Trust Wallet Users Lost $7 Million in Cryptocurrency Due to Hack

RBK-crypto發佈於 2025-12-26更新於 2025-12-26

文章摘要

On December 26, the team behind Trust Wallet, a popular cryptocurrency wallet owned by Binance, reported a security breach affecting the browser extension version 2.68. According to Binance founder Changpeng Zhao, the incident was the result of a hack, resulting in losses of approximately $7 million. Users of the compromised version were advised to disable or uninstall it and upgrade to the secure version 2.69. The breach did not impact the mobile application. Trust Wallet's native token (TWT) initially dropped around 7% in price but recovered after the official announcement. Zhao stated that Trust Wallet would cover all user losses and urged affected individuals to contact support. Although no official cause was confirmed, reports suggest that version 2.68 contained hidden malicious code that intercepted users' secret recovery phrases during wallet imports, sending them to an external server. This allowed attackers to gain full access to affected wallets. Some community members, including Zhao, suspect the breach may have been an inside job involving a team member.

On the night of December 26, the team of the popular cryptocurrency wallet Trust Wallet reported a security breach that affected the browser application version 2.68. As explained by Binance founder and head of YZi Labs, which owns Trust Wallet, Changpeng Zhao, the incident occurred as a result of a hacker attack, and the damage amounted to $7 million.

Users of version 2.68 should disable or delete this build and only then install the new version 2.69, and under no circumstances should they open or use the unsafe version. The hack only concerns the browser version 2.68 and did not affect the mobile application.

The native token of Trust Wallet (TWT) reacted with a price drop of about 7%, falling for three hours before the team's announcement around 01:20 Moscow time on December 26. After the official announcement, the TWT price recovered to previous levels and the asset is trading slightly below $0.83.

Zhao stated that Trust Wallet will cover all user losses, and affected users were asked to write to the wallet's support service, a link to which can be found on the official website.

No official statements have been made regarding the causes of the hack. But its essence, according to a report by user Akinator on social network X, may be that a hidden malicious code was embedded in version 2.68 of the Trust Wallet browser extension. Akinator was one of the few who reported the hack several hours before the official confirmation from Trust Wallet.

The assumption is that when a user enters their secret phrase to import a wallet, this code stealthily intercepts the data and sends it to an external server. In this way, the attackers could gain full access to the users' wallets and funds.

The crypto community believes that the malicious code was embedded by someone from the cryptocurrency wallet team. In response to a suggestion by X user under the nickname Crazino.eth that the hack was "certainly carried out by an insider working in the team," Zhao replied "probably."

Broke the cycle. How the price of Bitcoin changed over 10 years at Christmas

AI outperformed humans in a crypto trading tournament. What were the results

Miner "capitulation" called a bullish factor for Bitcoin. Why

相關問答

QWhat was the total amount of cryptocurrency lost by Trust Wallet due to the hack?

AUsers lost $7 million in cryptocurrency due to the hack.

QWhich specific version of the Trust Wallet application was compromised in the security breach?

AThe security breach affected the browser application version 2.68.

QWhat was the impact on Trust Wallet's native token (TWT) price following the incident?

AThe native token TWT initially dropped by approximately 7% but recovered to its previous levels after the official announcement, trading slightly below $0.83.

QAccording to the article, how did the alleged malware in version 2.68 potentially steal user funds?

AThe hidden malicious code allegedly intercepted a user's secret recovery phrase during wallet import and sent it to an external server, giving attackers full access to the wallets and funds.

QWho did the crypto community and Binance's Changpeng Zhao suggest might be responsible for the hack?

AThe crypto community and Changpeng Zhao suggested that the hack was likely carried out by an insider within the Trust Wallet team.

你可能也喜歡

比特币提现仍在继续:Coldcard冷钱包8年存储终成空

硬件钱包Coldcard遭黑客攻击,导致大量资金从易受攻击设备中被持续转出。据Galaxy Research数据,截至2026年8月2日,已有4585个地址被盗,损失总额达1367.05 BTC(约合8860万美元),远超7月30日最初报告的594.5 BTC。大部分被盗资金仍停留在攻击者地址。 问题根源并非固件,而是设备生成的种子短语存在漏洞。2021年3月起,因程序员错误集成libNgU库,设备从使用STM32硬件随机数生成器转为使用软件生成器Yasmarang,该生成器由公开可获取的芯片序列号和计时器状态初始化,导致生成的种子短语可在离线状态下被暴力破解。即使固件后续已更新,只要用户未将资金转移至基于新种子短语生成的新地址,旧钱包就始终处于风险中。 受影响的设备包括特定固件版本的Mk2/Mk3、Mk4/Mk5及Q系列。仅当种子短语是通过至少50次独立掷骰子或强唯一性BIP-39密码短语创建时方可幸免。官方建议受影响用户立即在已修复的固件上生成新种子短语并转移资产。 报道提及一位39岁投资者的案例,他因该漏洞损失了2 BTC(约13万美元)。他多年来通过体力劳动积攒比特币,将其视为在制裁和高通胀国家中的财务保障与提前退休的途径。此次事件使他的长期持有策略和“冷存储”信心遭受重击,他因此决定彻底退出加密货币领域。 从历史数据看,随机数生成器缺陷并非首例,类似问题曾导致巨额损失。此次事件警示,即使离线存储也未必绝对安全,其安全性高度依赖于底层硬件和算法的可靠性。

cryptonews.ru3 小時前

比特币提现仍在继续:Coldcard冷钱包8年存储终成空

cryptonews.ru3 小時前

交易

現貨
活动图片