ZachXBT flags suspected Trust Wallet extension issue as users report drained funds

ambcrypto发布于2025-12-25更新于2025-12-25

文章摘要

Security concerns emerged around the Trust Wallet browser extension on December 25, after blockchain investigator ZachXBT flagged suspicious activity potentially linked to a recent update. Reports suggest a supply-chain compromise may have been introduced in a December 24 update, where newly added code could silently exfiltrate sensitive wallet data—particularly during seed phrase imports—leading to immediate fund draining. Multiple users reported losses, with unverified estimates exceeding $2 million. The malicious code allegedly sent data to a recently registered external domain mimicking Trust Wallet infrastructure. The issue appears limited to the browser extension, with no evidence of mobile app compromise. Trust Wallet has not yet issued an official response or advisory. Researchers emphasize the situation remains under investigation, warning users to avoid importing seed phrases into the extension until clarified. If confirmed, this would represent a significant supply-chain attack.

Security concerns have emerged around the Trust Wallet browser extension on 25 December, after blockchain investigator ZachXBT flagged suspicious activity potentially linked to a recent update, prompting warnings from developers and security-focused accounts.

According to posts circulating on X, the issue may stem from a suspected supply-chain compromise introduced in a 24 December browser extension update.

Newly added code within the extension could silently exfiltrate sensitive wallet data when users import a seed phrase. The claims suggest that this has led to immediate wallet draining.

Alleged Trust Wallet malicious code and data exfiltration claims

Developers examining the extension allege that a JavaScript file added in the update contains logic disguised as analytics.

The code is said to activate specifically when a seed phrase is imported. It then silently transmits wallet-related data to an external domain designed to resemble official Trust Wallet infrastructure.

The domain referenced in the reports was reportedly registered only days ago and has since gone offline.

Researchers argue that its recent creation and the timing of the extension update raise concerns about a coordinated supply-chain attack rather than user-side phishing.

Users report wallet drains following seed imports

Multiple users have reported wallets being drained shortly after importing seed phrases into the Trust Wallet browser extension.

Publicly shared estimates suggest that more than $2 million may have been lost. Although these figures have not been independently verified.

Analysts indicate that funds were routed through multiple addresses, a pattern more commonly associated with automated exploitation than isolated user error.

Scope appears limited to browser extension

At this stage, there is no indication that Trust Wallet’s mobile applications are affected.

The warnings circulating online are focused specifically on the browser extension. This is where update mechanisms and third-party dependencies present higher supply-chain risk.

Users are advised not to import seed phrases into the Trust Wallet browser extension until further clarification is provided.

No official response from Trust Wallet yet

As of the time of writing, Trust Wallet has not issued any public response, clarification, or security advisory addressing the allegations.

There has been no confirmation or denial of the claims, nor any announcement of an extension, rollback, or emergency patch.

Investigation ongoing

Researchers have emphasized that the situation remains under active investigation. Conclusions should not be drawn until the extension code and related on-chain activity have been fully reviewed.

If confirmed, the incident would represent a serious supply-chain compromise.

This is a class of attack that differs significantly from phishing or user-side mistakes. Also, it has historically resulted in rapid, large-scale losses across the crypto ecosystem.


Final Thoughts

  • The allegations point to a potentially serious supply-chain risk affecting wallet extensions, underscoring how code updates can become a critical attack vector if compromised.
  • With no response yet from Trust Wallet, users and researchers are left relying on independent investigation as scrutiny around the incident continues.

相关问答

QWhat security concern was flagged by ZachXBT regarding the Trust Wallet browser extension?

AZachXBT flagged suspicious activity potentially linked to a recent update of the Trust Wallet browser extension, suggesting it could be a supply-chain compromise that leads to the silent exfiltration of sensitive wallet data and immediate draining of funds.

QHow does the suspected malicious code in the Trust Wallet extension allegedly operate?

AThe malicious JavaScript code, added in an update and disguised as analytics, is said to activate when a user imports a seed phrase. It then silently transmits wallet-related data to an external domain designed to look like official Trust Wallet infrastructure.

QWhat is the estimated financial impact based on user reports, and how were the funds moved?

APublicly shared estimates suggest that more than $2 million may have been lost, though this is unverified. Analysts indicate the funds were routed through multiple addresses, a pattern associated with automated exploitation rather than isolated user error.

QAre Trust Wallet's mobile applications also affected by this suspected compromise?

ANo, there is no indication that Trust Wallet’s mobile applications are affected. The warnings are specifically focused on the browser extension, which has higher supply-chain risk due to its update mechanisms and third-party dependencies.

QWhat is the current status of Trust Wallet's official response to these allegations?

AAs of the time the article was written, Trust Wallet had not issued any public response, clarification, or security advisory addressing the allegations. There has been no confirmation, denial, or announcement of an emergency patch.

你可能也喜欢

一周精选丨股市史诗级震荡,长鑫科技上市重塑存储格局,Saylor目标9月8日前后推动STRC回锚

PANews精选一周要闻。AI领域热度持续,智能体钱包成为加密支付新战场,Coinbase等巨头布局小额支付以抢占AI经济入口。韩国股市经历剧烈震荡,多次熔断并引发清算风暴,科技股暴跌堪比币圈行情。算力产业进入系统化竞争阶段,国产GPU与AI智能体(Agent)结合成为焦点。 宏观方面,长鑫科技上市后市值巨大,在经历长期亏损后单季度盈利显著。花旗银行预警未来大宗商品市场可能出现的极端风险。美联储维持利率不变,但内部出现罕见分歧,释放鹰派信号。 机构观点显示,有分析认为当前AI板块调整是去杠杆过程,长期牛市逻辑不变。中国散户在传统投资渠道收窄后,正转向加密资产等新途径。市场讨论未来货币形态,比特币价值受关注。比特币矿企被指出需向能源综合服务商转型。 市场热点包括NFT交易通过“抽卡”等新玩法激活流动性,但部分加密协议面临收入增长与代币价格脱钩的问题。RWA(真实世界资产)链上规模增长但利用率不足。以太坊公布2030年长期发展蓝图,Lido也进行了大规模升级。 行业动态方面,新银行领域面临洗牌,稳定币竞争加剧。重点资讯包括:美股收涨,Coinbase股价波动;MicroStrategy增持比特币并计划推动STRC回锚;多家AI与加密公司获得融资;韩国股市与长鑫科技股价出现大幅波动;巨鲸交易员在AI相关交易中获利了结。

marsbit14分钟前

一周精选丨股市史诗级震荡,长鑫科技上市重塑存储格局,Saylor目标9月8日前后推动STRC回锚

marsbit14分钟前

当市场开始质疑AI资本开支:五家科技巨头Q2财报全解析

2026年7月下旬,谷歌、英特尔、微软、Meta、苹果五家科技巨头相继发布第二季度财报。尽管各家营收和利润普遍超预期,且AI相关业务(如谷歌云、英特尔数据中心、Azure)增长强劲,但市场反应出现显著分化,焦点已从需求转向资本开支与现金流回报。 **谷歌**营收创十二季度双位数增长纪录,云业务同比大增82%,但资本支出同比翻倍至449亿美元,并上调全年指引,导致上市以来首次录得负自由现金流,股价下跌。 **英特尔**营收创十五年来最强增速,数据中心与AI业务表现突出,但因大幅上调资本支出指引引发对自由现金流的担忧,股价经历“过山车”式反转。 **微软**业绩超预期,Azure年收入首破千亿美元,同时通过会计调整下调资本支出指引并承诺正自由现金流,股价创十八年来最佳单日表现。 **Meta**广告业务稳健,营收增长28%,但因成本费用大增55%及资本开支指引上调,自由现金流同比萎缩逾90%,遭遇猛烈抛售。 **苹果**营收利润创同期新高,但下一季度营收指引上限低于预期,叠加供应链瓶颈担忧,股价大跌,市值单日蒸发超3000亿美元。 总结而言,本财报季显示AI需求依然强劲,但市场对巨额资本开支何时转化为实际回报的耐心正在消耗。各公司对资本开支节奏与现金流前景的表述,已成为影响股价的关键因素。

Odaily星球日报24分钟前

当市场开始质疑AI资本开支:五家科技巨头Q2财报全解析

Odaily星球日报24分钟前

交易

现货
活动图片