ZachXBT flags suspected Trust Wallet extension issue as users report drained funds

ambcrypto发布于2025-12-25更新于2025-12-25

文章摘要

Security concerns emerged around the Trust Wallet browser extension on December 25, after blockchain investigator ZachXBT flagged suspicious activity potentially linked to a recent update. Reports suggest a supply-chain compromise may have been introduced in a December 24 update, where newly added code could silently exfiltrate sensitive wallet data—particularly during seed phrase imports—leading to immediate fund draining. Multiple users reported losses, with unverified estimates exceeding $2 million. The malicious code allegedly sent data to a recently registered external domain mimicking Trust Wallet infrastructure. The issue appears limited to the browser extension, with no evidence of mobile app compromise. Trust Wallet has not yet issued an official response or advisory. Researchers emphasize the situation remains under investigation, warning users to avoid importing seed phrases into the extension until clarified. If confirmed, this would represent a significant supply-chain attack.

Security concerns have emerged around the Trust Wallet browser extension on 25 December, after blockchain investigator ZachXBT flagged suspicious activity potentially linked to a recent update, prompting warnings from developers and security-focused accounts.

According to posts circulating on X, the issue may stem from a suspected supply-chain compromise introduced in a 24 December browser extension update.

Newly added code within the extension could silently exfiltrate sensitive wallet data when users import a seed phrase. The claims suggest that this has led to immediate wallet draining.

Alleged Trust Wallet malicious code and data exfiltration claims

Developers examining the extension allege that a JavaScript file added in the update contains logic disguised as analytics.

The code is said to activate specifically when a seed phrase is imported. It then silently transmits wallet-related data to an external domain designed to resemble official Trust Wallet infrastructure.

The domain referenced in the reports was reportedly registered only days ago and has since gone offline.

Researchers argue that its recent creation and the timing of the extension update raise concerns about a coordinated supply-chain attack rather than user-side phishing.

Users report wallet drains following seed imports

Multiple users have reported wallets being drained shortly after importing seed phrases into the Trust Wallet browser extension.

Publicly shared estimates suggest that more than $2 million may have been lost. Although these figures have not been independently verified.

Analysts indicate that funds were routed through multiple addresses, a pattern more commonly associated with automated exploitation than isolated user error.

Scope appears limited to browser extension

At this stage, there is no indication that Trust Wallet’s mobile applications are affected.

The warnings circulating online are focused specifically on the browser extension. This is where update mechanisms and third-party dependencies present higher supply-chain risk.

Users are advised not to import seed phrases into the Trust Wallet browser extension until further clarification is provided.

No official response from Trust Wallet yet

As of the time of writing, Trust Wallet has not issued any public response, clarification, or security advisory addressing the allegations.

There has been no confirmation or denial of the claims, nor any announcement of an extension, rollback, or emergency patch.

Investigation ongoing

Researchers have emphasized that the situation remains under active investigation. Conclusions should not be drawn until the extension code and related on-chain activity have been fully reviewed.

If confirmed, the incident would represent a serious supply-chain compromise.

This is a class of attack that differs significantly from phishing or user-side mistakes. Also, it has historically resulted in rapid, large-scale losses across the crypto ecosystem.


Final Thoughts

  • The allegations point to a potentially serious supply-chain risk affecting wallet extensions, underscoring how code updates can become a critical attack vector if compromised.
  • With no response yet from Trust Wallet, users and researchers are left relying on independent investigation as scrutiny around the incident continues.

相关问答

QWhat security concern was flagged by ZachXBT regarding the Trust Wallet browser extension?

AZachXBT flagged suspicious activity potentially linked to a recent update of the Trust Wallet browser extension, suggesting it could be a supply-chain compromise that leads to the silent exfiltration of sensitive wallet data and immediate draining of funds.

QHow does the suspected malicious code in the Trust Wallet extension allegedly operate?

AThe malicious JavaScript code, added in an update and disguised as analytics, is said to activate when a user imports a seed phrase. It then silently transmits wallet-related data to an external domain designed to look like official Trust Wallet infrastructure.

QWhat is the estimated financial impact based on user reports, and how were the funds moved?

APublicly shared estimates suggest that more than $2 million may have been lost, though this is unverified. Analysts indicate the funds were routed through multiple addresses, a pattern associated with automated exploitation rather than isolated user error.

QAre Trust Wallet's mobile applications also affected by this suspected compromise?

ANo, there is no indication that Trust Wallet’s mobile applications are affected. The warnings are specifically focused on the browser extension, which has higher supply-chain risk due to its update mechanisms and third-party dependencies.

QWhat is the current status of Trust Wallet's official response to these allegations?

AAs of the time the article was written, Trust Wallet had not issued any public response, clarification, or security advisory addressing the allegations. There has been no confirmation, denial, or announcement of an emergency patch.

你可能也喜欢

以太坊上形成了长达43天的质押队列:但专家认为,这并非真正的看涨信号

以太坊网络上因希望进行质押的验证者数量激增,形成了约250万枚ETH的激活队列,新参与者需等待约43天才能激活其代币。然而,Sygnum Bank的托管与质押部门负责人托马斯·布伦纳指出,这种漫长的等待不应被直接解读为强烈的看涨信号。 布伦纳表示,验证者队列的拥堵虽然反映了机构需求,但也受到以太坊协议技术特性的显著影响。他提到,自Dencun升级后,每日验证者吞吐量被限制在约57,600枚ETH,且这一限制在Pectra升级中并未提高。Pectra升级允许单个验证者最多持有2048枚ETH并支持自动复利功能,大型质押运营商可以向现有验证者追加ETH而非创建新验证者。但即便仅向现有验证者添加1枚ETH,该交易也会与新的质押者一同进入相同的激活队列。 因此,布伦纳认为,并非队列中的所有ETH都源自新投资者的需求,其中部分积累来自于已质押ETH的再分配、对现有验证者的补充以及复利过程。他指出,一个更重要的市场信号是提款队列几乎为空,这表明现有参与者正在维持其网络头寸,显示出真实的信心。 目前,以太坊网络上已质押约4120万枚ETH,约占流通总量的33.8%。布伦纳还强调,尽管ETH价格有所疲软,机构投资者并未放弃质押。许多机构将质押收益视为以太坊内在的基本特性,但机构参与的最大障碍之一仍是隐私问题。由于验证者地址、存款地址和提款交易在区块链上可被追踪,机构投资者对扩大其质押规模持谨慎态度,隐私问题仍是制约以太坊机构质押市场更快增长的主要障碍。

cryptonews.ru1小时前

以太坊上形成了长达43天的质押队列:但专家认为,这并非真正的看涨信号

cryptonews.ru1小时前

韩国银行公布代币化存款测试结果

韩国央行公布了其代币化存款测试结果。该试点项目涉及28家央行及国际金融机构,韩方参与者包括KB国民银行、NH农协银行、新韩银行、友利银行和韩亚银行。 测试显示,从支付指令到最终结算的整个过程平均耗时约1分20秒,其中最终结算平均需80秒。在测试中,参与者执行了30笔交易,覆盖17种不同场景,包括企业和银行间转账,并涉及韩元、美元和欧元等六种货币。交易总额约合99.5万美元。 央行表示,平台在整个测试期间运行稳定,尽管仅在部分连接现有银行基础设施的环境下运作。即使在支付网络和银行系统兼容性有限的情况下,代币化存款结算仍能无缝、快速、透明地完成。 此外,韩国央行还通过Project Agora平台,在NH农协银行和新韩银行之间完成了一笔2000万韩元(约1.389万美元)的内部转账测试。该交易涉及手动连接其批发型央行数字货币(CBDC)平台Project Hangang至央行现有网络,以验证兼容性。 同时,韩国KB国民银行与日本三菱日联金融集团(MUFG Bank)也完成了使用存款代币的支付测试。这些代币是银行在试点中发行的数字凭证,并非由央行直接发行。韩国央行计划继续测试存款代币支付。 去年,韩国当局曾承诺加强对韩元稳定币的监管,要求其发行必须获得韩国央行和金融服务委员会(FSC)的批准。

cryptonews.ru2小时前

韩国银行公布代币化存款测试结果

cryptonews.ru2小时前

交易

现货
活动图片