A critical supply-chain attack hit Trust Wallet's browser extension (v2.68) on Christmas Day 2025, resulting in over $6 million drained from users' wallets.



Here's what went down: Malicious code injected into the extension managed to extract mnemonic phrases directly from desktop users. Once attackers gained access to the recovery phrases, they had full control—draining BTC, ETH, SOL, and various EVM-chain tokens from compromised wallets.

The automated nature of these drains meant losses cascaded quickly across multiple assets. Desktop users running the affected extension version faced the most exposure during the attack window.

This incident underscores a harsh reality in crypto: even established wallets can become vectors for sophisticated attacks. Supply-chain compromises target the software itself rather than individual security practices, making them particularly dangerous. If you're using browser extensions for wallet management, this is a wake-up call to review your security setup and consider hardware wallet alternatives for substantial holdings.
BTC-0,34%
ETH-0,64%
SOL-0,68%
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 5
  • Repost
  • Share
Comment
0/400
HashRateHermitvip
· 9h ago
Christmas can be hacked too, the crypto world is really unbelievable --- Trust Wallet has another issue? Better not use the browser plugin --- Six million gone... That's why I only use hardware wallets --- Supply chain attacks are the most disgusting, unstoppable --- Mnemonics were directly stolen? Who can withstand that? --- Are people still using browser extensions to manage large assets? --- Hacked again and again, this time it's Trust Wallet --- The contract code was injected, it's completely unreliable
View OriginalReply0
MetaverseVagabondvip
· 9h ago
Christmas was hacked for 6 million, trust wallet really let us down this time --- Browser plugins can't manage money well, now you all should have learned your lesson --- Can the supply chain be protected from being messed with? Just use a hardware wallet directly --- The seed phrase was directly stolen, the security is truly top-notch... --- It's both desktop and browser extension, still brave enough to use it --- Wake up everyone, no matter how convenient the wallet is, it can't withstand such tricks --- Six million is just a lesson fee, how many people are still using v2.68?
View OriginalReply0
MetaverseLandlordvip
· 9h ago
Damn, Trust Wallet can also be attacked? Now I really can't trust the browser extension anymore.
View OriginalReply0
NftRegretMachinevip
· 9h ago
Christmas stolen 6 million, Trust Wallet really messed up this time --- It's the supply chain again, now even wallets can't be trusted --- ngl that's why I already moved my main assets to a hardware wallet --- Browser plugin wallet? Wake up everyone, it's time to switch to a hardware wallet --- Even big projects like Trust can be compromised, the crypto world is really damn crazy --- So the question is, how can users who used this version fix the issue --- I knew it, self-custody is the only way out, everything else is just gambling on luck
View OriginalReply0
notSatoshi1971vip
· 9h ago
Christmas ruined? Trust Wallet really gave a big gift... That's why I only trust hardware wallets
View OriginalReply0
  • Pin

Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)