On December 25, 2025, Trust Wallet Browser Extension users were targeted by a sophisticated hack that resulted in the theft of approximately $7 million worth ofOn December 25, 2025, Trust Wallet Browser Extension users were targeted by a sophisticated hack that resulted in the theft of approximately $7 million worth of

Trust Wallet Suffers $7M Hack on Christmas Day, Binance’s CZ Commits to Full User Reimbursement

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com
Trust Wallet Suffers $7m Hack On Christmas Day, Binance's Cz Commits To Full User Reimbursement

On December 25, 2025, Trust Wallet Browser Extension users were targeted by a sophisticated hack that resulted in the theft of approximately $7 million worth of cryptocurrency.

The breach primarily targeted version 2.68 of the Chrome extension and was based on a hacker-developed backdoor that stole the private keys and mnemonic data of affected individuals, subsequently exporting the information to the hacker’s server.

According to on-chain analyst ZachXBT, who reported that the attack affected hundreds of individuals and compiled a list of theft addresses spanning EVM chains, Bitcoin, and Solana.

The hacker behind the attack is said to have started preparations for the attack as early as December 8, 2025, and gained access to Trust Wallet’s source code repository. On December 22, the malicious code was integrated into the update for the extension, which was then labeled with harmless-sounding “analytics” features.

The backdoor was then set to activate on Christmas Day, when the extraction of funds from affected wallets began. The malware code had warning signs, including connections to a dubious domain, “https://trustwallets.org,” which experts believe should have been flagged by basic automated audits or manual checks.

A security researcher pointed out that this domain was rather fishy, pointing toward the lack of protection against calls from external URL addresses.

Trust Wallet identified the issue on December 25, 2025. In an official statement, the company announced, “We advise those affected to turn off their client v2.68 and update to v2.89 via the official Chrome Web Store.”

The hack only affected desktop browser extension users, leaving mobile app users and other extension versions untouched.

Analysts from SlowMist and blockchain expert Anndy Lian believed that the attacker is well familiar with Trust Wallet’s codebase, suspecting it’s probably an insider job. Binance co-founder Changpeng Zhao (CZ) shared similar beliefs and assessments in a response on X, labeling it “most likely an inside attack.”

The attack is a testament to the vulnerabilities in crypto wallets, where individual compromises represented 37% of stolen value in 2025, not counting major exchange breaches like Bybit’s $1.4 billion loss in February 2025. It serves as another example of aggressive hacking tactics in the decentralized finance ecosystem.

Response, Reimbursement, and Broader Implications

Following the attack, CZ stated on December 26, 2025, that Trust Wallet would fully compensate the $7 million in losses.

This decision is in line with the user-protecting culture at Binance, as CZ stated that there were still investigations to determine how such an ‘evil’ version was submitted to the Chrome Store.

According to ZachXBT, he had been contacted directly by several victims with whom he compiled information on the scam addresses. While the quick reimbursement was seen as a positive step by some victims, other community members disagreed and criticized the decision over inconsistencies in handling similar attacks from 2023.

Trust Wallet’s team is still investigating the attack, as CZ suggested potential insider collusion could be a reason to make internal changes within the organization.

Some community members are pushing for improved security measures, including compulsory code audits and advanced phishing detection in updates. Following the hack, there have been debates on the dangers of using browser extensions versus mobile wallets, with suggestions to switch to mobile wallets for better security.

This article was originally published as Trust Wallet Suffers $7M Hack on Christmas Day, Binance’s CZ Commits to Full User Reimbursement on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.

Market Opportunity
Intuition Logo
Intuition Price(TRUST)
$0.07132
$0.07132$0.07132
+0.33%
USD
Intuition (TRUST) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

OpenVPP accused of falsely advertising cooperation with the US government; SEC commissioner clarifies no involvement

OpenVPP accused of falsely advertising cooperation with the US government; SEC commissioner clarifies no involvement

PANews reported on September 17th that on-chain sleuth ZachXBT tweeted that OpenVPP ( $OVPP ) announced this week that it was collaborating with the US government to advance energy tokenization. SEC Commissioner Hester Peirce subsequently responded, stating that the company does not collaborate with or endorse any private crypto projects. The OpenVPP team subsequently hid the response. Several crypto influencers have participated in promoting the project, and the accounts involved have been questioned as typical influencer accounts.
Share
PANews2025/09/17 23:58
Trump's allegation against Noem would constitute a federal crime: analyst

Trump's allegation against Noem would constitute a federal crime: analyst

President Donald Trump caught everyone off guard by suddenly firing Homeland Security Secretary Kristi Noem — but being out of a job could just be the start of
Share
Rawstory2026/03/06 04:49
Aave DAO to Shut Down 50% of L2s While Doubling Down on GHO

Aave DAO to Shut Down 50% of L2s While Doubling Down on GHO

The post Aave DAO to Shut Down 50% of L2s While Doubling Down on GHO appeared on BitcoinEthereumNews.com. Aave DAO is gearing up for a significant overhaul by shutting down over 50% of underperforming L2 instances. It is also restructuring its governance framework and deploying over $100 million to boost GHO. This could be a pivotal moment that propels Aave back to the forefront of on-chain lending or sparks unprecedented controversy within the DeFi community. Sponsored Sponsored ACI Proposes Shutting Down 50% of L2s The “State of the Union” report by the Aave Chan Initiative (ACI) paints a candid picture. After a turbulent period in the DeFi market and internal challenges, Aave (AAVE) now leads in key metrics: TVL, revenue, market share, and borrowing volume. Aave’s annual revenue of $130 million surpasses the combined cash reserves of its competitors. Tokenomics improvements and the AAVE token buyback program have also contributed to the ecosystem’s growth. Aave global metrics. Source: Aave However, the ACI’s report also highlights several pain points. First, regarding the Layer-2 (L2) strategy. While Aave’s L2 strategy was once a key driver of success, it is no longer fit for purpose. Over half of Aave’s instances on L2s and alt-L1s are not economically viable. Based on year-to-date data, over 86.6% of Aave’s revenue comes from the mainnet, indicating that everything else is a side quest. On this basis, ACI proposes closing underperforming networks. The DAO should invest in key networks with significant differentiators. Second, ACI is pushing for a complete overhaul of the “friendly fork” framework, as most have been unimpressive regarding TVL and revenue. In some cases, attackers have exploited them to Aave’s detriment, as seen with Spark. Sponsored Sponsored “The friendly fork model had a good intention but bad execution where the DAO was too friendly towards these forks, allowing the DAO only little upside,” the report states. Third, the instance model, once a smart…
Share
BitcoinEthereumNews2025/09/18 02:28