Trust Wallet Exploit Causes $7 Million Loss in Christmas Day Hack On Christmas Day, users of Trust Wallet, a popular cryptocurrency wallet service owned by BinanceTrust Wallet Exploit Causes $7 Million Loss in Christmas Day Hack On Christmas Day, users of Trust Wallet, a popular cryptocurrency wallet service owned by Binance

Trust Wallet Announces $7M Refund for Browser Extension Hack, Zhao Confirms

Trust Wallet Announces $7m Refund For Browser Extension Hack, Zhao Confirms

Trust Wallet Exploit Causes $7 Million Loss in Christmas Day Hack

On Christmas Day, users of Trust Wallet, a popular cryptocurrency wallet service owned by Binance, suffered a significant security breach resulting in estimated losses of approximately $7 million. The incident, which had been meticulously planned since early December, targeted the wallet’s desktop browser extension, version 2.68, compromised by an orchestrated attack. Trust Wallet has since urged users to update to version 2.89 to mitigate further risks.

Key Takeaways

  • Attackers implanted a backdoor on Trust Wallet’s desktop extension, enabling them to transfer funds and collect user information.
  • Binance’s CEO, Changpeng Zhao, assured that affected funds will be reimbursed, emphasizing the company’s commitment to user security.
  • Industry experts suggest insider involvement and highlight the sophisticated nature of the breach, as the attacker demonstrated considerable familiarity with Trust Wallet’s source code.
  • The attack underscores rising threats in the digital asset space, particularly concerning personal wallet security vulnerabilities.

Tickers mentioned: N/A

Sentiment: Negative

Price impact: Negative. The exploit highlights persistent security vulnerabilities and threats within the crypto ecosystem.

Trading idea (Not Financial Advice): Hold. Investors should await further updates on wallet security measures before making decisions.

Market context: As thefts from digital wallets increase, enhanced security protocols and industry vigilance become paramount to safeguarding user assets.

Details of the Trust Wallet Breach

Trust Wallet announced the breach via a post on social media, revealing that the security incident compromised the browser extension version 2.68, affecting desktop users. The attackers had been developing the exploit since December 8, with successful implantation of a backdoor on December 22. According to blockchain security expert Yu Xian, co-founder of SlowMist, the attacker began transferring stolen funds on December 25. The malicious code also collected users’ personal information, transmitting it to an external server.

Source: Chainalysis.com

Onchain detective ZachXBT confirmed that hundreds of Trust Wallet users were impacted by the breach. Several industry insiders raised concerns over possible insider involvement, especially since the attacker managed to submit an updated version of the wallet extension on Trust Wallet’s official website. Anndy Lian, an intergovernmental blockchain advisor, speculated that insider activity was highly probable, noting the attack’s sophistication. Binance CEO Changpeng Zhao echoed this sentiment, stating the breach was “most likely” an insider job.

Further analysis indicated that the attacker demonstrated an in-depth understanding of the wallet’s source code, facilitating the backdoor implementation. Security researchers warn that such breaches, increasingly driven by insider activity, pose a growing threat to the security and trustworthiness of crypto wallets.

The incident prompts a broader discussion on industry security measures and the importance of transparency to protect users from evolving tactical threats in the digital asset space.

This article was originally published as Trust Wallet Announces $7M Refund for Browser Extension Hack, Zhao Confirms on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.

Market Opportunity
Intuition Logo
Intuition Price(TRUST)
$0.1103
$0.1103$0.1103
-7.77%
USD
Intuition (TRUST) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Satoshi-Era Mt. Gox’s 1,000 Bitcoin Wallet Suddenly Reactivated

Satoshi-Era Mt. Gox’s 1,000 Bitcoin Wallet Suddenly Reactivated

The post Satoshi-Era Mt. Gox’s 1,000 Bitcoin Wallet Suddenly Reactivated appeared on BitcoinEthereumNews.com. X account @SaniExp, which belongs to the founder of the Timechain Index explorer, has published data showing that a dormant BTC wallet was activated after hibernating for six years. However, it was set up 13 years ago, according to the tweet — the time when Satoshi Nakamoto’s shadow was still casting itself around, so to speak. The X post states that the tweet belongs to infamous early Bitcoin exchange Mt. Gox, which suffered from a major hack in the early 2010s, and last year it began paying out compensation to clients who lost their crypto in that hack. The deadline was eventually extended to October 2025. Mt. Gox’s wallet with 1,000 BTC reactivated The above-mentioned data source shared a screenshot from the Timechain Index explorer, showing multiple transactions marked as confirmed and moving a total of 1,000 Bitcoins. This amount of crypto is valued at $116,195,100 at the time of the initiated transaction. Last year, Mt. Gox began to move the remains of its gargantuan funds to pay out compensations to its creditors. Earlier this year, it also made several massive transactions to partner exchanges to distribute funds to Mt. Gox investors. All of the compensations were promised to be paid out by Oct. 31, 2025. The aforementioned transaction is likely preparation for another payout. The exchange was hacked for several years due to multiple unnoticed security breaches, and in 2014, when the site went offline, 744,408 Bitcoins were reported stolen. Source: https://u.today/satoshi-era-mtgoxs-1000-bitcoin-wallet-suddenly-reactivated
Share
BitcoinEthereumNews2025/09/18 10:18
Zycus Launches Industry-First AI Adoption Index to Measure Real-World AI Maturity in Procurement

Zycus Launches Industry-First AI Adoption Index to Measure Real-World AI Maturity in Procurement

Princeton, NJ | Dec 26th, 2025 — Zycus, a global leader in AI-powered Source-to-Pay (S2P) solutions, today announced the launch of the AI Adoption Index for Procurement
Share
Techbullion2025/12/26 17:57
Soccer Replica Jerseys – Kits, Customization, and Best Practices for Caring for Them

Soccer Replica Jerseys – Kits, Customization, and Best Practices for Caring for Them

Today’s soccer jersey is more than just athletic clothing; it is a representation of loyalty, a statement of fashion, and an example of technical development. The
Share
Techbullion2025/12/26 18:04