ZachXBT flags suspected Trust Wallet extension issue as users report drained funds

ambcrypto发布于2025-12-25更新于2025-12-25

文章摘要

Security concerns emerged around the Trust Wallet browser extension on December 25, after blockchain investigator ZachXBT flagged suspicious activity potentially linked to a recent update. Reports suggest a supply-chain compromise may have been introduced in a December 24 update, where newly added code could silently exfiltrate sensitive wallet data—particularly during seed phrase imports—leading to immediate fund draining. Multiple users reported losses, with unverified estimates exceeding $2 million. The malicious code allegedly sent data to a recently registered external domain mimicking Trust Wallet infrastructure. The issue appears limited to the browser extension, with no evidence of mobile app compromise. Trust Wallet has not yet issued an official response or advisory. Researchers emphasize the situation remains under investigation, warning users to avoid importing seed phrases into the extension until clarified. If confirmed, this would represent a significant supply-chain attack.

Security concerns have emerged around the Trust Wallet browser extension on 25 December, after blockchain investigator ZachXBT flagged suspicious activity potentially linked to a recent update, prompting warnings from developers and security-focused accounts.

According to posts circulating on X, the issue may stem from a suspected supply-chain compromise introduced in a 24 December browser extension update.

Newly added code within the extension could silently exfiltrate sensitive wallet data when users import a seed phrase. The claims suggest that this has led to immediate wallet draining.

Alleged Trust Wallet malicious code and data exfiltration claims

Developers examining the extension allege that a JavaScript file added in the update contains logic disguised as analytics.

The code is said to activate specifically when a seed phrase is imported. It then silently transmits wallet-related data to an external domain designed to resemble official Trust Wallet infrastructure.

The domain referenced in the reports was reportedly registered only days ago and has since gone offline.

Researchers argue that its recent creation and the timing of the extension update raise concerns about a coordinated supply-chain attack rather than user-side phishing.

Users report wallet drains following seed imports

Multiple users have reported wallets being drained shortly after importing seed phrases into the Trust Wallet browser extension.

Publicly shared estimates suggest that more than $2 million may have been lost. Although these figures have not been independently verified.

Analysts indicate that funds were routed through multiple addresses, a pattern more commonly associated with automated exploitation than isolated user error.

Scope appears limited to browser extension

At this stage, there is no indication that Trust Wallet’s mobile applications are affected.

The warnings circulating online are focused specifically on the browser extension. This is where update mechanisms and third-party dependencies present higher supply-chain risk.

Users are advised not to import seed phrases into the Trust Wallet browser extension until further clarification is provided.

No official response from Trust Wallet yet

As of the time of writing, Trust Wallet has not issued any public response, clarification, or security advisory addressing the allegations.

There has been no confirmation or denial of the claims, nor any announcement of an extension, rollback, or emergency patch.

Investigation ongoing

Researchers have emphasized that the situation remains under active investigation. Conclusions should not be drawn until the extension code and related on-chain activity have been fully reviewed.

If confirmed, the incident would represent a serious supply-chain compromise.

This is a class of attack that differs significantly from phishing or user-side mistakes. Also, it has historically resulted in rapid, large-scale losses across the crypto ecosystem.


Final Thoughts

  • The allegations point to a potentially serious supply-chain risk affecting wallet extensions, underscoring how code updates can become a critical attack vector if compromised.
  • With no response yet from Trust Wallet, users and researchers are left relying on independent investigation as scrutiny around the incident continues.

相关问答

QWhat security concern was flagged by ZachXBT regarding the Trust Wallet browser extension?

AZachXBT flagged suspicious activity potentially linked to a recent update of the Trust Wallet browser extension, suggesting it could be a supply-chain compromise that leads to the silent exfiltration of sensitive wallet data and immediate draining of funds.

QHow does the suspected malicious code in the Trust Wallet extension allegedly operate?

AThe malicious JavaScript code, added in an update and disguised as analytics, is said to activate when a user imports a seed phrase. It then silently transmits wallet-related data to an external domain designed to look like official Trust Wallet infrastructure.

QWhat is the estimated financial impact based on user reports, and how were the funds moved?

APublicly shared estimates suggest that more than $2 million may have been lost, though this is unverified. Analysts indicate the funds were routed through multiple addresses, a pattern associated with automated exploitation rather than isolated user error.

QAre Trust Wallet's mobile applications also affected by this suspected compromise?

ANo, there is no indication that Trust Wallet’s mobile applications are affected. The warnings are specifically focused on the browser extension, which has higher supply-chain risk due to its update mechanisms and third-party dependencies.

QWhat is the current status of Trust Wallet's official response to these allegations?

AAs of the time the article was written, Trust Wallet had not issued any public response, clarification, or security advisory addressing the allegations. There has been no confirmation, denial, or announcement of an emergency patch.

你可能也喜欢

铜,2026年的黄金

过去两年,AI 的故事主要围绕芯片展开,但 AI 基础设施远不止于此,它需要电网、电缆、冷却系统等大量金属。市场对铜的关注度急剧上升,其叙事已从单纯的工业周期指标,转变为一个具有结构性需求支撑的战略性资产。 这一变化的核心在于,铜已成为电气化时代的基石。AI 数据中心、电网扩建、新能源车、储能及再工业化等趋势都在拉动铜的需求。数据显示,AI 数据中心的铜需求将从 2024 年的约 50 万吨,大幅增长至 2050 年的约 300 万吨。更重要的是,这些新兴需求与建筑、空调等传统需求共同构成了强劲的总需求。 供给端则面临长期瓶颈。新铜矿从发现到投产平均需要约 17 年,全球铜矿品位持续下降,新发现矿床稀少,建设周期长且成本攀升。国际能源署估算,到 2035 年,铜市场可能出现 30% 的供给缺口。此外,冶炼端加工费跌至历史低位,凸显了上游矿石供应的紧张。 因此,铜的稀缺性开始被市场重新定价,吸引了宏观资金的关注。知名投资人如 Stanley Druckenmiller 将铜作为宏观对冲工具,而 Pierre Andurand 等交易员则预测铜价可能飙升至每吨 40,000 美元。这种“黄金化”趋势也体现在铜矿股上,它们作为铜价的杠杆,提供了高弹性,但也伴随着资源国政策、成本通胀等复杂风险。 尽管铜仍会受经济周期影响而波动,但其长期供给瓶颈和结构性需求增长已为其构筑了新的价值底线。铜的“黄金化”叙事,可能才刚刚拉开序幕。

marsbit18分钟前

铜,2026年的黄金

marsbit18分钟前

pump.fun的新功能,把《黑镜》搬进了现实

文章以《黑镜》第七季第一集的故事开篇:一对夫妻因妻子患脑瘤,被迫接受科技公司的“订阅式”生命维持方案,丈夫为支付不断上涨的费用,不得不在直播平台完成羞辱性任务赚钱,最终悲剧收场。这集剧情与近期加密货币平台pump.fun上线的新功能“Pump.fun Go”形成了令人不安的呼应。 该功能允许用户发布有偿悬赏任务,迅速催生了各种为博流量而进行的极端行为。例如,有人悬赏40 SOL(约2600美元)要求将他人在额头纹上特定代币名称。一名印度男子为此忍受痛苦完成了纹身,虽因拼写错误一度被拒,但最终通过补纹获得了赏金,并因事件带来的流量额外获利数万美元。类似“赏金换纹身”的任务甚至出现过14000美元的高价。参与者坦言动机很简单:“我们需要钱。” 除了纹身,悬赏任务还包括吃虫子、喝辣椒酱等挑战,赏金仅百余美元,却仍有人完成。文章指出,这种“标价自由”容易放大黑暗,让人联想到早期直播中为打赏过度饮酒、暴食致死的案例。监管虽能部分遏制过度物化,但无法消除那些因迫切需要金钱而接受极端任务的人。 然而,平台上也存在一些温暖或有趣的悬赏,如在纽约组织“反抗工作”集会、向陌生人释放善意、组织社区食物捐赠,甚至“帮助老奶奶过马路”等。这些任务展现了在流量与金钱驱动的环境中,依然存在寻求联结与善意的尝试。 文章最后反思,技术放大了人性中的光明与黑暗,我们无法逃避其中冰冷的一面,但依然可以期待和创造更多光明。

marsbit23分钟前

pump.fun的新功能,把《黑镜》搬进了现实

marsbit23分钟前

交易

现货
合约
活动图片