Trust Wallet has pledged to cover roughly $7 million in customer funds lost in a Christmas Day exploit,… The post Trust Wallet founder, CZ vows to refund $7 millionTrust Wallet has pledged to cover roughly $7 million in customer funds lost in a Christmas Day exploit,… The post Trust Wallet founder, CZ vows to refund $7 million

Trust Wallet founder, CZ vows to refund $7 million lost in Christmas Day hack

2025/12/27 00:30
4 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Trust Wallet has pledged to cover roughly $7 million in customer funds lost in a Christmas Day exploit, its founder, Changpeng Zhao, confirmed on the social platform X. The sudden breach has rattled part of the crypto community. Still, Zhao’s swift assurance aims to steady nerves and restore confidence in the popular self-custodial wallet.

The incident unfolded on December 25, when a compromised version of the Trust Wallet browser extension was used to drain assets from users’ wallets. 

Early investigations suggest the malicious code was active in version 2.68 of the extension, prompting unauthorised transfers across multiple blockchains, including Ethereum, Bitcoin and Solana. Within hours, on-chain data showed funds being siphoned away to unknown addresses, with losses quickly approaching $7 million.

In a post on X on Friday, Zhao emphasised that “user funds are SAFU,” using the popular crypto industry acronym for Secure Asset Fund for Users. He said Trust Wallet will reimburse affected users for their losses. The team is continuing to investigate exactly how the attackers were able to upload and distribute the compromised extension.

Trust Wallet founder CZ vows to reimburse $7 million lost in Christmas Day hack Chinpeng Zao

The wallet provider also described the breach as limited to the browser extension. Trust Wallet urged users to disable the compromised version immediately and update to the fixed release, version 2.69, available via the official Chrome Web Store.

Mobile app users and those using other extension versions were reportedly not affected.

How the Trust Wallet exploit played out

Security researchers and on-chain analysts have begun piecing together a timeline of the attack. Initial signs of preparation by the threat actors date back to early December, according to cybersecurity firm SlowMist. Their reporting indicates that malicious code was embedded into the extension build before going live, suggesting a carefully planned exploit rather than a simple automated attack.

Once live on Christmas Day, the compromised extension collected sensitive user data, including seed phrases, and transmitted it to a remote server controlled by the attackers. Victims who imported a seed phrase into the extension saw their wallets drained in a matter of minutes, even if they had followed common security practices.

Across the crypto community, on-chain sleuths flagged hundreds of wallets affected by the breach. The rapid movement of assets through mixing services complicated efforts to trace stolen funds, making recovery efforts challenging.

The broader market felt the shock of the news, coming at a time when crypto prices were already under pressure. Despite the relatively modest size of the loss compared with massive exchange hacks this year, the incident has drawn fresh scrutiny to browser-based wallet infrastructure and supply chain security.

Trust Wallet founder CZ vows to reimburse $7 million lost in Christmas Day hack

Meanwhile, Zhao’s public promise to cover the losses was intended to reassure users that the incident would not result in personal financial loss. His message emphasised that affected funds will be reimbursed from Trust Wallet’s reserves, and that the issue appears to be confined to the compromised extension.

Some industry observers have raised questions about how the malicious version passed through review and was distributed via official channels.

There are early suggestions that the breach may involve a supply chain compromise or even insider knowledge, given how the altered code was able to slip into the official release. These suggestions have sparked debate across forums and social platforms, with some users voicing concerns about internal controls and review processes.

Trust Wallet has responded by prioritising the release of the patched extension and asking users to update immediately. It has also been recommended that those affected generate new seed phrases and migrate assets to secure environments.

The post Trust Wallet founder, CZ vows to refund $7 million lost in Christmas Day hack first appeared on Technext.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Shiba Inu Leader Breaks Silence on $2.4M Shibarium Exploit, Confirms Active Recovery

Shiba Inu Leader Breaks Silence on $2.4M Shibarium Exploit, Confirms Active Recovery

The lead developer of Shiba Inu, Shytoshi Kusama, has publicly addressed the Shibarium bridge exploit that occurred recently, draining $2.4 million from the network. After days of speculation about his involvement in managing the crisis, the project leader broke his silence.Kusama emphasized that a special ”war room” has been set up to restore stolen finances and enhance network security. The statement is his first official words since the bridge compromise occurred.”Although I am focusing on AI initiatives to benefit all our tokens, I remain with the developers and leadership in the war room,” Kusama posted on social media platform X. He dismissed claims that he had distanced himself from the project as ”utterly preposterous.”The developer said that the reason behind his silence at first was strategic. Before he could make any statements publicly, he must have taken time to evaluate what he termed a complex and deep situation properly. Kusama also vowed to provide further updates in the official Shiba Inu channels as the team comes up with long-term solutions.Attack Details and Immediate ResponseAs highlighted in our previous article, targeted Shibarium's bridge infrastructure through a sophisticated attack vector. Hackers gained unauthorized access to validator signing keys, compromising the network's security framework.The hackers executed a flash loan to acquire 4.6 million BONE ShibaSwap tokens. The validator power on the network was majority held by them after this purchase. They were able to transfer assets out of Shibarium with this control.The response of Shibarium developers was timely to limit the breach. They instantly halted all validator functions in order to avoid additional exploitation. The team proceeded to deposit the assets under staking in a multisig hardware wallet that is secure.External security companies were involved in the investigation effort. Hexens, Seal 911, and PeckShield are collaborating with internal developers to examine the attack and discover vulnerabilities.The project's key concerns are network stability and the protection of user funds, as underlined by the lead developer, Dhairya. The team is working around the clock to restore normal operations.In an effort to recover the funds, Shiba Inu has offered a bounty worth 5 Ether ($23,000) to the hackers. The bounty offer includes a 30-day deadline with decreasing rewards after seven days.Market Impact and Recovery IncentivesThe exploit caused serious volatility in the marketplace of Shiba Inu ecosystem tokens. SHIB dropped about 6% after the news of the attack. However, The token has bounced back and is currently trading at around $0.00001298 at the time of writing.SHIB Price Source CoinMarketCap
Share
Coinstats2025/09/18 02:25
‘Gold Pillars Crumbling?’ Strategist Questions Durability of Gold’s Geopolitical Bid

‘Gold Pillars Crumbling?’ Strategist Questions Durability of Gold’s Geopolitical Bid

Gold’s geopolitical premium may be fading as crude oil and silver eye powerful upside, with shifting global tensions and market volatility poised to redraw the
Share
Coinstats2026/03/04 10:30
Headwind Helps Best Wallet Token

Headwind Helps Best Wallet Token

The post Headwind Helps Best Wallet Token appeared on BitcoinEthereumNews.com. Google has announced the launch of a new open-source protocol called Agent Payments Protocol (AP2) in partnership with Coinbase, the Ethereum Foundation, and 60 other organizations. This allows AI agents to make payments on behalf of users using various methods such as real-time bank transfers, credit and debit cards, and, most importantly, stablecoins. Let’s explore in detail what this could mean for the broader cryptocurrency markets, and also highlight a presale crypto (Best Wallet Token) that could explode as a result of this development. Google’s Push for Stablecoins Agent Payments Protocol (AP2) uses digital contracts known as ‘Intent Mandates’ and ‘Verifiable Credentials’ to ensure that AI agents undertake only those payments authorized by the user. Mandates, by the way, are cryptographically signed, tamper-proof digital contracts that act as verifiable proof of a user’s instruction. For example, let’s say you instruct an AI agent to never spend more than $200 in a single transaction. This instruction is written into an Intent Mandate, which serves as a digital contract. Now, whenever the AI agent tries to make a payment, it must present this mandate as proof of authorization, which will then be verified via the AP2 protocol. Alongside this, Google has also launched the A2A x402 extension to accelerate support for the Web3 ecosystem. This production-ready solution enables agent-based crypto payments and will help reshape the growth of cryptocurrency integration within the AP2 protocol. Google’s inclusion of stablecoins in AP2 is a massive vote of confidence in dollar-pegged cryptocurrencies and a huge step toward making them a mainstream payment option. This widens stablecoin usage beyond trading and speculation, positioning them at the center of the consumption economy. The recent enactment of the GENIUS Act in the U.S. gives stablecoins more structure and legal support. Imagine paying for things like data crawls, per-task…
Share
BitcoinEthereumNews2025/09/18 01:27