Trust Wallet browser extension hack — December 2025
Incident facts
| Date of incident | (approximate) |
|---|---|
| Publicly disclosed | December 26, 2025 |
| Target type | Wallet software or provider |
| Loss | $8,500,000Published estimates range $7,000,000 to $8,500,000Price at time of incident |
| Method | Supply chain or frontend compromiseTrust Wallet said developer secrets exposed in the November 2025 "Sha1-Hulud" npm supply-chain campaign gave an attacker its browser extension source code and its Chrome Web Store API key. The key was used to publish a backdoored version 2.68 directly to the Chrome Web Store, bypassing internal release review. The injected code hooked both the password and biometric unlock paths, captured decrypted seed phrases and exfiltrated them to attacker infrastructure disguised as PostHog analytics traffic. The npm-campaign origin is Trust Wallet's own attribution; Koi Security notes thematic overlap with that campaign but says no technical connection was established. |
| Chains | Multiple chains |
| Outcome | Users reimbursed |
What happened
Between 24 and 26 December 2025 an attacker published a backdoored version of the Trust Wallet browser extension to the Chrome Web Store and used it to steal seed phrases from users who unlocked their wallets while it was live. Trust Wallet, which Binance owns, said the attacker obtained its browser extension source code and Chrome Web Store API key from developer secrets exposed in the November 2025 "Sha1-Hulud" npm supply-chain campaign, and used that key to upload version 2.68 directly, bypassing the company's internal release review. Chief executive Eowyn Chen said the malicious build "was NOT released through our internal manual process".
The injected code hooked the extension's password and biometric unlock paths, captured decrypted seed phrases and sent them to attacker-controlled infrastructure at api.metrics-trustwallet.com, disguised as PostHog analytics traffic. Koi Security and BlockSec both documented the modified files and the domains used, and Koi found the exfiltration infrastructure had been staged by 8 December. On-chain investigator ZachXBT flagged the drains on 25 December, and Trust Wallet shipped a clean version 2.69. Mobile users and other extension versions were not affected.
The reported loss has moved. Trust Wallet initially put it at about $7 million across 2,596 affected addresses, the figure Binance co-founder Changpeng Zhao cited when he said losses would be covered through the SAFU fund. A later Trust Wallet community update gave 2,520 drained addresses and about $8.5 million in assets traced to 17 attacker-controlled wallets. BlockSec's February 2026 analysis reports the same totals across ten blockchains; it was published after the community update and does not claim an independent derivation, so the higher figure rests principally on the affected company's own accounting.
Trust Wallet said it would voluntarily reimburse affected users and opened a claims process through its support portal. It reported receiving more than 5,000 claims, including duplicates and false submissions, and said it was building an auditable verification process before paying out; completion of reimbursement is not confirmed by any source. No actor has been named.
Sources
- Trust WalletPrimary · retrieved 2026-08-01
- BlockSecSecondary · retrieved 2026-08-01
- BleepingComputerSecondary · retrieved 2026-08-01
- Koi SecuritySecondary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
Official post-mortem: https://trustwallet.com/blog/announcements/trust-wallet-browser-extension-v268-incident-community-update
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Trust Wallet browser extension hack — December 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/trust-wallethttps://itokenly.com/hacks/trust-walletPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.