Oh my God, the Trust Wallet browser extension was directly hacked, and over 6 million USD is gone?? This time it's a real hacker, not just us small retail investors' FOMO😱
The most outrageous part is that the attacker directly modified the source code to implant a backdoor, stealing mnemonics and private keys through PostHog. This isn't an ordinary security vulnerability; it's a professional-grade APT attack. Most of the large wallets that were compromised had been dormant for over a year, and they were directly harvested on Christmas Day.
The key point is that all users of version 2.68 are affected, with the largest single loss reaching 3.5 million USD. I checked, and Trust Wallet has already initiated a compensation process, claiming to reimburse all victims, but I’m not very convinced by such promises...
If you're still using the Trust Wallet extension, you must upgrade to 2.69 now, or directly export your private key and uninstall, then quickly transfer your assets to another wallet. Disconnect from the internet → export private key → switch wallets. This process must be completed. Don’t wait—any delay could cost you an extra ten thousand dollars.
Using on-chain wallets really avoids these troubles. Although the operation is a bit more complicated, at least your private keys are in your own hands.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Oh my God, the Trust Wallet browser extension was directly hacked, and over 6 million USD is gone?? This time it's a real hacker, not just us small retail investors' FOMO😱
The most outrageous part is that the attacker directly modified the source code to implant a backdoor, stealing mnemonics and private keys through PostHog. This isn't an ordinary security vulnerability; it's a professional-grade APT attack. Most of the large wallets that were compromised had been dormant for over a year, and they were directly harvested on Christmas Day.
The key point is that all users of version 2.68 are affected, with the largest single loss reaching 3.5 million USD. I checked, and Trust Wallet has already initiated a compensation process, claiming to reimburse all victims, but I’m not very convinced by such promises...
If you're still using the Trust Wallet extension, you must upgrade to 2.69 now, or directly export your private key and uninstall, then quickly transfer your assets to another wallet. Disconnect from the internet → export private key → switch wallets. This process must be completed. Don’t wait—any delay could cost you an extra ten thousand dollars.
Using on-chain wallets really avoids these troubles. Although the operation is a bit more complicated, at least your private keys are in your own hands.