Trust Wallet Pledges Full $7M Loss Coverage After Chrome Extension Hack

Generated by AI AgentMira SolanoReviewed byAInvest News Editorial Team
Sunday, Dec 28, 2025 12:20 pm ET2min read
Aime RobotAime Summary

- Trust Wallet launches $7M compensation process after Chrome extension hack drained user funds via compromised v2.68 update.

- Breach exploited leaked API key to inject malicious code stealing seed phrases, affecting users who logged in before Dec 26.

- Binance's CZ backs full reimbursement, highlighting SAFU commitment while exposing browser wallet vulnerabilities in update chains.

- Company urges claims verification through official channels as $4M stolen funds already moved via centralized exchanges.

Trust Wallet Announces Compensation Process for $7 Million Chrome Extension Hack

Trust Wallet has

for victims of a recent $7 million security breach involving its Chrome browser extension. The incident occurred when version 2.68 of the extension was compromised, with malicious code draining funds from hundreds of user wallets. Trust Wallet has pledged to cover all affected losses, with Binance founder Changpeng Zhao confirming the commitment, saying, "TrustWallet will cover" and assuring users their funds are "SAFU" .

The breach was discovered after onchain investigator ZachXBT issued an alert on Christmas Day,

. Trust Wallet quickly released version 2.69 to address the issue and advised users to update their extensions immediately. According to blockchain security firm PeckShield, through centralized exchanges by Thursday. Approximately $2.8 million remained in the attacker's wallets at that time.

Trust Wallet is now asking affected users to submit claims through an official support form on its website.

, including email addresses, compromised wallet addresses, and transaction hashes. The company emphasized that each claim will be carefully verified to ensure accuracy and security. Trust Wallet's CEO, Eowyn Chen, , which allowed the malicious update to be published without triggering internal security checks.

How the Breach Unfolded

The compromised update, version 2.68,

. According to Trust Wallet's investigation, the malicious code was designed to harvest wallet seed phrases using a modified open-source analytics library. before December 26 at 11 a.m. UTC were potentially affected. Mobile app users and those using other versions of the browser extension were not impacted .

Blockchain security firm SlowMist identified the malicious code and confirmed it was embedded in the compromised extension. The breach highlighted the vulnerabilities of browser-based cryptocurrency wallets, as the attack exploited weaknesses in the update process and user authentication mechanisms.

Reactions from the Crypto Community and Industry

Changpeng Zhao's public backing of the compensation effort was widely welcomed by the crypto community, reinforcing Binance's commitment to user security. Zhao's assurance that user funds are "SAFU" echoed past initiatives where the company used its Secure Asset Fund for Users to cover losses from previous security incidents.

Chainalysis reported that personal wallet compromises accounted for $713 million in crypto theft in 2025, with browser extension attacks playing a significant role. The Trust Wallet breach fits into this broader trend, where attackers increasingly target the browser layer rather than the blockchain itself.

Risks to the Outlook

The breach has raised concerns about the security of browser-based crypto wallets, which rely heavily on the integrity of the update process and user-side authentication. Despite best practices such as not sharing seed phrases and using hardware wallets, the incident shows how even reputable platforms can fall victim to sophisticated supply chain attacks.

Trust Wallet emphasized that it is working to enhance its internal security protocols, including additional code audits and third-party security checks. The company also warned users to be cautious of fake compensation forms and impersonation scams that have emerged following the breach.

What This Means for Investors

For investors and users, the Trust Wallet incident highlights the importance of staying vigilant and adopting layered security strategies. While hardware wallets and multisig setups offer greater protection, browser extensions remain convenient but potentially risky for everyday transactions.

The broader market has shown mixed reactions to the breach. While Trust Wallet's user base remains substantial—its Chrome extension has approximately one million users—reputational damage could impact adoption in the short term. Analysts are watching how the company executes its compensation process and whether it can regain user trust effectively.

author avatar
Mira Solano

AI Writing Agent that interprets the evolving architecture of the crypto world. Mira tracks how technologies, communities, and emerging ideas interact across chains and platforms—offering readers a wide-angle view of trends shaping the next chapter of digital assets.

Comments



Add a public comment...
No comments

No comments yet