ZachXBT flags suspected Trust Wallet extension issue as users report drained funds

ambcrypto發佈於 2025-12-25更新於 2025-12-25

文章摘要

Security concerns emerged around the Trust Wallet browser extension on December 25, after blockchain investigator ZachXBT flagged suspicious activity potentially linked to a recent update. Reports suggest a supply-chain compromise may have been introduced in a December 24 update, where newly added code could silently exfiltrate sensitive wallet data—particularly during seed phrase imports—leading to immediate fund draining. Multiple users reported losses, with unverified estimates exceeding $2 million. The malicious code allegedly sent data to a recently registered external domain mimicking Trust Wallet infrastructure. The issue appears limited to the browser extension, with no evidence of mobile app compromise. Trust Wallet has not yet issued an official response or advisory. Researchers emphasize the situation remains under investigation, warning users to avoid importing seed phrases into the extension until clarified. If confirmed, this would represent a significant supply-chain attack.

Security concerns have emerged around the Trust Wallet browser extension on 25 December, after blockchain investigator ZachXBT flagged suspicious activity potentially linked to a recent update, prompting warnings from developers and security-focused accounts.

According to posts circulating on X, the issue may stem from a suspected supply-chain compromise introduced in a 24 December browser extension update.

Newly added code within the extension could silently exfiltrate sensitive wallet data when users import a seed phrase. The claims suggest that this has led to immediate wallet draining.

Alleged Trust Wallet malicious code and data exfiltration claims

Developers examining the extension allege that a JavaScript file added in the update contains logic disguised as analytics.

The code is said to activate specifically when a seed phrase is imported. It then silently transmits wallet-related data to an external domain designed to resemble official Trust Wallet infrastructure.

The domain referenced in the reports was reportedly registered only days ago and has since gone offline.

Researchers argue that its recent creation and the timing of the extension update raise concerns about a coordinated supply-chain attack rather than user-side phishing.

Users report wallet drains following seed imports

Multiple users have reported wallets being drained shortly after importing seed phrases into the Trust Wallet browser extension.

Publicly shared estimates suggest that more than $2 million may have been lost. Although these figures have not been independently verified.

Analysts indicate that funds were routed through multiple addresses, a pattern more commonly associated with automated exploitation than isolated user error.

Scope appears limited to browser extension

At this stage, there is no indication that Trust Wallet’s mobile applications are affected.

The warnings circulating online are focused specifically on the browser extension. This is where update mechanisms and third-party dependencies present higher supply-chain risk.

Users are advised not to import seed phrases into the Trust Wallet browser extension until further clarification is provided.

No official response from Trust Wallet yet

As of the time of writing, Trust Wallet has not issued any public response, clarification, or security advisory addressing the allegations.

There has been no confirmation or denial of the claims, nor any announcement of an extension, rollback, or emergency patch.

Investigation ongoing

Researchers have emphasized that the situation remains under active investigation. Conclusions should not be drawn until the extension code and related on-chain activity have been fully reviewed.

If confirmed, the incident would represent a serious supply-chain compromise.

This is a class of attack that differs significantly from phishing or user-side mistakes. Also, it has historically resulted in rapid, large-scale losses across the crypto ecosystem.


Final Thoughts

  • The allegations point to a potentially serious supply-chain risk affecting wallet extensions, underscoring how code updates can become a critical attack vector if compromised.
  • With no response yet from Trust Wallet, users and researchers are left relying on independent investigation as scrutiny around the incident continues.

相關問答

QWhat security concern was flagged by ZachXBT regarding the Trust Wallet browser extension?

AZachXBT flagged suspicious activity potentially linked to a recent update of the Trust Wallet browser extension, suggesting it could be a supply-chain compromise that leads to the silent exfiltration of sensitive wallet data and immediate draining of funds.

QHow does the suspected malicious code in the Trust Wallet extension allegedly operate?

AThe malicious JavaScript code, added in an update and disguised as analytics, is said to activate when a user imports a seed phrase. It then silently transmits wallet-related data to an external domain designed to look like official Trust Wallet infrastructure.

QWhat is the estimated financial impact based on user reports, and how were the funds moved?

APublicly shared estimates suggest that more than $2 million may have been lost, though this is unverified. Analysts indicate the funds were routed through multiple addresses, a pattern associated with automated exploitation rather than isolated user error.

QAre Trust Wallet's mobile applications also affected by this suspected compromise?

ANo, there is no indication that Trust Wallet’s mobile applications are affected. The warnings are specifically focused on the browser extension, which has higher supply-chain risk due to its update mechanisms and third-party dependencies.

QWhat is the current status of Trust Wallet's official response to these allegations?

AAs of the time the article was written, Trust Wallet had not issued any public response, clarification, or security advisory addressing the allegations. There has been no confirmation, denial, or announcement of an emergency patch.

你可能也喜歡

从3亿估值到千万「贱卖」,Messari经历了什么?

6月12日,加密数据与资本市场平台Blockworks宣布收购竞争对手Messari,交易对价超过1000万美元。Messari曾在2022年获得约3亿美元估值,此次交易价格大幅折让,反映出熊市下高估值初创企业的生存压力以及数据基础设施领域的整合趋势。 收购完成后,Messari首席执行官Diran Li将加入Blockworks担任高级职务,其核心数据平台及API将并入Blockworks体系。Blockworks此前刚完成Series A延伸融资,估值约1.92亿美元,并表示此次收购旨在整合加密领域碎片化的数据与信息。 Blockworks成立于2018年,早期以媒体和活动业务为主,后转向链上资本市场情报平台,重点发展机构级数据、投资者关系与合规工具。Messari同样成立于2018年,以专业加密研究与数据分析起家,2022年完成3500万美元B轮融资后估值达3亿美元。但随着熊市持续、融资环境收紧,公司面临增长压力,联合创始人亦已离职。 行业数据显示,2026年加密领域并购活跃,总额同比增长。市场分析认为,行业正处于分化阶段,早期基于增长故事的高估值正在被基本面重新校准。此次收购将Messari的数据广度与API能力,与Blockworks在发行方披露、投资者关系及合规工作流方面的优势结合,旨在构建链上市场的“单一记录系统”。 当前,随着机构加速上链、稳定币及RWA等赛道发展,市场对标准化披露、实时数据及可编程访问的需求激增。Blockworks计划以Messari的数据集为基础,结合自身发行方服务能力,打造从数据采集到合规分发的闭环。人工智能的融入也将依赖高质量结构化数据发挥作用。此次整合标志着加密数据与研究领域从百花齐放走向集中,在行业周期波动中,通过整合构建数据与信任的护城河,被认为是穿越周期的路径之一。

marsbit3 分鐘前

从3亿估值到千万「贱卖」,Messari经历了什么?

marsbit3 分鐘前

如果 AI 泡沫已经在破了,谁会真正留下?

AI行业存在泡沫已成为市场共识,观点两极分化:达利欧认为泡沫已高,黄仁勋则视其为巨大机遇的开始。文章指出,泡沫类似于2000年互联网泡沫,虽导致市场暴跌和公司倒闭,却沉淀了关键基础设施(如海底光缆、宽带),为后来亚马逊、Netflix等巨头崛起奠定基础。当前AI领域,巨头正投入数千亿美元建设数据中心、电力、GPU等基础设施,而应用层收入尚未完全匹配,形成“基建投入远大于应用收入”的明显落差。 然而,AI推理成本(Token成本)已暴跌超99.7%,这使得企业AI支出不降反升。成本下降解锁了大量长尾需求,AI正从聊天工具深入代码、医疗、金融、制造等行业的真实工作流,进入智能体与多模态应用时代。市场正在自我净化,淘汰缺乏核心竞争力的“套壳”公司,但AI赋能千行百业的大趋势不可逆转。 未来,价值将从资本支出(CapEx)的基础设施层,逐渐转向运营支出(OpEx)的应用层。那些能真正解决垂直行业痛点、重塑业务流程的AI原生企业将获得超额利润。尽管估值存在压力,但企业盈利增长有望逐步消化高估值。最终,泡沫破裂后留下的将是坚实的基础设施和高度优化的技术,推动社会进入一个所有行业均由AI驱动的智能时代。泡沫终会破灭,但底层的生产力革命真实无水分。

marsbit35 分鐘前

如果 AI 泡沫已经在破了,谁会真正留下?

marsbit35 分鐘前

微软CEO:在AI时代,如何定义一家公司的护城河?

微软CEO萨提亚·纳德拉认为,AI时代企业的核心竞争力并非依赖于单一的最强大模型,而在于能否构建一个持续进化的“学习闭环”。这一系统能将企业内部的工作流程、专业知识、组织判断和员工经验沉淀下来,并让人工智能与人类能力相互强化、共同提升。 未来的公司将积累两类关键资产:一是以员工知识、判断力、创造力和模式识别能力为核心的“人力资本”;二是企业自身构建并拥有的AI能力,即“Token资本”。纳德拉强调,AI不仅不会削弱人力资本的价值,反而会让人类的目标设定、跨领域连接和关键决策能力变得更为重要。缺乏人的引导,算力将失去方向;没有企业自身知识的注入,再强的模型也仅是外部工具。 因此,企业的真正护城河在于建立私有的评估体系、强化学习环境和知识库,将隐性经验转化为可迭代、可扩展的系统能力。即使更换底层通用模型,企业独有的“公司老员工式”的专业经验和学习成果也不会丢失。这确保了企业的知识产权与控制权。 纳德拉指出,健康的AI未来应是一个繁荣的“前沿生态”,而非由少数通用模型垄断价值。只有这样,价值才能广泛惠及每家公司、每个行业和国家,让各组织能基于自身知识创造并保留经济价值,最终实现企业、员工与社区的共同繁荣。

marsbit1 小時前

微软CEO:在AI时代,如何定义一家公司的护城河?

marsbit1 小時前

交易

現貨
合約
活动图片