ZachXBT flags suspected Trust Wallet extension issue as users report drained funds

ambcrypto發佈於 2025-12-25更新於 2025-12-25

文章摘要

Security concerns emerged around the Trust Wallet browser extension on December 25, after blockchain investigator ZachXBT flagged suspicious activity potentially linked to a recent update. Reports suggest a supply-chain compromise may have been introduced in a December 24 update, where newly added code could silently exfiltrate sensitive wallet data—particularly during seed phrase imports—leading to immediate fund draining. Multiple users reported losses, with unverified estimates exceeding $2 million. The malicious code allegedly sent data to a recently registered external domain mimicking Trust Wallet infrastructure. The issue appears limited to the browser extension, with no evidence of mobile app compromise. Trust Wallet has not yet issued an official response or advisory. Researchers emphasize the situation remains under investigation, warning users to avoid importing seed phrases into the extension until clarified. If confirmed, this would represent a significant supply-chain attack.

Security concerns have emerged around the Trust Wallet browser extension on 25 December, after blockchain investigator ZachXBT flagged suspicious activity potentially linked to a recent update, prompting warnings from developers and security-focused accounts.

According to posts circulating on X, the issue may stem from a suspected supply-chain compromise introduced in a 24 December browser extension update.

Newly added code within the extension could silently exfiltrate sensitive wallet data when users import a seed phrase. The claims suggest that this has led to immediate wallet draining.

Alleged Trust Wallet malicious code and data exfiltration claims

Developers examining the extension allege that a JavaScript file added in the update contains logic disguised as analytics.

The code is said to activate specifically when a seed phrase is imported. It then silently transmits wallet-related data to an external domain designed to resemble official Trust Wallet infrastructure.

The domain referenced in the reports was reportedly registered only days ago and has since gone offline.

Researchers argue that its recent creation and the timing of the extension update raise concerns about a coordinated supply-chain attack rather than user-side phishing.

Users report wallet drains following seed imports

Multiple users have reported wallets being drained shortly after importing seed phrases into the Trust Wallet browser extension.

Publicly shared estimates suggest that more than $2 million may have been lost. Although these figures have not been independently verified.

Analysts indicate that funds were routed through multiple addresses, a pattern more commonly associated with automated exploitation than isolated user error.

Scope appears limited to browser extension

At this stage, there is no indication that Trust Wallet’s mobile applications are affected.

The warnings circulating online are focused specifically on the browser extension. This is where update mechanisms and third-party dependencies present higher supply-chain risk.

Users are advised not to import seed phrases into the Trust Wallet browser extension until further clarification is provided.

No official response from Trust Wallet yet

As of the time of writing, Trust Wallet has not issued any public response, clarification, or security advisory addressing the allegations.

There has been no confirmation or denial of the claims, nor any announcement of an extension, rollback, or emergency patch.

Investigation ongoing

Researchers have emphasized that the situation remains under active investigation. Conclusions should not be drawn until the extension code and related on-chain activity have been fully reviewed.

If confirmed, the incident would represent a serious supply-chain compromise.

This is a class of attack that differs significantly from phishing or user-side mistakes. Also, it has historically resulted in rapid, large-scale losses across the crypto ecosystem.


Final Thoughts

  • The allegations point to a potentially serious supply-chain risk affecting wallet extensions, underscoring how code updates can become a critical attack vector if compromised.
  • With no response yet from Trust Wallet, users and researchers are left relying on independent investigation as scrutiny around the incident continues.

相關問答

QWhat security concern was flagged by ZachXBT regarding the Trust Wallet browser extension?

AZachXBT flagged suspicious activity potentially linked to a recent update of the Trust Wallet browser extension, suggesting it could be a supply-chain compromise that leads to the silent exfiltration of sensitive wallet data and immediate draining of funds.

QHow does the suspected malicious code in the Trust Wallet extension allegedly operate?

AThe malicious JavaScript code, added in an update and disguised as analytics, is said to activate when a user imports a seed phrase. It then silently transmits wallet-related data to an external domain designed to look like official Trust Wallet infrastructure.

QWhat is the estimated financial impact based on user reports, and how were the funds moved?

APublicly shared estimates suggest that more than $2 million may have been lost, though this is unverified. Analysts indicate the funds were routed through multiple addresses, a pattern associated with automated exploitation rather than isolated user error.

QAre Trust Wallet's mobile applications also affected by this suspected compromise?

ANo, there is no indication that Trust Wallet’s mobile applications are affected. The warnings are specifically focused on the browser extension, which has higher supply-chain risk due to its update mechanisms and third-party dependencies.

QWhat is the current status of Trust Wallet's official response to these allegations?

AAs of the time the article was written, Trust Wallet had not issued any public response, clarification, or security advisory addressing the allegations. There has been no confirmation, denial, or announcement of an emergency patch.

你可能也喜歡

SpaceX 万亿估值的底座:谁在瓜分马斯克每年的百亿资本开支?

SpaceX(股票代码待定)上市后,其万亿估值背后是每年数百亿美元的资本开支,这为供应链上的众多公司带来了机遇。文章认为,投资SpaceX的供应链企业,可能比直接投资其本身更具潜力和确定性。 SpaceX的业务主要由三部分构成:稳定盈利的星链(Starlink)业务、持续投入的火箭发射业务(猎鹰、星舰)以及仍在亏损的AI业务(包括地面超算和规划中的轨道数据中心)。公司形成一个资金循环:星链的利润支持火箭研发以降低发射成本,低成本发射再将AI硬件送入太空,最终通过出租AI算力创造新收入。这个循环每年产生巨大的采购需求。 供应商按其可替代性分为三类: 1. **短期内无法替代**:包括提供GPU和CUDA生态的英伟达(NVDA)、持有关键卫星通信频谱的欧洲通信卫星公司(Eutelsat,SATS)、为星链卫星提供毫米波放大器的Filtronic(FTC)、全球铍金属主要供应商Materion(MTRN),以及提供相控阵天线芯片的意法半导体(STM)。 2. **技术上可换但代价高昂**:包括提供火箭飞控系统的霍尼韦尔(HON)、提供发动机特种钢的Carpenter Technology(CRS)、供应航天碳纤维的赫氏(Hexcel, HXL)、负责高速数据交换的博通(AVGO),以及在发射场附近供应液氧液氮的林德集团。 3. **需要稳定量产、成本优先**:这类公司集中在星链终端等需要大规模生产的产品上。例如,星链终端主要代工厂启碁科技(6285),以及多家A股公司,如信维通信(300136)、派克新材(605123)、西部材料(002149)、应流股份(603308)、天银机电和通宇通讯等。此外,还有提供时间同步、配电、散热等关键“螺丝钉”功能的美股公司。 文章指出,当前关注SpaceX供应链恰逢其时,原因有三:一是SpaceX的采购量正处于加速增长的起点;二是公司上市后提高了财务透明度,便于跟踪验证供应链订单;三是参照苹果、特斯拉产业链的发展历史,SpaceX供应链目前可能类似于特斯拉2018年的阶段,正进入快速增长期。 最后,文章总结,无论SpaceX股价如何波动,其庞大的、持续的采购订单将为供应链上的公司带来确定的营收。对于投资者而言,关注这些“安静供货”的供应链企业,或许是参与太空经济浪潮的另一种方式。

链捕手50 分鐘前

SpaceX 万亿估值的底座:谁在瓜分马斯克每年的百亿资本开支?

链捕手50 分鐘前

交易

現貨
合約
活动图片