Overview
- Trust Wallet confirmed the incident was limited to Chrome extension version 2.68 and urged users to disable it and upgrade to the fixed release, version 2.69.
- The company said mobile users and other extension versions were not affected by the breach.
- On-chain investigator ZachXBT flagged widespread unauthorized outflows after the Dec. 24 update, with reports pointing to hundreds of impacted users and losses topping $6 million.
- CZ said at least $7 million was affected and that Trust Wallet will cover user losses, while the team reviews how a malicious version was submitted.
- Researchers report the attacker moved funds through many addresses, with roughly $4.25 million routed to services including KuCoin, HTX, ChangeNOW, and FixedFloat, and the precise root cause remains under investigation.