TLDR Trust Wallet confirmed a $7 million loss due to a breach in its Chrome extension. Users of version 2.68 of the Trust Wallet extension were impacted. Trust TLDR Trust Wallet confirmed a $7 million loss due to a breach in its Chrome extension. Users of version 2.68 of the Trust Wallet extension were impacted. Trust

Trust Wallet to Refund $7M Following Chrome Extension Vulnerability

TLDR

  • Trust Wallet confirmed a $7 million loss due to a breach in its Chrome extension.

  • Users of version 2.68 of the Trust Wallet extension were impacted.

  • Trust Wallet promises to fully reimburse the affected users.

  • Trust Wallet urges users to upgrade to version 2.69 to avoid risks.


Trust Wallet has confirmed a significant security breach affecting its Chrome browser extension. The company revealed that approximately $7 million in user funds had been compromised due to a vulnerability in version 2.68 of the extension. The breach was identified after a warning was issued by blockchain investigator ZachXBT, who observed suspicious activities involving the affected extension version.

In response to the breach, Trust Wallet assured users that all impacted individuals would be fully reimbursed. The company stated that addressing the incident and ensuring the safety of its users remains a top priority. Trust Wallet clarified that this security issue was isolated to the Chrome extension version 2.68, and users with other versions, including the mobile-only app, were not affected.

Immediate Actions Taken by Trust Wallet

To mitigate the damage, Trust Wallet swiftly acted by advising users to disable the compromised version and upgrade to version 2.69, which is considered secure. The company emphasized that the vulnerability was exclusive to the specific browser extension version and assured users that no other versions or mobile users were impacted.

Trust Wallet has actively communicated with users throughout the event, explaining the steps for remediation.

Users were also warned not to interact with messages or instructions that did not originate from Trust Wallet’s official channels, as scammers may exploit the situation for further malicious activity. The company stated that it would provide further updates as the refund process is finalized.

Security Concerns Around Browser Extensions

The breach has once again drawn attention to the security risks associated with browser extensions, especially in the crypto wallet space. Updates to such extensions can sometimes introduce vulnerabilities, raising concerns over supply-chain risks. Trust Wallet has not disclosed specific technical details regarding the cause of the breach, but the event has underscored the need for enhanced security measures in crypto wallet software.

Commenting on the issue, Richard Heart, a notable figure in the crypto community, warned against automatic updates in software, citing this as a potential vector for supply chain attacks. He wrote on X,

He continued to emphasize that software updates should not happen automatically and that users should control updates themselves to avoid vulnerabilities introduced by external updates.

Trust Wallet Refund Process and Ongoing Investigation

While Trust Wallet has assured users that their losses will be refunded, the company continues to investigate the root cause of the breach. The incident has raised questions about the security protocols in place for updates and the need for heightened vigilance from users and developers alike.

Trust Wallet has emphasized that users who were impacted by the breach will receive detailed instructions on how to proceed with the refund process. The company also reassured users that they are working on long-term solutions to enhance the security of their products moving forward.

As the investigation continues, Trust Wallet remains committed to transparency and will provide further details as they become available. The company also reiterated that the breach was contained to a single version of the extension, helping to limit the overall impact on users.

The post Trust Wallet to Refund $7M Following Chrome Extension Vulnerability appeared first on CoinCentral.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Shocking OpenVPP Partnership Claim Draws Urgent Scrutiny

Shocking OpenVPP Partnership Claim Draws Urgent Scrutiny

The post Shocking OpenVPP Partnership Claim Draws Urgent Scrutiny appeared on BitcoinEthereumNews.com. The cryptocurrency world is buzzing with a recent controversy surrounding a bold OpenVPP partnership claim. This week, OpenVPP (OVPP) announced what it presented as a significant collaboration with the U.S. government in the innovative field of energy tokenization. However, this claim quickly drew the sharp eye of on-chain analyst ZachXBT, who highlighted a swift and official rebuttal that has sent ripples through the digital asset community. What Sparked the OpenVPP Partnership Claim Controversy? The core of the issue revolves around OpenVPP’s assertion of a U.S. government partnership. This kind of collaboration would typically be a monumental endorsement for any private cryptocurrency project, especially given the current regulatory climate. Such a partnership could signify a new era of mainstream adoption and legitimacy for energy tokenization initiatives. OpenVPP initially claimed cooperation with the U.S. government. This alleged partnership was said to be in the domain of energy tokenization. The announcement generated considerable interest and discussion online. ZachXBT, known for his diligent on-chain investigations, was quick to flag the development. He brought attention to the fact that U.S. Securities and Exchange Commission (SEC) Commissioner Hester Peirce had directly addressed the OpenVPP partnership claim. Her response, delivered within hours, was unequivocal and starkly contradicted OpenVPP’s narrative. How Did Regulatory Authorities Respond to the OpenVPP Partnership Claim? Commissioner Hester Peirce’s statement was a crucial turning point in this unfolding story. She clearly stated that the SEC, as an agency, does not engage in partnerships with private cryptocurrency projects. This response effectively dismantled the credibility of OpenVPP’s initial announcement regarding their supposed government collaboration. Peirce’s swift clarification underscores a fundamental principle of regulatory bodies: maintaining impartiality and avoiding endorsements of private entities. Her statement serves as a vital reminder to the crypto community about the official stance of government agencies concerning private ventures. Moreover, ZachXBT’s analysis…
Share
BitcoinEthereumNews2025/09/18 02:13
Federal Reserve’s Rate Cuts May Affect Cryptocurrency Market

Federal Reserve’s Rate Cuts May Affect Cryptocurrency Market

Detail: https://coincu.com/markets/federal-reserve-2025-rate-cut-plans/
Share
Coinstats2025/09/18 02:40
Here’s why Polygon price is at risk of a 25% plunge

Here’s why Polygon price is at risk of a 25% plunge

Polygon price continued its freefall, reaching its lowest level since April 21, as the broader crypto sell-off gained momentum. Polygon (POL) dropped to $0.1915, down 32% from its highest point in May and 74% below its 2024 peak. The crash…
Share
Crypto.news2025/06/19 00:56