26, the malicious code collected sensitive wallet information and transmitted it to a server controlled by the attacker. This allowed the attacker to access the affected wallets and transfer funds without any further approval from their owners.
The first public signs of the attack emerged on December 25, when blockchain researchers, including ZachXBT, identified a series of suspicious transfers from Trust Wallet addresses. Trust Wallet subsequently acknowledged the incident, released version 2.69 and instructed users to stop using version 2.68.
How the Attack Happened
Trust Wallet later linked the incident with high confidence to the industry-wide Sha1-Hulud supply-chain attack of November 2025. Rather than exploiting a vulnerability in the wallet itself or tricking individual users, the attackers compromised systems used in Trust Wallet’s software-development process.
The Sha1-Hulud campaign targeted companies through compromised npm packages – reusable pieces of JavaScript code used by software developers. According to Trust Wallet, the attack exposed developer credentials stored on GitHub, giving the attackers access to the browser extension’s source code and its Chrome Web Store publishing key.

Using this access, the attackers prepared a modified version of the extension and submitted it to the Chrome Web Store outside Trust Wallet’s normal release process. They also registered their own domain to host the malicious code embedded in the extension. The modified version passed the Chrome Web Store’s review but bypassed Trust Wallet’s internal review and approval procedures.
Who Was Affected?
The attack was limited to users of one specific browser extension version during a relatively short period.
Users were potentially affected if they:
- used Trust Wallet Browser Extension v2.68;
- opened the extension; and
- logged in between December 24 and 11:00 UTC on December 26, 2025.
According to Trust Wallet, the following users were not affected:
- users of the Trust Wallet mobile app;
- users of browser extension versions other than v2.68;
- v2.68 users who first opened and logged in after 11:00 UTC on December 26; and
- users who did not see the security-incident banner in their browser extension.
Losses reach up to $8.5 million
Trust Wallet ultimately identified 2,520 affected wallet addresses, from which approximately $8.5 million in crypto assets was stolen. The funds were linked to 17 addresses controlled by the attackers.
Trust Wallet noted that the 17 attacker-controlled addresses had also received assets stolen from wallets unrelated to the Trust Wallet incident. Not all activity involving them could therefore be attributed to this particular attack.
Separate on-chain analysis by Scorechain found that the stolen assets were quickly divided among multiple intermediary wallets. Some of the funds were then moved through swap services and across different blockchains, making their subsequent movement more difficult to trace.
How Trust Wallet Responded
After confirming the breach, Trust Wallet rolled back the compromised extension to a verified clean version and released it as v2.69. Users who had logged in through v2.68 during the affected period were advised to transfer any remaining assets to a newly created wallet with a new seed phrase. Any wallet exposed through the compromised extension had to be considered permanently unsafe.
Trust Wallet also committed to reimbursing affected users and introduced a claims process requiring applicants to prove ownership of the compromised wallets. By its latest published update in July 2026, reviews were still being handled individually. The company had received more than 5,000 claims relating to 2,520 confirmed affected addresses, indicating that many submissions were duplicates or potentially fraudulent.
Following the incident, Trust Wallet said it had revoked the exposed publishing credentials, restricted deployment permissions and strengthened its controls around software releases, access management, monitoring and incident response.
Lessons from the Trust Wallet Hack
What makes this incident notable is that users were compromised through an official software update. They did not need to disclose their seed phrases, visit a phishing website or approve fraudulent transactions. Simply opening and unlocking the compromised extension was enough to expose their wallet credentials.

The incident provides a real-world example of the supply-chain risks discussed in our earlier examination of the 2025 npm attacks. The attacker did not need to break Trust Wallet’s cryptography or target thousands of users individually. By obtaining developer credentials and access to the release process, malicious software could be distributed under Trust Wallet’s name through the official Chrome Web Store.
For users, the broader lesson is that self-custody does not eliminate software risk. Browser extensions and other hot wallets rely on internet-connected devices, software updates and development systems – any of which may become compromised. They are useful for everyday transactions, but significant long-term holdings are better isolated behind a hardware wallet that keeps the private keys offline and allows transaction details to be verified independently.
How to harden your personal self-custody setup
Once again: software and browser wallets should hold little more than pocket money – if anything. As convenient as these tools may be, they are equally convenient targets for threat actors seeking to steal your money. The sheer number of potential software vulnerabilities means that no internet-connected device should ever be considered fully secure. The vast majority of successful crypto thefts from individuals involve precisely these kinds of hot wallets.
As a practical rule of thumb, once you hold more than approximately $1,000 in crypto assets, procure and utilize a dedicated hardware wallet. This keeps your private keys and transaction signing capabilities inside a separate device rather than on your internet-connected computer or phone, where malware may be able to access and steal your wallet contents.

Modern hardware wallets are relatively affordable and straightforward to use. Entry-level devices such as the Trezor Safe 3 or Ledger Nano S Plus provide everything most users need. Premium models offer larger touchscreens, improved ergonomics and additional convenience features, but an entry-level device is perfectly adequate for establishing the essential separation.
Whichever model you choose, always verify the destination address and transaction details on the hardware wallet’s own screen. A hardware wallet can prevent a compromised computer from extracting your private keys, but it cannot protect you if you approve a malicious transaction without checking it.
If you’re based in – or visiting – Vietnam, our colleagues at BitcoinVN Shop offer a wide selection of genuine hardware wallets from leading manufacturers, including Trezor, Ledger and Keystone. Buying locally avoids the hassle, delays and uncertainty often involved in importing a device yourself.
Orders can also be collected directly from our Saigon headquarters or Da Nang showroom. This allows you to avoid attaching your name and home address to the delivery of your device – an option we strongly encourage as part of our data-minimization approach.

Furthermore, the shop also offers “disaster-proof” steel backup plates for securely recording your seed phrase. Unlike paper or digital backups, these are designed to withstand fire, flooding and other forms of physical damage.
Access Qualified Assistance Securing Your Digital Assets
If you would like to get serious about protecting your digital assets, our team has accumulated more than a decade of experience in securing and storing them. As one of the world’s longest-running crypto exchanges, we are also – in many ways by necessity – daily “in the trenches,” analyzing and defending against emerging cyber threats.
As a result, we have built considerable expertise, which you can access through our personal, one-to-one self-custody consulting service.
One of our senior cybersecurity team members will walk you through the process, answer your questions and discuss a setup that works for your personal circumstances. We will help ensure that you avoid the common pitfalls that can lead to a loss of funds when taking on the freedom – but also the responsibility – that comes with self-custodial crypto holdings.
Securing large amounts of Bitcoin – Multivendor Multisig a Must
Once you have “made it” – and most likely de-risked your digital-asset holdings by allocating a significant share of your personal portfolio to “boring but predictable” Bitcoin – a simple single-signature setup is no longer good enough.
As the Coldcard fiasco earlier this year demonstrated, single points of failure – however rare they may be in practice – do eventually materialize. You do not want to fumble your “intergenerational bag” of Bitcoin wealth by failing to prepare for the moment disaster strikes.
A solid multivendor multisig setup protects against several potential single points of failure: losing one of your keys, a device manufacturer supplying defective or compromised hardware, or any other scenario in which the security of one key becomes “make or break.”
Multivendor multisig removes this single-path dependency in favour of a more resilient and forgiving custody setup – one capable of withstanding various low-probability, high-impact “freak accident” scenarios.
Multisig must, however, be designed, implemented and backed up correctly. A poorly constructed setup can introduce new points of failure of its own.
Our team is ready to discuss your circumstances and provide qualified guidance on building a suitable multivendor multisig setup.