Trust Wallet's Christmas security breach has taken an unexpected turn. The company now faces nearly double the number of compensation claims compared to actual Trust Wallet's Christmas security breach has taken an unexpected turn. The company now faces nearly double the number of compensation claims compared to actual

Trust Wallet Faces Wave of Fraudulent Claims After $7 Million Chrome Extension Hack

CEO Eowyn Chen revealed on Monday that Trust Wallet identified 2,596 compromised wallet addresses from the December 24 hack. However, the company received almost 5,000 claims for reimbursement—a discrepancy that points to widespread fraudulent submissions.

“Because of this, accurate verification of wallet ownership is critical to ensure funds are returned to the right people,” Chen stated. “Our team is working diligently to verify claims; combining multiple data points to distinguish legitimate victims from malicious actors.”

The massive gap between actual victims and total claims has forced Trust Wallet to abandon speed in favor of accuracy, marking a significant operational pivot in one of the year’s most notable crypto security incidents.

How the Attack Unfolded

The breach began when attackers obtained a leaked Chrome Web Store API key, allowing them to bypass Trust Wallet’s internal security checks. On December 24 at 12:32 p.m. UTC, the compromised version 2.68 of the Chrome extension went live on Google’s official store.

According to blockchain security firm SlowMist’s analysis, the malicious code was carefully hidden inside a modified analytics library called posthog-js. When users unlocked their wallets, the code secretly extracted their seed phrases—the master keys to cryptocurrency wallets—and sent them to a server controlled by the attackers.

The domain used to collect stolen data, “api.metrics-trustwallet.com,” was registered on December 8, suggesting the attack was planned at least two weeks in advance. Cryptocurrency investigator ZachXBT first flagged the issue on Christmas Day after hundreds of users reported drained wallets.

Source: @EowynChen

Trust Wallet pushed a fixed version 2.69 on December 25. The breach affected only Chrome extension users who logged in before December 26 at 11 a.m. UTC. Mobile app users and other browser versions remained safe.

The Insider Question

Multiple industry figures have raised concerns about potential insider involvement in the attack. Binance co-founder Changpeng Zhao, whose company owns Trust Wallet, said the exploit was “most likely” carried out by an insider, though he provided no additional evidence.

SlowMist co-founder Yu Xian noted that the attacker demonstrated detailed knowledge of the extension’s source code and had prepared the infrastructure weeks before executing the theft. The ability to obtain and misuse a Chrome Web Store API key suggests either compromised developer devices or stolen deployment permissions.

Chen confirmed the company is conducting a broader forensic investigation alongside the compensation process but has not confirmed whether insiders were involved.

Stolen Funds and Money Laundering

The attack resulted in approximately $7 million in losses across multiple cryptocurrencies, including Bitcoin, Ethereum, and Solana. Blockchain security firm PeckShield tracked more than $4 million of the stolen funds moving through centralized exchanges like ChangeNOW, FixedFloat, and KuCoin. About $2.8 million remained in attacker-controlled wallets as of December 26.

The rapid movement of funds through multiple exchanges and blockchain networks has complicated recovery efforts and made tracing the attackers more difficult.

Compensation Process Under Scrutiny

Binance founder Zhao has committed to covering all verified losses, stating “user funds are SAFU”—a crypto industry term meaning “Secure Asset Fund for Users.” However, the verification process has become more complex than initially expected.

Trust Wallet requires affected users to submit detailed information through an official support form, including email addresses, compromised wallet addresses, attacker addresses, and transaction hashes. The company emphasized that accuracy now takes priority over speed.

The surge in false claims highlights a recurring problem in cryptocurrency security incidents. While blockchain transparency allows incidents to be traced, linking wallet addresses to verified users without centralized records remains challenging. This tension becomes acute when millions of dollars are at stake.

Chen said the team is combining multiple verification methods to assess claims but did not detail the specific criteria being used. The verification phase marks a critical test of whether Trust Wallet can successfully filter out fraudulent submissions while maintaining trust among genuine victims.

Warning About Secondary Scams

Trust Wallet issued urgent warnings about scammers exploiting the situation. The company reported seeing fake compensation forms spread through Telegram advertisements, impersonated support accounts, and direct messages requesting private keys or seed phrases.

The official compensation process never requests passwords, private keys, or recovery phrases. Users should only submit claims through Trust Wallet’s verified support portal at trustwallet-support.freshdesk.com. Any other communication claiming to offer reimbursement should be treated as fraudulent.

This secondary wave of scams adds another layer of risk for victims already dealing with stolen funds. The company stressed that users should verify all communications come from official Trust Wallet channels before taking any action.

Broader Security Implications

The Trust Wallet incident fits into a larger pattern of supply chain attacks targeting cryptocurrency users in 2024. According to Chainalysis data, cryptocurrency theft reached $6.75 billion in 2024, with personal wallet compromises surging to 158,000 from 64,000 the previous year.

Browser extensions present unique security challenges because they operate with elevated permissions and can access sensitive user data. A single compromised update can affect hundreds of thousands of users within hours.

The incident also demonstrates how weak verification processes can transform a single security breach into multiple problems. Trust Wallet must now dedicate significant resources to filtering false claims while genuine victims wait for compensation.

Trust Wallet’s Chrome extension has approximately one million users according to its official listing, though practical exposure depends on how many people installed version 2.68 and entered sensitive data during the vulnerable window.

The Path Forward

Trust Wallet has taken several steps to prevent future incidents. The company expired all release APIs to block unauthorized version updates for the next two weeks. The malicious domain used to collect stolen data was reported to its registrar and promptly suspended.

However, questions remain about how attackers obtained the Chrome Web Store API key and whether additional security measures will be implemented. The ongoing forensic investigation may provide answers, but Trust Wallet has not announced specific changes to its release process.

For cryptocurrency users, the incident reinforces the importance of treating wallet updates with extreme caution. Security experts recommend waiting for community confirmation before installing updates and considering hardware wallets for significant holdings.

The compensation process continues as Trust Wallet works through thousands of claims. The company’s ability to accurately identify legitimate victims while blocking fraudulent submissions will likely influence how other wallet providers handle future security incidents.

Reality Check

The Trust Wallet breach exposes two critical vulnerabilities in cryptocurrency security: supply chain attacks can bypass even well-designed security systems, and compensation processes themselves become targets for fraud. As Trust Wallet navigates verification of nearly 5,000 claims for 2,596 actual victims, the incident serves as a costly reminder that in crypto security, the cleanup can be as challenging as the breach itself.

Market Opportunity
Intuition Logo
Intuition Price(TRUST)
$0.1088
$0.1088$0.1088
-4.30%
USD
Intuition (TRUST) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

The Best Crypto Presale in 2025? Solana and ADA Struggle, but Lyno AI Surges With Growing Momentum

The Best Crypto Presale in 2025? Solana and ADA Struggle, but Lyno AI Surges With Growing Momentum

The post The Best Crypto Presale in 2025? Solana and ADA Struggle, but Lyno AI Surges With Growing Momentum appeared on BitcoinEthereumNews.com. With the development of 2025, certain large cryptocurrencies encounter continuous issues and a new player secures an impressive advantage. Solana is struggling with congestion, and the ADA of Cardano is still at a significantly lower level than its highest price. In the meantime, Lyno AI presale is gaining momentum, attracting a large number of investors. Solana Faces Setbacks Amid Market Pressure However, despite the hype surrounding ETFs, Solana fell by 7% to $ 203, due to the constant congestion problems that hamper its network functionality. This makes adoption slow and aggravates traders who want to get things done quickly. Recent upgrades should combat those issues but the competition is rising, and Solana continues to lag in terms of user adoption and ecosystem development. Cardano Struggles to Regain Momentum ADA, the token of a Cardano, costs 72% less than the 2021 high and is developing more slowly than Ethereum Layer 2 solutions. The adoption of the coin is not making any progress despite the good forecasts. Analysts believe that the road to regain the past heights is long before Cardano can go back, with more technological advancements getting more and more attention. Lyno AI’s Explosive Presale Growth In stark contrast, Lyno AI is currently in its Early Bird presale, in which tokens are sold at 0.05 per unit and have already sold 632,398 tokens and raised 31,462 dollars. The next stage price will be established at $0.055 and the final target will be at $0.10. Audited by Cyberscope , Lyno AI provides a cross-chain AI arbitrage platform that enables retail traders to compete with institutions. Its AI algorithms perform trades in 15+ blockchains in real time, opening profitable arbitrage opportunities to everyone. Those who make purchases above 100 dollars are also offered the possibility of winning in the 100K Lyno AI…
Share
BitcoinEthereumNews2025/09/18 18:22
Semler Scientific founder: Special shareholders' meeting approving the proposed merger with Strive will be held on January 13.

Semler Scientific founder: Special shareholders' meeting approving the proposed merger with Strive will be held on January 13.

PANews reported on December 30th that Eric Semler, founder of the US-listed company Semler Scientific, issued a statement urging all shareholders to vote in favor
Share
PANews2025/12/30 08:23
GBP/USD has moved into a range-trading phase – UOB Group

GBP/USD has moved into a range-trading phase – UOB Group

The post GBP/USD has moved into a range-trading phase – UOB Group appeared on BitcoinEthereumNews.com. Pound Sterling (GBP) has moved into a range-trading phase; softening underlying tone suggests it is likely to test the lower end of the 1.3470/1.3650 range first, UOB Group’s FX analysts Quek Ser Leang and Peter Chia note. GBP/USD is likely to test the lower end of the 1.3470/1.3650 range 24-HOUR VIEW: “After GBP briefly rose to 1.3726 two days ago and then plummeted, we indicated yesterday that ‘the brief rise did not result in any increase in upward momentum.’ We were of the view that GBP ‘is likely to range-trade between 1.3600 and 1.3665.’ GBP subsequently edged up to 1.3661 and then plummeted to a low of 1.3534. While the sharp drop has scope to extend, the decline is quickly approaching oversold level, and any further downside is likely limited to a test of 1.3520. The next support at 1.3470 is unlikely to come into view. To keep the momentum, GBP must hold below 1.3600, with minor resistance at 1.3575.” 1-3 WEEKS VIEW: “Two days ago (17 Sep, spot at 1.3655), we highlighted that ‘there is room for further GBP gains toward 1.3700.’ We also highlighted that ‘the odds of an extended rise to 1.3765 are currently lower.’ After GBP rose to 1.3726 and then pulled back sharply, we highlighted yesterday (18 Sep, spot at 1.3635) that ‘there has been no further increase in upward momentum, and the odds of GBP rising to 1.3765 have diminished noticeably.’ We pointed out that ‘only a breach of 1.3575 (‘strong support’ level) would indicate that GBP has moved into a range-trading phase.’ GBP then breached 1.3575, dropping to a low of 1.3534. GBP appears to have moved into a range-trading phase, but the softening underlying tone suggests it is likely to test the lower end of the 1.3470/1.3650 range first.” Source: https://www.fxstreet.com/news/gbp-usd-has-moved-into-a-range-trading-phase-uob-group-202509191115
Share
BitcoinEthereumNews2025/09/19 23:04