ZachXBT flags suspected Trust Wallet extension issue as users report drained funds

ambcryptoОпубліковано о 2025-12-25Востаннє оновлено о 2025-12-25

Анотація

Security concerns emerged around the Trust Wallet browser extension on December 25, after blockchain investigator ZachXBT flagged suspicious activity potentially linked to a recent update. Reports suggest a supply-chain compromise may have been introduced in a December 24 update, where newly added code could silently exfiltrate sensitive wallet data—particularly during seed phrase imports—leading to immediate fund draining. Multiple users reported losses, with unverified estimates exceeding $2 million. The malicious code allegedly sent data to a recently registered external domain mimicking Trust Wallet infrastructure. The issue appears limited to the browser extension, with no evidence of mobile app compromise. Trust Wallet has not yet issued an official response or advisory. Researchers emphasize the situation remains under investigation, warning users to avoid importing seed phrases into the extension until clarified. If confirmed, this would represent a significant supply-chain attack.

Security concerns have emerged around the Trust Wallet browser extension on 25 December, after blockchain investigator ZachXBT flagged suspicious activity potentially linked to a recent update, prompting warnings from developers and security-focused accounts.

According to posts circulating on X, the issue may stem from a suspected supply-chain compromise introduced in a 24 December browser extension update.

Newly added code within the extension could silently exfiltrate sensitive wallet data when users import a seed phrase. The claims suggest that this has led to immediate wallet draining.

Alleged Trust Wallet malicious code and data exfiltration claims

Developers examining the extension allege that a JavaScript file added in the update contains logic disguised as analytics.

The code is said to activate specifically when a seed phrase is imported. It then silently transmits wallet-related data to an external domain designed to resemble official Trust Wallet infrastructure.

The domain referenced in the reports was reportedly registered only days ago and has since gone offline.

Researchers argue that its recent creation and the timing of the extension update raise concerns about a coordinated supply-chain attack rather than user-side phishing.

Users report wallet drains following seed imports

Multiple users have reported wallets being drained shortly after importing seed phrases into the Trust Wallet browser extension.

Publicly shared estimates suggest that more than $2 million may have been lost. Although these figures have not been independently verified.

Analysts indicate that funds were routed through multiple addresses, a pattern more commonly associated with automated exploitation than isolated user error.

Scope appears limited to browser extension

At this stage, there is no indication that Trust Wallet’s mobile applications are affected.

The warnings circulating online are focused specifically on the browser extension. This is where update mechanisms and third-party dependencies present higher supply-chain risk.

Users are advised not to import seed phrases into the Trust Wallet browser extension until further clarification is provided.

No official response from Trust Wallet yet

As of the time of writing, Trust Wallet has not issued any public response, clarification, or security advisory addressing the allegations.

There has been no confirmation or denial of the claims, nor any announcement of an extension, rollback, or emergency patch.

Investigation ongoing

Researchers have emphasized that the situation remains under active investigation. Conclusions should not be drawn until the extension code and related on-chain activity have been fully reviewed.

If confirmed, the incident would represent a serious supply-chain compromise.

This is a class of attack that differs significantly from phishing or user-side mistakes. Also, it has historically resulted in rapid, large-scale losses across the crypto ecosystem.


Final Thoughts

  • The allegations point to a potentially serious supply-chain risk affecting wallet extensions, underscoring how code updates can become a critical attack vector if compromised.
  • With no response yet from Trust Wallet, users and researchers are left relying on independent investigation as scrutiny around the incident continues.

Пов'язані питання

QWhat security concern was flagged by ZachXBT regarding the Trust Wallet browser extension?

AZachXBT flagged suspicious activity potentially linked to a recent update of the Trust Wallet browser extension, suggesting it could be a supply-chain compromise that leads to the silent exfiltration of sensitive wallet data and immediate draining of funds.

QHow does the suspected malicious code in the Trust Wallet extension allegedly operate?

AThe malicious JavaScript code, added in an update and disguised as analytics, is said to activate when a user imports a seed phrase. It then silently transmits wallet-related data to an external domain designed to look like official Trust Wallet infrastructure.

QWhat is the estimated financial impact based on user reports, and how were the funds moved?

APublicly shared estimates suggest that more than $2 million may have been lost, though this is unverified. Analysts indicate the funds were routed through multiple addresses, a pattern associated with automated exploitation rather than isolated user error.

QAre Trust Wallet's mobile applications also affected by this suspected compromise?

ANo, there is no indication that Trust Wallet’s mobile applications are affected. The warnings are specifically focused on the browser extension, which has higher supply-chain risk due to its update mechanisms and third-party dependencies.

QWhat is the current status of Trust Wallet's official response to these allegations?

AAs of the time the article was written, Trust Wallet had not issued any public response, clarification, or security advisory addressing the allegations. There has been no confirmation, denial, or announcement of an emergency patch.

Пов'язані матеріали

Only a 50% Chance of Passing This Year, Can the CLARITY Bill Succeed Before the Midterm Elections?

The CLARITY Act, which passed the House in July 2025 with strong bipartisan support (294-134), faces a critical juncture in the Senate. The Senate Banking Committee is expected to hold a markup soon, but key issues remain unresolved, including stablecoin yield provisions, DeFi regulations, and securing full Republican committee support. Other contentious points involve the Blockchain Regulatory Certainty Act (BRCA), ethics amendments for government officials, and SEC-related matters. The legislative calendar is tight, with limited time before the midterm elections. If the committee markup is delayed beyond mid-May, the chances of passage in 2026 drop significantly. Senator Cynthia Lummis has warned that failure this year could delay comprehensive crypto market structure legislation until 2030 or later. Galaxy estimates the probability of the CLARITY Act becoming law in 2026 is only about 50%. The bill provides crucial regulatory clarity by defining jurisdictional boundaries between the SEC and CFTC, establishing a path for decentralization, and bringing digital commodity intermediaries under federal regulation. Its passage is seen as vital before potential power shifts in the next Congress, which could bring less favorable leadership to key committees. The timeline is compressed, and the bill must compete for floor time with other priorities like Iran authorization and DHS appropriations. Key hurdles include finalizing the stablecoin yield compromise text, addressing law enforcement concerns about BRCA, and navigating political dynamics around SEC nominations. The outcome of the Banking Committee markup and the level of bipartisan support will be critical indicators of its future success.

marsbit5 хв тому

Only a 50% Chance of Passing This Year, Can the CLARITY Bill Succeed Before the Midterm Elections?

marsbit5 хв тому

Dialogue with Xinhuo Chief Economist Fu Peng: Macro Bear Market Expected to End This Year, Prioritize Allocation to Value Assets

Fu Peng, Chief Economist at New Huo Group, discusses the integration of crypto assets into traditional finance, marking a shift from a speculative phase to institutionalization. He highlights the current era as the second major fusion of finance and technology, driven by AI, data, and computing power, with crypto assets becoming part of the FICC+C (Fixed Income, Currencies, Commodities + Crypto) framework. Regulatory clarity in the U.S., such as the GENIUS and Clarity Acts, has paved the way for institutional adoption by defining digital assets as financial instruments. Fu views RWA (Real World Assets) as a tool for asset tokenization rather than a standalone asset class, noting that financial innovation differs between Eastern and Western markets due to cultural approaches to risk and regulation. He emphasizes that stablecoins are essential for future finance, but Asian markets, including Hong Kong, will adopt them cautiously. Macro liquidity now significantly influences crypto markets, as institutional participation increases correlation with traditional assets. Fu suggests the macro-driven bear market may end by year-end, reducing the relevance of Bitcoin’s four-year cycle. For asset allocation, he recommends value-oriented AI stocks for stability, Bitcoin for moderate certainty, and Ethereum for higher volatility.

marsbit13 хв тому

Dialogue with Xinhuo Chief Economist Fu Peng: Macro Bear Market Expected to End This Year, Prioritize Allocation to Value Assets

marsbit13 хв тому

Only a 50% Chance of Passing This Year, Can the CLARITY Bill Succeed Before the Midterm Elections?

The CLARITY Act, which passed the U.S. House in July 2025 with strong bipartisan support (294-134), faces a critical juncture in the Senate. The Senate Banking Committee is expected to hold a markup soon, but key issues remain unresolved, including stablecoin yield provisions, DeFi regulations, and securing full Republican committee support. Additional challenges involve the Blockchain Regulatory Certainty Act (BRCA), ethics amendments for government officials, and SEC-related concerns. Galaxy estimates only a 50% chance of the bill becoming law in 2026. The tight legislative calendar, competing priorities like Iran military authorization and DHS appropriations, and the impending midterm elections create significant time pressure. If the bill is not passed before the new Congress convenes in 2027, comprehensive crypto market structure legislation could be delayed until 2030 or later, especially if leadership changes result in less favorable committee chairs. The act provides crucial regulatory clarity by defining the jurisdictional boundaries between the SEC and CFTC, establishing a path for decentralized networks to be classified as non-securities, and bringing digital commodity intermediaries under federal regulation. The outcome of ongoing Senate negotiations, particularly the release of revised text on stablecoin yields, will be a key indicator of its future prospects.

Odaily星球日报15 хв тому

Only a 50% Chance of Passing This Year, Can the CLARITY Bill Succeed Before the Midterm Elections?

Odaily星球日报15 хв тому

Four-Dimensional Resonance: Hong Kong Web3 Carnival Sub-Forum Co-Creates Blueprint for Global Financial New Infrastructure

The "Four-Dimensional Resonance: 2026 Global Financial New Infrastructure" forum, a core event of the Hong Kong Web3 Festival, was successfully held at the Hong Kong Convention and Exhibition Centre. Co-hosted by Web3Labs and DeShang Singularity Tech, with joint support from Bitroot, Injective, Microsoft, and Z Oracle, the event gathered policymakers, industry leaders, and investors to explore the integration and innovation of global financial infrastructure, focusing on RWA, AI, DeFi, and compliant payments. Policy speakers, including Hong Kong Legislative Council Member Mr. Wu Jiezhuang, South Korean National Assembly Member Mr. Min Byung-duk, and ACED Chairman Mr. Yun Seok-hun, emphasized the importance of cross-border regulatory collaboration and an open policy environment for fintech innovation. Web3Labs CEO Caspar and DeShang Singularity Tech CEO Chang Shuai highlighted Hong Kong’s role as a financial innovation center and the approaching "singularity moment" for global financial infrastructure. Technical insights were shared by MagnetX, Bitroot, Microsoft, and Injective on topics including AI Agent economies, the evolution of public blockchains, and AI’s transformative role in finance. Key partnerships and initiatives were launched: - GWDC 2026 Korea collaboration between Hong Kong and South Korea. - A strategic agreement between Web3Labs and Microsoft. - The launch of a public anti-fraud alliance by Z Oracle and partners. - The "Injective Rising Star" program to support AI and Web3 projects. Panel discussions delved into AI-driven smart payments, compliant cross-border transactions, and the fusion of RWA and DeFi. Participants agreed that integrating RWA with DeFi is crucial for the next stage of financial infrastructure, enabling a shift from physical to digital finance. The forum underscored Hong Kong’s pivotal role in advancing a globalized and sustainable Asian fintech ecosystem.

marsbit24 хв тому

Four-Dimensional Resonance: Hong Kong Web3 Carnival Sub-Forum Co-Creates Blueprint for Global Financial New Infrastructure

marsbit24 хв тому

Торгівля

Спот
Ф'ючерси
活动图片