Trust Wallet Users Lost $7 Million in Cryptocurrency Due to Hack

RBK-crypto發佈於 2025-12-26更新於 2025-12-26

文章摘要

On December 26, the team behind Trust Wallet, a popular cryptocurrency wallet owned by Binance, reported a security breach affecting the browser extension version 2.68. According to Binance founder Changpeng Zhao, the incident was the result of a hack, resulting in losses of approximately $7 million. Users of the compromised version were advised to disable or uninstall it and upgrade to the secure version 2.69. The breach did not impact the mobile application. Trust Wallet's native token (TWT) initially dropped around 7% in price but recovered after the official announcement. Zhao stated that Trust Wallet would cover all user losses and urged affected individuals to contact support. Although no official cause was confirmed, reports suggest that version 2.68 contained hidden malicious code that intercepted users' secret recovery phrases during wallet imports, sending them to an external server. This allowed attackers to gain full access to affected wallets. Some community members, including Zhao, suspect the breach may have been an inside job involving a team member.

On the night of December 26, the team of the popular cryptocurrency wallet Trust Wallet reported a security breach that affected the browser application version 2.68. As explained by Binance founder and head of YZi Labs, which owns Trust Wallet, Changpeng Zhao, the incident occurred as a result of a hacker attack, and the damage amounted to $7 million.

Users of version 2.68 should disable or delete this build and only then install the new version 2.69, and under no circumstances should they open or use the unsafe version. The hack only concerns the browser version 2.68 and did not affect the mobile application.

The native token of Trust Wallet (TWT) reacted with a price drop of about 7%, falling for three hours before the team's announcement around 01:20 Moscow time on December 26. After the official announcement, the TWT price recovered to previous levels and the asset is trading slightly below $0.83.

Zhao stated that Trust Wallet will cover all user losses, and affected users were asked to write to the wallet's support service, a link to which can be found on the official website.

No official statements have been made regarding the causes of the hack. But its essence, according to a report by user Akinator on social network X, may be that a hidden malicious code was embedded in version 2.68 of the Trust Wallet browser extension. Akinator was one of the few who reported the hack several hours before the official confirmation from Trust Wallet.

The assumption is that when a user enters their secret phrase to import a wallet, this code stealthily intercepts the data and sends it to an external server. In this way, the attackers could gain full access to the users' wallets and funds.

The crypto community believes that the malicious code was embedded by someone from the cryptocurrency wallet team. In response to a suggestion by X user under the nickname Crazino.eth that the hack was "certainly carried out by an insider working in the team," Zhao replied "probably."

Broke the cycle. How the price of Bitcoin changed over 10 years at Christmas

AI outperformed humans in a crypto trading tournament. What were the results

Miner "capitulation" called a bullish factor for Bitcoin. Why

相關問答

QWhat was the total amount of cryptocurrency lost by Trust Wallet due to the hack?

AUsers lost $7 million in cryptocurrency due to the hack.

QWhich specific version of the Trust Wallet application was compromised in the security breach?

AThe security breach affected the browser application version 2.68.

QWhat was the impact on Trust Wallet's native token (TWT) price following the incident?

AThe native token TWT initially dropped by approximately 7% but recovered to its previous levels after the official announcement, trading slightly below $0.83.

QAccording to the article, how did the alleged malware in version 2.68 potentially steal user funds?

AThe hidden malicious code allegedly intercepted a user's secret recovery phrase during wallet import and sent it to an external server, giving attackers full access to the wallets and funds.

QWho did the crypto community and Binance's Changpeng Zhao suggest might be responsible for the hack?

AThe crypto community and Changpeng Zhao suggested that the hack was likely carried out by an insider within the Trust Wallet team.

你可能也喜歡

Coldcard攻击升级:第四波攻击使比特币失窃金额突破9000万美元

冷钱包安全事件升级:第四波攻击导致比特币被盗金额超过9000万美元 最初只是警告的漏洞,现已演变为比特币历史上最严重的硬件钱包安全事件之一。过去三天,运行存在漏洞固件的Coldcard设备遭到攻击者利用关键缺陷清空资产。 受影响设备生成的种子短语熵值低于预期,导致其可被预测和利用。此次事件已造成约9000万美元的损失,涉及超过4500个钱包,在多轮协同攻击中被盗比特币超过1367枚。 **第四波攻击仍在持续** Galaxy Research研究主管Alex Thorn指出很可能存在第四波攻击。在区块960,778至960,792大约2.5小时内的模式显示,218笔交易涉及462个受害地址,216个新的目标地址收到了388.92枚比特币。清扫活动速率达到正常水平的约45倍,每区块13.8次清扫,而基线为0.3次。所有交易均显示没有早于Coldcard固件边界之前的输入,拓扑结构为1:1(每个受害者对应一个新目的地),没有收集漏斗。在排除6个有先前交易历史的地址后,第四波攻击的核心数据为709个地址和448.73枚比特币。部分被盗资金已转移至第二跳地址,而一些交易仍带有RBF选择加入信号,这可能为受害者提供了短暂的响应窗口。 **Coldcard的应对措施** Coldcard背后的加拿大公司Coinkite已确认该漏洞并迅速采取行动:销毁了其设施内所有剩余受影响固件设备、暂停发货,并直接联系已收到受影响订单的用户提供迁移步骤。目前所有受影响型号均已提供修补固件,但该修复仅保护新生成的种子短语。在漏洞固件上创建的任何种子即使更新后仍面临风险,用户必须生成新钱包并立即转移所有资金。Satscard、Opendime和Tapsigner因使用不同代码库未受影响。对于需要立即替代方案的用户,Coldcard建议可临时使用Bitkey、Ledger、Trezor、Jade和Bitbox。公司还要求受影响用户保留设备以支持未来可能的恢复工作。受影响的固件版本为Coldcard Mk3的v4.0.1至v5.0.3。 此次大规模漏洞事件严重动摇了市场对比特币最受信任的冷存储解决方案之一的信心,也对硬件钱包安全性提出了广泛警示。

TheNewsCrypto5 分鐘前

Coldcard攻击升级:第四波攻击使比特币失窃金额突破9000万美元

TheNewsCrypto5 分鐘前

中国科技产业,正在批量越过“可见线”

最近,中国科技产业多个领域接连进入全球视野,如大模型Kimi K3和DeepSeek-V4-Flash发布、机器人设备受国际关注、辉瑞与信达生物达成创新药合作等。这标志着中国产业能力正集中越过“可见线”——即从内部积累进入全球市场验证的阶段。 回顾过去,中国出口主力从服装家电“老三样”,到新能源汽车等“新三样”,再到如今人工智能、机器人、创新药“新新三样”,产业迭代周期明显缩短。越过“可见线”的产业通常具备四大特征:形成规模、优势突出、增长加速、带动产业链。与以往不同,当前中国产业不再只是跟进成熟市场,而是通过降低门槛、开放生态,主动参与定义新产品和新需求。 这种变化源于中国产业体系从“完整”走向“稠密”:不同领域共享技术、人才与供应链,形成能力迁移。例如,新能源汽车积累的技术向机器人产业延伸,算力需求带动芯片、存储、光通信等整条产业链。产业与研发的距离缩短,真实应用反馈加速创新,规模化成为创新的一部分。 越过“可见线”意味着中国产业的竞争焦点,从“做出产品”延伸至构建包含专利、标准、生态的持续价值系统。未来,中国需在开放中筑牢产业护城河,通过开源、协同研发扩大生态,推动技术迭代与广泛应用。 “十五五”规划已布局战略性新兴产业与未来产业,持续将新产业推向市场检验。一批又一批产业越过“可见线”,不仅体现单点突破,更意味着中国正形成持续产生新产业的能力。

marsbit30 分鐘前

中国科技产业,正在批量越过“可见线”

marsbit30 分鐘前

福布斯:700 万枚比特币暴露在量子计算风险下,BTC 必须换一把“锁”了吗?

《福布斯》文章指出,量子计算对比特币构成潜在威胁。据估计,约有700万枚比特币(价值约4700亿美元)因公钥已在链上暴露而面临风险,这主要包括中本聪时代地址和重复使用的地址。不过,暴露不等于立即被盗,关键在于能破解椭圆曲线密码学的量子计算机尚未出现。 谷歌等机构研究显示,量子计算能力进步迅速,破解加密所需的量子比特数预估持续降低。以太坊基金会研究员预估,到2032年,量子计算机从暴露公钥破解私钥的概率约为10%。 比特币社区对应对方案存在分歧。BIP-360提案建议新增抗量子地址类型;BIP-361则提议分阶段淘汰旧签名,长期未迁移的币(包括可能属于中本聪的)将无法花费,此举被部分人视同“没收”。与此同时,Algorand等区块链已采用抗量子签名。 多家创业公司正积极开发解决方案。例如,American Fortress宣称其技术能让所有链上地址免迁移获得抗量子性,并计划通过软分叉自动冻结高风险休眠钱包。但其技术细节未公开、未经审计,部分说法有待验证。该公司还计划构建一个结合合规与隐私的交易层。 尽管修复方案不断涌现,但黄金支持者等质疑比特币能否像黄金那样经受超长时期的考验。当前,量子威胁虽未迫在眉睫,但已引发密码学升级与资产安全的广泛关注和提前布局。

marsbit36 分鐘前

福布斯:700 万枚比特币暴露在量子计算风险下,BTC 必须换一把“锁”了吗?

marsbit36 分鐘前

交易

現貨
活动图片