ZachXBT flags suspected Trust Wallet extension issue as users report drained funds

ambcrypto发布于2025-12-25更新于2025-12-25

文章摘要

Security concerns emerged around the Trust Wallet browser extension on December 25, after blockchain investigator ZachXBT flagged suspicious activity potentially linked to a recent update. Reports suggest a supply-chain compromise may have been introduced in a December 24 update, where newly added code could silently exfiltrate sensitive wallet data—particularly during seed phrase imports—leading to immediate fund draining. Multiple users reported losses, with unverified estimates exceeding $2 million. The malicious code allegedly sent data to a recently registered external domain mimicking Trust Wallet infrastructure. The issue appears limited to the browser extension, with no evidence of mobile app compromise. Trust Wallet has not yet issued an official response or advisory. Researchers emphasize the situation remains under investigation, warning users to avoid importing seed phrases into the extension until clarified. If confirmed, this would represent a significant supply-chain attack.

Security concerns have emerged around the Trust Wallet browser extension on 25 December, after blockchain investigator ZachXBT flagged suspicious activity potentially linked to a recent update, prompting warnings from developers and security-focused accounts.

According to posts circulating on X, the issue may stem from a suspected supply-chain compromise introduced in a 24 December browser extension update.

Newly added code within the extension could silently exfiltrate sensitive wallet data when users import a seed phrase. The claims suggest that this has led to immediate wallet draining.

Alleged Trust Wallet malicious code and data exfiltration claims

Developers examining the extension allege that a JavaScript file added in the update contains logic disguised as analytics.

The code is said to activate specifically when a seed phrase is imported. It then silently transmits wallet-related data to an external domain designed to resemble official Trust Wallet infrastructure.

The domain referenced in the reports was reportedly registered only days ago and has since gone offline.

Researchers argue that its recent creation and the timing of the extension update raise concerns about a coordinated supply-chain attack rather than user-side phishing.

Users report wallet drains following seed imports

Multiple users have reported wallets being drained shortly after importing seed phrases into the Trust Wallet browser extension.

Publicly shared estimates suggest that more than $2 million may have been lost. Although these figures have not been independently verified.

Analysts indicate that funds were routed through multiple addresses, a pattern more commonly associated with automated exploitation than isolated user error.

Scope appears limited to browser extension

At this stage, there is no indication that Trust Wallet’s mobile applications are affected.

The warnings circulating online are focused specifically on the browser extension. This is where update mechanisms and third-party dependencies present higher supply-chain risk.

Users are advised not to import seed phrases into the Trust Wallet browser extension until further clarification is provided.

No official response from Trust Wallet yet

As of the time of writing, Trust Wallet has not issued any public response, clarification, or security advisory addressing the allegations.

There has been no confirmation or denial of the claims, nor any announcement of an extension, rollback, or emergency patch.

Investigation ongoing

Researchers have emphasized that the situation remains under active investigation. Conclusions should not be drawn until the extension code and related on-chain activity have been fully reviewed.

If confirmed, the incident would represent a serious supply-chain compromise.

This is a class of attack that differs significantly from phishing or user-side mistakes. Also, it has historically resulted in rapid, large-scale losses across the crypto ecosystem.


Final Thoughts

  • The allegations point to a potentially serious supply-chain risk affecting wallet extensions, underscoring how code updates can become a critical attack vector if compromised.
  • With no response yet from Trust Wallet, users and researchers are left relying on independent investigation as scrutiny around the incident continues.

相关问答

QWhat security concern was flagged by ZachXBT regarding the Trust Wallet browser extension?

AZachXBT flagged suspicious activity potentially linked to a recent update of the Trust Wallet browser extension, suggesting it could be a supply-chain compromise that leads to the silent exfiltration of sensitive wallet data and immediate draining of funds.

QHow does the suspected malicious code in the Trust Wallet extension allegedly operate?

AThe malicious JavaScript code, added in an update and disguised as analytics, is said to activate when a user imports a seed phrase. It then silently transmits wallet-related data to an external domain designed to look like official Trust Wallet infrastructure.

QWhat is the estimated financial impact based on user reports, and how were the funds moved?

APublicly shared estimates suggest that more than $2 million may have been lost, though this is unverified. Analysts indicate the funds were routed through multiple addresses, a pattern associated with automated exploitation rather than isolated user error.

QAre Trust Wallet's mobile applications also affected by this suspected compromise?

ANo, there is no indication that Trust Wallet’s mobile applications are affected. The warnings are specifically focused on the browser extension, which has higher supply-chain risk due to its update mechanisms and third-party dependencies.

QWhat is the current status of Trust Wallet's official response to these allegations?

AAs of the time the article was written, Trust Wallet had not issued any public response, clarification, or security advisory addressing the allegations. There has been no confirmation, denial, or announcement of an emergency patch.

你可能也喜欢

意大利央行未发现稳定币在汇款中存在系统性优势

意大利银行的一项研究显示,稳定币在跨境汇款中并未展现出持续的成本与速度优势。其潜在优势被法币出入金手续费以及本地支付基础设施的处理流程所抵消。 研究比较了通过200 USDC在意大利与巴西、阿根廷、日本、阿联酋和南非等10条双向通道进行汇款的成本与结算时间,并与标准汇款服务进行对比。 结果显示,稳定币转账的总成本在0.3%到近9%之间波动,具体取决于汇款方向。在具备即时支付系统的通道中,结算可在20分钟内完成;若缺乏此类基础设施,则需一至两个工作日。 主要成本和延迟源于货币兑换以及当地基础设施的质量。区块链网络手续费并非主要因素。 尽管在大多数研究通道中,稳定币成本低于世界银行统计的全球平均汇款成本(6.65%),但与传统汇款服务商Wise相比,仅在七条可比通道中的三条具备成本优势。 研究者认为,若稳定币能直接用于商品服务消费而无需兑换成当地货币,其优势将更为明显。同时指出,禁令性监管无法消除市场对稳定币的需求,而过严的规则只会增加零售用户的使用难度。 此外,报告提及,稳定币总市值在7月已从5月峰值下跌超100亿美元,至约3100亿美元,创下自2022年5月Terra崩溃以来的最大月度跌幅。

cryptonews.ru2小时前

意大利央行未发现稳定币在汇款中存在系统性优势

cryptonews.ru2小时前

比特币热潮正酣:塞勒尔新声明引发关于购买的猜测

纳斯达克上市公司MicroStrategy(代码:MSTR)的执行董事长迈克尔·塞勒于8月2日发布信息“Bitcoin Drive engaged”(比特币驱动已启动),再次引发市场对于该公司将在周一宣布新一轮比特币购买的猜测。其周日的帖子附带了该公司惯用的购买追踪图表,这符合塞勒通常在每周财报发布前暗示其金库变动的做法。 塞勒的附图报告显示,MicroStrategy的比特币储备为843,775枚BTC,市值约532.5亿美元。平均购买成本为每枚75,653美元,未实现亏损为105.8亿美元(-16.58%)。截至8月2日,累计进行了113次购买操作。 此前在7月27日,类似的周日信号曾预告了公司的公告,当时塞勒发文称“我们还需要一种颜色”,随后MicroStrategy披露了其更大的现金储备。这种时间上的巧合强化了市场对周一将发布新金库状况公告的预期。 然而,该公司实时账本显示,在最近两次共计出售3,588枚BTC(包括1,363枚和2,225枚)后,其比特币储备已从847,363枚降至843,775枚。根据提交给美国证券交易委员会(SEC)的文件,这些出售是为了资助优先股支付并补充美元储备。最近的报告还显示,在截至7月26日的一周内,MicroStrategy没有购买任何比特币,同时将其美元储备增加至约37.5亿美元,这使其优先股股息和债务利息的预计覆盖期限延长至约2.1年。 财务风险依然高企,该公司报告2026年第二季度运营亏损83.3亿美元,与上年同期140.3亿美元的运营利润形成急剧逆转。这些业绩包含了公司数字资产方面83.2亿美元的未实现亏损,而2025年第二季度为未实现利润140.5亿美元。 管理层还可能通过额外出售比特币获得高达12.5亿美元,以补充用于支付优先股股息和债务利息的美元储备。因此,预计周一的披露将揭示“Bitcoin Drive”信息是否标志着资产积累的恢复,因为MicroStrategy需要在平衡其843,775枚BTC自有储备与不断增长的现金负债和积极的资本管理之间做出抉择。

cryptonews.ru2小时前

比特币热潮正酣:塞勒尔新声明引发关于购买的猜测

cryptonews.ru2小时前

交易

现货
活动图片