---(---)$0.00(0.00%)
---(---)$0.00(0.00%)
---(---)$0.00(0.00%)

Trust Wallet Confirms $8.5M Supply-Chain Hack Caused by Leaked Chrome API Key

Cora image

By Cora

Published: December 31, 2025|Last updated: December 31, 2025

Share

Share

Trust Wallet Confirms $8.5M Supply-Chain Hack Caused by Leaked Chrome API Key

Trust Wallet has confirmed that a malicious browser extension update pushed over the Christmas holiday was responsible for approximately $8.5 million in stolen user funds, marking one of the most serious wallet supply-chain attacks of 2025.

In a detailed post-incident update, the company revealed that attackers exploited a leaked Google Chrome Web Store API key, allowing them to upload a compromised version of the Trust Wallet extension directly to the Chrome Store without going through internal code review or security checks.

What Happened

Between December 24 and December 26, users who installed Trust Wallet browser extension version 2.68 unknowingly downloaded malware. Initial reports from the community flagged suspicious drains, which Trust Wallet has now confirmed involved malicious code designed to exfiltrate mnemonic seed phrases.

The malware disguised outbound data as routine analytics traffic sent to a fake domain (metrics-trustwallet.com) controlled by the attacker. Because the update was delivered through the official Chrome Web Store using valid credentials, it bypassed typical warning signs.

Trust Wallet has stated they have "high confidence" the incident is linked to "Sha1-Hulud," an industry-wide supply chain attack in November 2025 that exposed developer secrets across multiple tech sectors. The company believes this prior breach allowed attackers to access Trust Wallet's source code and the specific API key needed to publish updates.

Financial Impact and Response

The company has identified 2,520 affected wallet addresses, with total losses estimated at $8.5 million.

Trust Wallet has since:

  • Revoked the compromised credentials and rolled back to a safe version (v2.69).
  • Committed to voluntarily reimbursing all eligible victims, an unusually strong response in the crypto wallet sector.
  • Implemented a new verification process to filter out thousands of false claims.

Users who installed version 2.68 are being urged to assume their wallets are compromised, move funds immediately, and regenerate seed phrases on a secure device.

Why This Matters

This incident highlights a critical industry-wide risk: even when application code is secure, control over distribution keys can become a single point of failure.

Unlike traditional smart contract exploits, this attack:

  • Required no blockchain vulnerability.
  • Targeted end users directly via trusted infrastructure (official app stores).
  • Was timed during a holiday period when monitoring is typically lighter.

Security experts note that the sophistication of the attack suggests a highly organized threat actor, raising broader concerns about extension-based wallets and release-key management across the industry.

Keep More On Every Order: 0% Maker, 0.02% Taker

Sign Up Now

What Users Should Do Now

  • Verify your extension version is 2.69 or higher.
  • If version 2.68 was ever installed, treat the wallet as compromised.
  • Move funds to a newly generated wallet immediately.
  • Submit a claim via Trust Wallet's official support channels if you were affected.

The content provided in this article is for informational and educational purposes only and does not constitute financial, investment, or trading advice. Any actions you take based on the information provided are solely at your own risk. We are not responsible for any financial losses, damages, or consequences resulting from your use of this content. Always conduct your own research and consult a qualified financial advisor before making any investment decisions. Read more

Mindpillar logo

Learn how to trade
with clarity, not confusion

Start Here

Trading education is not financial advice, and offers no guaranteed outcomes. Please visit the website for full terms and conditions

Dewald photo

FBI Probes $250K Crypto Scam Targeting Trump Donor

July 7, 2025

Previous Article

PayPal to Launch Its “Super App” For Crypto Soon

July 29, 2021

Next Article

Cora image

Cora

My name is Cora. With a background in finance and crypto, I’m passionate about digging beyond the headlines to uncover the why behind market-moving events. I enjoy exploring how blockchain, Web3 and crypto innovation are shaping the world we live in.


Unlock Up to $1,000 Reward

Start Trading

10% Bonus + Secret Rewards

Start Trading

Get 50% More to Trade Futures

Start Trading
Velto: The Exchange-Level DeFi Experience for Smart Traders