Trust Wallet Users Lost $7 Million in Cryptocurrency Due to Hack

RBK-crypto发布于2025-12-26更新于2025-12-26

文章摘要

On December 26, the team behind Trust Wallet, a popular cryptocurrency wallet owned by Binance, reported a security breach affecting the browser extension version 2.68. According to Binance founder Changpeng Zhao, the incident was the result of a hack, resulting in losses of approximately $7 million. Users of the compromised version were advised to disable or uninstall it and upgrade to the secure version 2.69. The breach did not impact the mobile application. Trust Wallet's native token (TWT) initially dropped around 7% in price but recovered after the official announcement. Zhao stated that Trust Wallet would cover all user losses and urged affected individuals to contact support. Although no official cause was confirmed, reports suggest that version 2.68 contained hidden malicious code that intercepted users' secret recovery phrases during wallet imports, sending them to an external server. This allowed attackers to gain full access to affected wallets. Some community members, including Zhao, suspect the breach may have been an inside job involving a team member.

On the night of December 26, the team of the popular cryptocurrency wallet Trust Wallet reported a security breach that affected the browser application version 2.68. As explained by Binance founder and head of YZi Labs, which owns Trust Wallet, Changpeng Zhao, the incident occurred as a result of a hacker attack, and the damage amounted to $7 million.

Users of version 2.68 should disable or delete this build and only then install the new version 2.69, and under no circumstances should they open or use the unsafe version. The hack only concerns the browser version 2.68 and did not affect the mobile application.

The native token of Trust Wallet (TWT) reacted with a price drop of about 7%, falling for three hours before the team's announcement around 01:20 Moscow time on December 26. After the official announcement, the TWT price recovered to previous levels and the asset is trading slightly below $0.83.

Zhao stated that Trust Wallet will cover all user losses, and affected users were asked to write to the wallet's support service, a link to which can be found on the official website.

No official statements have been made regarding the causes of the hack. But its essence, according to a report by user Akinator on social network X, may be that a hidden malicious code was embedded in version 2.68 of the Trust Wallet browser extension. Akinator was one of the few who reported the hack several hours before the official confirmation from Trust Wallet.

The assumption is that when a user enters their secret phrase to import a wallet, this code stealthily intercepts the data and sends it to an external server. In this way, the attackers could gain full access to the users' wallets and funds.

The crypto community believes that the malicious code was embedded by someone from the cryptocurrency wallet team. In response to a suggestion by X user under the nickname Crazino.eth that the hack was "certainly carried out by an insider working in the team," Zhao replied "probably."

Broke the cycle. How the price of Bitcoin changed over 10 years at Christmas

AI outperformed humans in a crypto trading tournament. What were the results

Miner "capitulation" called a bullish factor for Bitcoin. Why

相关问答

QWhat was the total amount of cryptocurrency lost by Trust Wallet due to the hack?

AUsers lost $7 million in cryptocurrency due to the hack.

QWhich specific version of the Trust Wallet application was compromised in the security breach?

AThe security breach affected the browser application version 2.68.

QWhat was the impact on Trust Wallet's native token (TWT) price following the incident?

AThe native token TWT initially dropped by approximately 7% but recovered to its previous levels after the official announcement, trading slightly below $0.83.

QAccording to the article, how did the alleged malware in version 2.68 potentially steal user funds?

AThe hidden malicious code allegedly intercepted a user's secret recovery phrase during wallet import and sent it to an external server, giving attackers full access to the wallets and funds.

QWho did the crypto community and Binance's Changpeng Zhao suggest might be responsible for the hack?

AThe crypto community and Changpeng Zhao suggested that the hack was likely carried out by an insider within the Trust Wallet team.

你可能也喜欢

白宫让步扫清伦理障碍,Clarity Act赶上休会前最后的时间窗口?

北京时间7月21日,据多位消息人士透露,特朗普政府已在《数字资产市场结构法案》(Clarity Act)中同意加入伦理条款,并已将文本提交给部分参议院共和党议员。此举被视为扫清了该法案推进的最后主要障碍之一。同时,白宫数字资产顾问委员会执行主任Patrick Witt确认留任,将继续推动法案完成最后冲刺。 Clarity Act旨在为美国数字资产市场建立统一的联邦监管框架,核心目标是明确数字资产的法律属性,并划分美国证券交易委员会(SEC)与商品期货交易委员会(CFTC)的监管职责。法案将数字资产分类监管,以期结束SEC与CFTC长期的监管权争夺,为行业提供明确的合规路径。 过去一年,法案的谈判分歧主要集中在稳定币收益规则、DeFi监管边界以及政府官员与加密行业的利益冲突(即伦理问题)三方面。目前前两大分歧已基本解决,伦理条款成为最后的关键争议点。白宫的让步为法案在参议院获得两党支持并最终表决创造了可能。 然而,法案面临紧迫的时间窗口。美国国会预计在8月中旬进入夏季休会期,留给参议院审议的时间仅剩十几个工作日。行业游说组织美国区块链协会CEO表示,未来几周是关键时刻,若伦理争议得以解决,法案有望在休会前取得突破;否则可能需等待新的政治时机。 如果Clarity Act能成功通过,它将成为美国乃至全球加密货币监管的一个重要转折点,为数字资产市场提供更清晰、稳定的制度框架,降低监管不确定性,并为传统资本进入该领域奠定基础。

Odaily星球日报16分钟前

白宫让步扫清伦理障碍,Clarity Act赶上休会前最后的时间窗口?

Odaily星球日报16分钟前

AI时代、产业革命与未来文明访谈——张丁文:未来不属于追赶者

本文是对90后科技企业家张丁文的专访。他强调,决定企业命运的并非短期风口,而是时代演进的方向。真正的创业者应关注人与数字世界连接方式的根本变化,而非追逐热点。 回顾创业历程,张丁文认为早期摄影社区项目的经历教会他重要一课:用户价值不等同于商业价值,可持续的商业模式至关重要。他将创业视为不断刷新自我认知的过程,企业的边界取决于创始人的认知格局。 面对未来,张丁文将重心从单一产品转向寻找下一代生态“入口”。他深度布局智能穿戴领域,认为智能硬件如手表的价值远超越硬件本身,在于其作为连接健康、支付、社交等服务的平台潜力,是建立长期用户关系、承载复合属性的生态容器。企业的竞争最终是成为用户不可或缺的信任入口。 张丁文进一步将思考提升至产业与文明层面。他认为,企业的发展会经历产品竞争、平台竞争,最终是“文明竞争”,即定义未来运行规则的能力。真正伟大的企业致力于解决时代问题,推动社会效率与公平,其最深的护城河是价值观与长期积累的信任。 他表示,财富只是价值的计量单位,而非目标。下一代企业家不仅需要经营能力,更需要广阔的世界观,在复杂变化中坚持长期主义,保持学习和进化。企业的终极意义在于创造持久的社会价值,成为时代进步的推动者。

marsbit27分钟前

AI时代、产业革命与未来文明访谈——张丁文:未来不属于追赶者

marsbit27分钟前

交易

现货
活动图片