Trust Wallet Users Lost $7 Million in Cryptocurrency Due to Hack

RBK-crypto发布于2025-12-26更新于2025-12-26

文章摘要

On December 26, the team behind Trust Wallet, a popular cryptocurrency wallet owned by Binance, reported a security breach affecting the browser extension version 2.68. According to Binance founder Changpeng Zhao, the incident was the result of a hack, resulting in losses of approximately $7 million. Users of the compromised version were advised to disable or uninstall it and upgrade to the secure version 2.69. The breach did not impact the mobile application. Trust Wallet's native token (TWT) initially dropped around 7% in price but recovered after the official announcement. Zhao stated that Trust Wallet would cover all user losses and urged affected individuals to contact support. Although no official cause was confirmed, reports suggest that version 2.68 contained hidden malicious code that intercepted users' secret recovery phrases during wallet imports, sending them to an external server. This allowed attackers to gain full access to affected wallets. Some community members, including Zhao, suspect the breach may have been an inside job involving a team member.

On the night of December 26, the team of the popular cryptocurrency wallet Trust Wallet reported a security breach that affected the browser application version 2.68. As explained by Binance founder and head of YZi Labs, which owns Trust Wallet, Changpeng Zhao, the incident occurred as a result of a hacker attack, and the damage amounted to $7 million.

Users of version 2.68 should disable or delete this build and only then install the new version 2.69, and under no circumstances should they open or use the unsafe version. The hack only concerns the browser version 2.68 and did not affect the mobile application.

The native token of Trust Wallet (TWT) reacted with a price drop of about 7%, falling for three hours before the team's announcement around 01:20 Moscow time on December 26. After the official announcement, the TWT price recovered to previous levels and the asset is trading slightly below $0.83.

Zhao stated that Trust Wallet will cover all user losses, and affected users were asked to write to the wallet's support service, a link to which can be found on the official website.

No official statements have been made regarding the causes of the hack. But its essence, according to a report by user Akinator on social network X, may be that a hidden malicious code was embedded in version 2.68 of the Trust Wallet browser extension. Akinator was one of the few who reported the hack several hours before the official confirmation from Trust Wallet.

The assumption is that when a user enters their secret phrase to import a wallet, this code stealthily intercepts the data and sends it to an external server. In this way, the attackers could gain full access to the users' wallets and funds.

The crypto community believes that the malicious code was embedded by someone from the cryptocurrency wallet team. In response to a suggestion by X user under the nickname Crazino.eth that the hack was "certainly carried out by an insider working in the team," Zhao replied "probably."

Broke the cycle. How the price of Bitcoin changed over 10 years at Christmas

AI outperformed humans in a crypto trading tournament. What were the results

Miner "capitulation" called a bullish factor for Bitcoin. Why

相关问答

QWhat was the total amount of cryptocurrency lost by Trust Wallet due to the hack?

AUsers lost $7 million in cryptocurrency due to the hack.

QWhich specific version of the Trust Wallet application was compromised in the security breach?

AThe security breach affected the browser application version 2.68.

QWhat was the impact on Trust Wallet's native token (TWT) price following the incident?

AThe native token TWT initially dropped by approximately 7% but recovered to its previous levels after the official announcement, trading slightly below $0.83.

QAccording to the article, how did the alleged malware in version 2.68 potentially steal user funds?

AThe hidden malicious code allegedly intercepted a user's secret recovery phrase during wallet import and sent it to an external server, giving attackers full access to the wallets and funds.

QWho did the crypto community and Binance's Changpeng Zhao suggest might be responsible for the hack?

AThe crypto community and Changpeng Zhao suggested that the hack was likely carried out by an insider within the Trust Wallet team.

你可能也喜欢

Agent 赛马结束,超级工作台上位

过去一个月,腾讯、阿里、字节三家巨头不约而同地开始调整其AI战略:他们并未发布新的Agent(智能体),反而着手缩减和整合现有的众多Agent产品。腾讯将QClaw业务并入其战略级产品WorkBuddy;阿里计划将多款办公智能体整合进“千问办公”,由钉钉统一主导;字节则将其AI编程产品TRAE SOLO更名为TRAE Work,转向工作流协同。这标志着行业对Agent发展的共识正在形成:分散探索阶段结束,资源开始向统一入口集中。 此前,各大厂曾效仿早期互联网,在各个部门和场景广泛布局Agent,导致产品功能重叠、资源分散、成本高昂。随着技术壁垒因开源工具而降低,竞争核心转向算力效率与市场聚焦。当下的调整类似于PC时代的浏览器和移动时代的超级App,预示着AI时代正进入以“超级工作台”统一入口的新阶段。 这一转变背后是市场重心的深刻转移:AI的最大市场并非最初的程序员群体,而是更广阔的数十亿职场人的通用办公场景。超级工作台的目标是成为员工处理邮件、文档、数据、审批等日常工作的首要AI入口,从而掌握企业数据和系统API的调度权。 这并非要取代现有的企业软件(如ERP、CRM),而是通过引入“Skills”(标准化能力接口)让软件能力无缝接入工作台。软件的前端交互界面重要性下降,其价值将转向按能力调用和结果付费。Agent本身也从独立产品,逐渐演变为一种底层能力,最终像电力和网络协议一样,无处不在却又隐于无形。 行业正从Agent作为明星产品的第一阶段,快速迈向其作为统一工作入口的第二阶段,并终将进入其化为无形基础设施的第三阶段。

marsbit13分钟前

Agent 赛马结束,超级工作台上位

marsbit13分钟前

Michael Saylor:反对 BIP—110 的 110 个理由

Michael Saylor发表长文,系统性地阐述了反对比特币改进提案BIP 110的110个理由。他认为,BIP 110旨在通过修改共识规则来限制区块链上的非支付类数据存储(如铭文等),但其根本动机源于对特定应用的价值判断和“垃圾信息”的担忧,而非修复协议的安全或技术漏洞。Saylor强调,比特币的核心优势在于其中立性、硬共识和开放的无许可创新环境。 他反对BIP 110的主要论点包括:该提案将社会性价值判断提升为协议法律,破坏了规则的中立性;其举证不足,未能量化所谓“紧急威胁”的具体影响;提案捆绑了七项过于宽泛的技术限制,可能误伤未来的合法金融应用与升级路径;临时性的共识规则增加了系统复杂性和协调风险;可能对矿工收入、网络安全和长期创新产生不确定的负面经济影响。 Saylor指出,比特币已具备区块大小和手续费市场等中立的调节机制,节点和矿工也可以自行制定中继和打包策略,这些是比动用共识分叉更优的解决方案。他警告,BIP 110会开创一个危险的先例,即通过协议规则排除不受欢迎的用途,这可能导致未来更多的治理冲突,并扼杀尚未被发现的创新。他呼吁社区应完善测量、采用更精准的资源定价机制,并等待压倒性的共识,而非仓促实施一个可能弊大于利的方案。他最终主张,比特币需要的是“中立性的守护者”,而非“救赎性的守护者”。

marsbit29分钟前

Michael Saylor:反对 BIP—110 的 110 个理由

marsbit29分钟前

United Stables 市值突破 10 亿美元,Chainlink 数据喂价保障 U 代币抵押资产

United Stables发行的稳定币U市值已突破10亿美元,其关键在于采用了Chainlink数据预言机网络来提供抵押品定价和数据基础设施。 这一里程碑事件突显了在稳定币领域,可靠的数据基础设施已非可选,而是必需品。稳定币的价值依赖于用户对其抵押品、定价和赎回机制的信任,若相关数据薄弱或不透明,将阻碍其在DeFi中的整合与应用。Chainlink通过提供外部数据源,为U稳定币生态系统支持自动化的抵押品审计和定价。 需要明确的是,Chainlink在此扮演的是基础设施角色,它本身并不直接赋予稳定币价值,而是通过提供可靠的数据层,使其他系统能更安全地与稳定币交互。U市值的增长也表明,尽管稳定币市场仍由巨头主导,但新的发行方正在凭借强大的基础设施支持找到发展空间。 对于LINK持有者而言,这一集成案例巩固了Chainlink在稳定币关键基础设施(如抵押品验证)领域的战略地位,增强了其网络效应和机构相关性。然而,单一稳定币的增长并不能直接等同于LINK代币的费用增长或价格驱动,其影响更多是间接和战略层面的。核心在于,稳定币正变得越来越重要、受监管且依赖基础设施,而Chainlink正将自己定位为该环境中的关键服务提供商。

bitcoinist1小时前

United Stables 市值突破 10 亿美元,Chainlink 数据喂价保障 U 代币抵押资产

bitcoinist1小时前

交易

现货
活动图片