Tricky Profit
  • Stock
  • Economy
  • Politics
  • Editor’s Pick
Editor's Pick

Trust Wallet just got hacked on Christmas, $7M drained

by December 27, 2025
by December 27, 2025 0 comment

Trust Wallet has confirmed a hack that led to millions of dollars in user funds being drained.

What initially appeared as scattered wallet losses quickly hardened into something far more serious: a confirmed supply-chain compromise of Trust Wallet’s official Chrome browser extension.

The Christmas Trust Wallet hack

The incident traces back to December 24, 2025, when Trust Wallet released version 2.68.0 of its Chrome browser extension.

The first major public alarm came from on-chain investigator ZachXBT, who linked the wallet drains directly to the v2.68 update while funds were still in motion. His warnings helped frame the incident as an extension compromise rather than a user-level mistake.

In many cases, wallets were emptied within minutes of importing a seed phrase or accessing an existing wallet through the extension.

By December 26, the picture was clearer, and Trust Wallet publicly confirmed that only the browser extension version 2.68 was affected.

Trust Wallet

@TrustWallet

·Follow

We’ve identified a security incident affecting Trust Wallet Browser Extension version 2.68 only. Users with Browser Extension 2.68 should disable and upgrade to 2.69.
Please refer to the official Chrome Webstore link here:
chrome.google.com/webstore/detai…
Please note: Mobile-only users

1:21 am · 26 Dec 2025

2

Reply

Read more on Twitter

Although mobile users were not impacted, the company advised all extension users to immediately disable version 2.68 and upgrade to version 2.69 through the official Chrome Web Store.

What really went wrong

Researchers and on-chain investigators described the exploit as a straight supply-chain attack, not phishing and not user error.

According to multiple analyses shared publicly, the compromised extension contained a malicious JavaScript payload embedded in what appeared to be routine analytics code.

The script, often referenced as a file similar to “4482.js,” allegedly masqueraded as a PostHog-style integration. Its function was simple and devastating.

When users entered or accessed their recovery phrase, the data was silently exfiltrated to attacker-controlled infrastructure using domains that closely resembled legitimate Trust Wallet metrics endpoints.

Once attackers had the seed phrase, no further interaction was needed. There were no approvals to trick and no transactions to sign.

The wallet could be restored elsewhere and drained across every supported blockchain.

That is exactly what investigators observed, with rapid multi-chain sweeps affecting Bitcoin, EVM networks, Solana, and BNB Chain.

Money trailed to instant exchange services and CEXs

While some reports pointed to roughly $2.8 million in confirmed drains, others tracked more than $4 million passing through identified services. Trust Wallet has, however, confirmed that the total impact stood at approximately $7 million.

Binance founder CZ, whose company acquired Trust Wallet in 2018, also stated that losses were around $7 million and confirmed that users would be made whole.

CZ also highlighted the most uncomfortable issue raised by the incident: how a malicious build was able to reach the Chrome Web Store under an official wallet brand.

On-chain analysis reveals that the stolen funds are being transferred quickly, with a significant portion routed through instant exchange services and centralised platforms.

Public trackers cited flows into services such as ChangeNOW and FixedFloat, as well as exchanges including KuCoin and HTX.

Lookonchain

@lookonchain

·Follow

Trust Wallet(@TrustWallet) has been exploited, with hundreds of users affected and over $6.77M stolen so far.
The hacker has already sent ~$4.25M to ChangeNOW, FixedFloat, KuCoin, and HTX.
CZ(
@cz_binance) has stated that Trust Wallet will fully cover the losses.
Check hacker

9:02 am · 26 Dec 2025

616

Reply

Read 93 replies

As investigations continue, Trust Wallet has warned users to ignore any messages that did not come from official Trust Wallet channels.

The post Trust Wallet just got hacked on Christmas, $7M drained appeared first on Invezz

0 comment
0
FacebookTwitterPinterestEmail

previous post
Liquidity drain causes Solana-based USX stablecoin to depeg to $0.1
next post
FTX whistleblower Caroline Ellison set for early release next month

You may also like

FTX whistleblower Caroline Ellison set for early release...

December 27, 2025

Liquidity drain causes Solana-based USX stablecoin to depeg...

December 27, 2025

Uniswap community passes UNIfication proposal, 100M UNI set...

December 27, 2025

Why 2025 was crypto’s year of wins, yet...

December 27, 2025

Sui, Avalanche, TON led L1 tokens dump in...

December 27, 2025

SEC charges 7 entities in $14M crypto scam...

December 26, 2025

Crypto M&A deals hit record $8.6B in 2025:...

December 26, 2025

How crypto ETFs are redefining the crypto market:...

December 26, 2025

Curve DAO rejects proposal for $6.2M allocation to...

December 25, 2025

Ethereum price faces stiff resistance amid ETF outflows

December 25, 2025

    Join our mailing list to get access to special deals, promotions, and insider information. Your exclusive benefits await! Enjoy personalized recommendations, first dibs on sales, and members-only content that makes you feel like a true VIP. Sign up now and start saving!


    By opting in you agree to receive emails from us and our affiliates. Your information is secure and your privacy is protected.

    Recent Posts

    • Can Saudi Arabia really undercut the world on AI with low-cost electricity?

      December 27, 2025
    • Looking back at 2025: the $3.2 billion Fintech IPO comeback nobody predicted

      December 27, 2025
    • FTX whistleblower Caroline Ellison set for early release next month

      December 27, 2025
    • Trust Wallet just got hacked on Christmas, $7M drained

      December 27, 2025
    • Liquidity drain causes Solana-based USX stablecoin to depeg to $0.1

      December 27, 2025

    Disclaimer: TrickyProfit.com, its managers, its employees, and assigns (collectively "The Company") do not make any guarantee or warranty about what is advertised above. Information provided by this website is for research purposes only and should not be considered as personalized financial advice.
    The Company is not affiliated with, nor does it receive compensation from, any specific security. The Company is not registered or licensed by any governing body in any jurisdiction to give investing advice or provide investment recommendation. Any investments recommended here should be taken into consideration only after consulting with your investment advisor and after reviewing the prospectus or financial statements of the company.

    • About us
    • Contacts
    • Privacy Policy
    • Terms and Conditions
    • Email Whitelisting

    Copyright © 2025 TrickyProfit.com All Rights Reserved.

    Tricky Profit
    • Stock
    • Economy
    • Politics
    • Editor’s Pick