Trust Wallet Reveals Number of Victims from the Hack and the Compensation Problem

RBK-cryptoPublished on 2025-12-29Last updated on 2025-12-29

Abstract

Trust Wallet CEO Eowyn Chen revealed that last week's hack affected over 2,500 user accounts. However, the service has received approximately 5,000 compensation claims, indicating a significant number of fraudulent or duplicate requests, which is slowing down the payout process. The hack occurred on the night of December 26 due to a vulnerability in the browser extension version 2.68. An update (v2.69) was released, and the company promised to cover the estimated $7 million in losses. The verification of claims is being conducted alongside the technical investigation, prioritizing accuracy over speed. Trust Wallet is working with Google to obtain Chrome audit logs and is conducting a detailed security check on remote devices. In a related context, a recent Chainalysis report noted that 2025 has seen over 158,000 personal wallet compromises, resulting in $713 million in losses.

Trust Wallet head Eowyn Chen reported that last week's crypto wallet hack affected over 2,500 accounts. However, she stated that the service received twice as many compensation claims, which is slowing down payouts as it takes time to weed out fraudulent requests.

The Trust Wallet hack occurred on the night of December 26. Developers had previously acknowledged a vulnerability in the browser wallet version 2.68, released an update to version 2.69, and promised to compensate for the damage, which they estimated at $7 million.

"To date, we have identified 2,596 addresses affected by the hack. From this group, we have received about 5,000 claims, indicating a significant number of false or duplicate attempts to access victim compensation," wrote Chen.

The verification of claims is being conducted in parallel with the technical investigation of the incident. Chen noted that this has proven to be a complex task, so processing the requests is taking longer than affected users expected. The priority remains the accurate verification of wallet owners, not speed.

The day before, Chen reported that Google is assisting in the investigation—the crypto wallet team hopes to obtain audit logs (access request logs) from the Chrome browser. Also, the Trust Wallet security service will conduct a detailed check of the devices of employees working remotely.

A week earlier, Chainalysis estimated that the total damage from hackers' actions in 2025 exceeded $3.4 billion. This year, 158,000 cases of personal wallet compromises were recorded with a total damage of $713 million (compared to $1.5 billion the previous year), affecting over 80,000 users.

Bitcoin's price updated its weekly high. What happened to cryptocurrencies

Memecoin market cap plunged by $100 billion in 2025. CoinGecko report

"Overcoming the psychological barrier." What will happen to Bitcoin this week

Related Questions

QHow many user accounts were affected by the Trust Wallet hack according to CEO Eowyn Chen?

AOver 2,500 accounts were affected by the Trust Wallet hack.

QWhat was the estimated financial damage from the Trust Wallet security breach?

AThe estimated financial damage from the hack was $7 million.

QWhy is the compensation process taking longer than expected for Trust Wallet users?

AThe process is taking longer because the service received about 5,000 claims for 2,596 affected addresses, indicating a significant number of fraudulent or duplicate claims that require time to filter out.

QWhich specific version of the Trust Wallet browser extension contained the vulnerability that was exploited?

AThe vulnerability was in the browser wallet version 2.68.

QWhat is the total estimated damage from hacker activities in 2025, as reported by Chainalysis?

AAccording to Chainalysis, the cumulative damage from hacker activities in 2025 exceeded $3.4 billion.

Related Reads

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

Coldcard Hardware Wallet Hacked: Losses Mount Due to Vulnerable Seed Generation A critical vulnerability in Coldcard hardware wallets has led to a continued wave of fund thefts. According to Galaxy Research, the total stolen has reached 1,367.05 BTC (approx. $88.6 million) from 4,585 addresses, a significant increase from the initial 594.5 BTC reported on July 30, 2026. Most of the stolen funds remain on the attackers' addresses. The issue is not with the current firmware, which Coinkite has updated, but with seed phrases generated on vulnerable devices between March 2021 and the release of fixed firmware versions. Due to a programmer error, devices switched from using a hardware random number generator to the software-based Yasmarang generator, which was initialized with publicly accessible data like the chip's serial number. This made the seed phrases predictable through offline brute-force attacks, meaning wallets remain at risk until funds are moved to a new wallet generated with the patched firmware. Affected devices include Mk2/Mk3 with firmware 4.0.1–4.1.9 (and up to 5.0.3), Mk4/Mk5 up to version 5.6.0, and Q models up to 1.5.0Q. The only exceptions are seeds created with a high-entropy method like at least 50 independent dice rolls or a strong unique BIP-39 passphrase. All other owners must generate a new seed on the fixed firmware and transfer their assets. A case highlighting the human impact involves a 39-year-old long-term investor who lost 2 BTC (approx. $130,000) in minutes. He had accumulated the Bitcoin over eight years through physical labor, viewing it as a financial lifeline and a retirement plan in a country suffering from hyperinflation. His story underscores that even conservative "buy and hold in cold storage" strategies can be compromised by such underlying technical flaws. From a technical perspective, this incident echoes historical failures where weak random number generators undermined cryptographic security, challenging the assumption that offline storage is automatically foolproof.

cryptonews.ru4h ago

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

cryptonews.ru4h ago

Trading

Spot
活动图片