background Early this morning Beijing time, @zachxbt posted a message on his channel stating that "some Trust Wallet users reported that funds were stolen from background Early this morning Beijing time, @zachxbt posted a message on his channel stating that "some Trust Wallet users reported that funds were stolen from

Crypto Christmas Crash: Over $6 Million Loss, Analysis of the Trust Wallet Extended Wallet Hack

2025/12/26 18:00

background

Early this morning Beijing time, @zachxbt posted a message on his channel stating that "some Trust Wallet users reported that funds were stolen from their wallet addresses in the past few hours." Subsequently, Trust Wallet's official account also released an official statement confirming that Trust Wallet browser extension version 2.68 has a security risk and advising all users using version 2.68 to immediately disable it and upgrade to version 2.69.

Tactics and Techniques

Upon receiving the intelligence, the SlowMist security team immediately began analyzing the relevant samples. Let's first look at a comparison of the core code of the previously released versions 2.67 and 2.68:

By diffing the two versions of the code, the following malicious code added by the hacker was discovered:

The malicious code iterates through all wallets in the plugin and sends a "get mnemonic phrase" request to each user's wallet to obtain the user's encrypted mnemonic phrase. Finally, it decrypts the mnemonic phrase using the password or passkeyPassword entered by the user when unlocking the wallet. If decryption is successful, the user's mnemonic phrase is sent to the attacker's domain `api.metrics-trustwallet[.]com`.

We also analyzed the attacker's domain information. The attacker used the domain: metrics-trustwallet.com.

According to the inquiry, the malicious domain name was registered on 2025-12-08 at 02:28:18, and the domain name service provider is NICENIC INTERNATIONA.

The first request to api.metrics-trustwallet[.]com was recorded on December 21, 2025.

This timing coincides almost exactly with the time when the backdoor was implanted in code 12.22.

We continued to reproduce the entire attack process through code tracing and analysis:

Dynamic analysis reveals that after unlocking the wallet, attackers can be seen filling the error field with mnemonic phrase information in R1.

The source of this error data is obtained through the GET_SEED_PHRASE function call. Currently, Trust Wallet supports two unlocking methods: password and passkeyPassword. When unlocking, the attacker obtains the password or passkeyPassword, then calls GET_SEED_PHRASE to obtain the wallet's mnemonic phrase (the private key is similar), and then puts the mnemonic phrase into the "errorMessage".

The following is the code that uses emit to call GetSeedPhrase to retrieve mnemonic phrase data and populate it into error.

Traffic analysis using BurpSuite showed that after obtaining the mnemonic phrase, it was encapsulated in the errorMessage field of the request body and sent to the malicious server (https://api.metrics-trustwallet.com), which is consistent with the previous analysis.

The above process completes the mnemonic phrase/private key theft attack. Additionally, the attackers are likely familiar with the extended source code, utilizing the open-source end-to-end product analytics platform PostHogJS to collect user wallet information.

Analysis of stolen assets

(https://t.me/investigations/296)

According to the hacker addresses disclosed by ZachXBT, our statistics show that, as of the time of writing, approximately 33 BTC (worth about 3 million USD) of assets were stolen from the Bitcoin blockchain, approximately 431 USD from the Solana blockchain, and approximately 3 million USD from various blockchains including the Ethereum mainnet and Layer 2. After the theft, the hackers transferred and exchanged some of the assets using various centralized exchanges and cross-chain bridges.

Summarize

This backdoor incident stemmed from malicious source code modification of Trust Wallet's internal codebase (analysis service logic), rather than the introduction of a tampered generic third-party package (such as a malicious npm package). The attackers directly modified the application's own code, using the legitimate PostHog library to redirect analytics data to a malicious server. Therefore, we have reason to believe this was a professional APT attack, and the attackers may have gained control of the devices or deployment permissions of Trust Wallet's developers before December 8th.

suggestion:

1. If you have installed the Trust Wallet extension wallet, you should disconnect from the internet immediately as a prerequisite for troubleshooting and taking any action.

2. Immediately export your private key/mnemonic phrase and uninstall the Trust Wallet extension wallet.

3. After backing up your private key/mnemonic phrase, transfer your funds to another wallet as soon as possible.

Market Opportunity
Intuition Logo
Intuition Price(TRUST)
$0.1115
$0.1115$0.1115
+2.38%
USD
Intuition (TRUST) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Is Putnam Global Technology A (PGTAX) a strong mutual fund pick right now?

Is Putnam Global Technology A (PGTAX) a strong mutual fund pick right now?

The post Is Putnam Global Technology A (PGTAX) a strong mutual fund pick right now? appeared on BitcoinEthereumNews.com. On the lookout for a Sector – Tech fund? Starting with Putnam Global Technology A (PGTAX – Free Report) should not be a possibility at this time. PGTAX possesses a Zacks Mutual Fund Rank of 4 (Sell), which is based on various forecasting factors like size, cost, and past performance. Objective We note that PGTAX is a Sector – Tech option, and this area is loaded with many options. Found in a wide number of industries such as semiconductors, software, internet, and networking, tech companies are everywhere. Thus, Sector – Tech mutual funds that invest in technology let investors own a stake in a notoriously volatile sector, but with a much more diversified approach. History of fund/manager Putnam Funds is based in Canton, MA, and is the manager of PGTAX. The Putnam Global Technology A made its debut in January of 2009 and PGTAX has managed to accumulate roughly $650.01 million in assets, as of the most recently available information. The fund is currently managed by Di Yao who has been in charge of the fund since December of 2012. Performance Obviously, what investors are looking for in these funds is strong performance relative to their peers. PGTAX has a 5-year annualized total return of 14.46%, and is in the middle third among its category peers. But if you are looking for a shorter time frame, it is also worth looking at its 3-year annualized total return of 27.02%, which places it in the middle third during this time-frame. It is important to note that the product’s returns may not reflect all its expenses. Any fees not reflected would lower the returns. Total returns do not reflect the fund’s [%] sale charge. If sales charges were included, total returns would have been lower. When looking at a fund’s performance, it…
Share
BitcoinEthereumNews2025/09/18 04:05
WazirX founder confirms that the Indian crypto exchange’s dispute with Binance has escalated to formal litigation

WazirX founder confirms that the Indian crypto exchange’s dispute with Binance has escalated to formal litigation

WazirX founder and CEO Nischal Shetty has confirmed that the Indian crypto exchange’s dispute with Binance has escalated to formal litigation. This has raised concerns
Share
Coinstats2025/12/27 05:45
WazirX founder Nischal Shetty says Binance ownership dispute now in litigation

WazirX founder Nischal Shetty says Binance ownership dispute now in litigation

The post WazirX founder Nischal Shetty says Binance ownership dispute now in litigation appeared on BitcoinEthereumNews.com. WazirX founder and CEO Nischal Shetty
Share
BitcoinEthereumNews2025/12/27 05:53