Particle.news
Download on the App Store

Trust Wallet Chrome Extension Breach Triggers $6–7 Million Losses as CZ Vows Reimbursement

The company is auditing the compromised Chrome extension, with CZ pledging full reimbursement.

Overview

  • Trust Wallet confirmed the incident was limited to Chrome extension version 2.68 and urged users to disable it and upgrade to the fixed release, version 2.69.
  • The company said mobile users and other extension versions were not affected by the breach.
  • On-chain investigator ZachXBT flagged widespread unauthorized outflows after the Dec. 24 update, with reports pointing to hundreds of impacted users and losses topping $6 million.
  • CZ said at least $7 million was affected and that Trust Wallet will cover user losses, while the team reviews how a malicious version was submitted.
  • Researchers report the attacker moved funds through many addresses, with roughly $4.25 million routed to services including KuCoin, HTX, ChangeNOW, and FixedFloat, and the precise root cause remains under investigation.