ZachXBT flags suspected Trust Wallet extension issue as users report drained funds

ambcrypto发布于2025-12-25更新于2025-12-25

文章摘要

Security concerns emerged around the Trust Wallet browser extension on December 25, after blockchain investigator ZachXBT flagged suspicious activity potentially linked to a recent update. Reports suggest a supply-chain compromise may have been introduced in a December 24 update, where newly added code could silently exfiltrate sensitive wallet data—particularly during seed phrase imports—leading to immediate fund draining. Multiple users reported losses, with unverified estimates exceeding $2 million. The malicious code allegedly sent data to a recently registered external domain mimicking Trust Wallet infrastructure. The issue appears limited to the browser extension, with no evidence of mobile app compromise. Trust Wallet has not yet issued an official response or advisory. Researchers emphasize the situation remains under investigation, warning users to avoid importing seed phrases into the extension until clarified. If confirmed, this would represent a significant supply-chain attack.

Security concerns have emerged around the Trust Wallet browser extension on 25 December, after blockchain investigator ZachXBT flagged suspicious activity potentially linked to a recent update, prompting warnings from developers and security-focused accounts.

According to posts circulating on X, the issue may stem from a suspected supply-chain compromise introduced in a 24 December browser extension update.

Newly added code within the extension could silently exfiltrate sensitive wallet data when users import a seed phrase. The claims suggest that this has led to immediate wallet draining.

Alleged Trust Wallet malicious code and data exfiltration claims

Developers examining the extension allege that a JavaScript file added in the update contains logic disguised as analytics.

The code is said to activate specifically when a seed phrase is imported. It then silently transmits wallet-related data to an external domain designed to resemble official Trust Wallet infrastructure.

The domain referenced in the reports was reportedly registered only days ago and has since gone offline.

Researchers argue that its recent creation and the timing of the extension update raise concerns about a coordinated supply-chain attack rather than user-side phishing.

Users report wallet drains following seed imports

Multiple users have reported wallets being drained shortly after importing seed phrases into the Trust Wallet browser extension.

Publicly shared estimates suggest that more than $2 million may have been lost. Although these figures have not been independently verified.

Analysts indicate that funds were routed through multiple addresses, a pattern more commonly associated with automated exploitation than isolated user error.

Scope appears limited to browser extension

At this stage, there is no indication that Trust Wallet’s mobile applications are affected.

The warnings circulating online are focused specifically on the browser extension. This is where update mechanisms and third-party dependencies present higher supply-chain risk.

Users are advised not to import seed phrases into the Trust Wallet browser extension until further clarification is provided.

No official response from Trust Wallet yet

As of the time of writing, Trust Wallet has not issued any public response, clarification, or security advisory addressing the allegations.

There has been no confirmation or denial of the claims, nor any announcement of an extension, rollback, or emergency patch.

Investigation ongoing

Researchers have emphasized that the situation remains under active investigation. Conclusions should not be drawn until the extension code and related on-chain activity have been fully reviewed.

If confirmed, the incident would represent a serious supply-chain compromise.

This is a class of attack that differs significantly from phishing or user-side mistakes. Also, it has historically resulted in rapid, large-scale losses across the crypto ecosystem.


Final Thoughts

  • The allegations point to a potentially serious supply-chain risk affecting wallet extensions, underscoring how code updates can become a critical attack vector if compromised.
  • With no response yet from Trust Wallet, users and researchers are left relying on independent investigation as scrutiny around the incident continues.

相关问答

QWhat security concern was flagged by ZachXBT regarding the Trust Wallet browser extension?

AZachXBT flagged suspicious activity potentially linked to a recent update of the Trust Wallet browser extension, suggesting it could be a supply-chain compromise that leads to the silent exfiltration of sensitive wallet data and immediate draining of funds.

QHow does the suspected malicious code in the Trust Wallet extension allegedly operate?

AThe malicious JavaScript code, added in an update and disguised as analytics, is said to activate when a user imports a seed phrase. It then silently transmits wallet-related data to an external domain designed to look like official Trust Wallet infrastructure.

QWhat is the estimated financial impact based on user reports, and how were the funds moved?

APublicly shared estimates suggest that more than $2 million may have been lost, though this is unverified. Analysts indicate the funds were routed through multiple addresses, a pattern associated with automated exploitation rather than isolated user error.

QAre Trust Wallet's mobile applications also affected by this suspected compromise?

ANo, there is no indication that Trust Wallet’s mobile applications are affected. The warnings are specifically focused on the browser extension, which has higher supply-chain risk due to its update mechanisms and third-party dependencies.

QWhat is the current status of Trust Wallet's official response to these allegations?

AAs of the time the article was written, Trust Wallet had not issued any public response, clarification, or security advisory addressing the allegations. There has been no confirmation, denial, or announcement of an emergency patch.

你可能也喜欢

Coldcard攻击升级:第四波攻击使比特币失窃金额突破9000万美元

冷钱包安全事件升级:第四波攻击导致比特币被盗金额超过9000万美元 最初只是警告的漏洞,现已演变为比特币历史上最严重的硬件钱包安全事件之一。过去三天,运行存在漏洞固件的Coldcard设备遭到攻击者利用关键缺陷清空资产。 受影响设备生成的种子短语熵值低于预期,导致其可被预测和利用。此次事件已造成约9000万美元的损失,涉及超过4500个钱包,在多轮协同攻击中被盗比特币超过1367枚。 **第四波攻击仍在持续** Galaxy Research研究主管Alex Thorn指出很可能存在第四波攻击。在区块960,778至960,792大约2.5小时内的模式显示,218笔交易涉及462个受害地址,216个新的目标地址收到了388.92枚比特币。清扫活动速率达到正常水平的约45倍,每区块13.8次清扫,而基线为0.3次。所有交易均显示没有早于Coldcard固件边界之前的输入,拓扑结构为1:1(每个受害者对应一个新目的地),没有收集漏斗。在排除6个有先前交易历史的地址后,第四波攻击的核心数据为709个地址和448.73枚比特币。部分被盗资金已转移至第二跳地址,而一些交易仍带有RBF选择加入信号,这可能为受害者提供了短暂的响应窗口。 **Coldcard的应对措施** Coldcard背后的加拿大公司Coinkite已确认该漏洞并迅速采取行动:销毁了其设施内所有剩余受影响固件设备、暂停发货,并直接联系已收到受影响订单的用户提供迁移步骤。目前所有受影响型号均已提供修补固件,但该修复仅保护新生成的种子短语。在漏洞固件上创建的任何种子即使更新后仍面临风险,用户必须生成新钱包并立即转移所有资金。Satscard、Opendime和Tapsigner因使用不同代码库未受影响。对于需要立即替代方案的用户,Coldcard建议可临时使用Bitkey、Ledger、Trezor、Jade和Bitbox。公司还要求受影响用户保留设备以支持未来可能的恢复工作。受影响的固件版本为Coldcard Mk3的v4.0.1至v5.0.3。 此次大规模漏洞事件严重动摇了市场对比特币最受信任的冷存储解决方案之一的信心,也对硬件钱包安全性提出了广泛警示。

TheNewsCrypto8分钟前

Coldcard攻击升级:第四波攻击使比特币失窃金额突破9000万美元

TheNewsCrypto8分钟前

中国科技产业,正在批量越过“可见线”

最近,中国科技产业多个领域接连进入全球视野,如大模型Kimi K3和DeepSeek-V4-Flash发布、机器人设备受国际关注、辉瑞与信达生物达成创新药合作等。这标志着中国产业能力正集中越过“可见线”——即从内部积累进入全球市场验证的阶段。 回顾过去,中国出口主力从服装家电“老三样”,到新能源汽车等“新三样”,再到如今人工智能、机器人、创新药“新新三样”,产业迭代周期明显缩短。越过“可见线”的产业通常具备四大特征:形成规模、优势突出、增长加速、带动产业链。与以往不同,当前中国产业不再只是跟进成熟市场,而是通过降低门槛、开放生态,主动参与定义新产品和新需求。 这种变化源于中国产业体系从“完整”走向“稠密”:不同领域共享技术、人才与供应链,形成能力迁移。例如,新能源汽车积累的技术向机器人产业延伸,算力需求带动芯片、存储、光通信等整条产业链。产业与研发的距离缩短,真实应用反馈加速创新,规模化成为创新的一部分。 越过“可见线”意味着中国产业的竞争焦点,从“做出产品”延伸至构建包含专利、标准、生态的持续价值系统。未来,中国需在开放中筑牢产业护城河,通过开源、协同研发扩大生态,推动技术迭代与广泛应用。 “十五五”规划已布局战略性新兴产业与未来产业,持续将新产业推向市场检验。一批又一批产业越过“可见线”,不仅体现单点突破,更意味着中国正形成持续产生新产业的能力。

marsbit33分钟前

中国科技产业,正在批量越过“可见线”

marsbit33分钟前

福布斯:700 万枚比特币暴露在量子计算风险下,BTC 必须换一把“锁”了吗?

《福布斯》文章指出,量子计算对比特币构成潜在威胁。据估计,约有700万枚比特币(价值约4700亿美元)因公钥已在链上暴露而面临风险,这主要包括中本聪时代地址和重复使用的地址。不过,暴露不等于立即被盗,关键在于能破解椭圆曲线密码学的量子计算机尚未出现。 谷歌等机构研究显示,量子计算能力进步迅速,破解加密所需的量子比特数预估持续降低。以太坊基金会研究员预估,到2032年,量子计算机从暴露公钥破解私钥的概率约为10%。 比特币社区对应对方案存在分歧。BIP-360提案建议新增抗量子地址类型;BIP-361则提议分阶段淘汰旧签名,长期未迁移的币(包括可能属于中本聪的)将无法花费,此举被部分人视同“没收”。与此同时,Algorand等区块链已采用抗量子签名。 多家创业公司正积极开发解决方案。例如,American Fortress宣称其技术能让所有链上地址免迁移获得抗量子性,并计划通过软分叉自动冻结高风险休眠钱包。但其技术细节未公开、未经审计,部分说法有待验证。该公司还计划构建一个结合合规与隐私的交易层。 尽管修复方案不断涌现,但黄金支持者等质疑比特币能否像黄金那样经受超长时期的考验。当前,量子威胁虽未迫在眉睫,但已引发密码学升级与资产安全的广泛关注和提前布局。

marsbit39分钟前

福布斯:700 万枚比特币暴露在量子计算风险下,BTC 必须换一把“锁”了吗?

marsbit39分钟前

交易

现货
活动图片