Phishing, exploits & privacy
Trust Wallet’s extension incident: the December 2025 record
As of 26.12.2025, this looks like a straight supply chain compromise of the Trust Wallet Chrome extension, not a user approval mistake.
Original publication · 26 Dec 2025. Figures, claims and opinions reflect the original publication date.
The original publications are in English. Navigation is available in seven languages.
Everything we know about the #TrustWallet exploit summarized:
As of 26.12.2025, this looks like a straight supply chain compromise of the Trust Wallet Chrome extension, not a user approval mistake.
🔺What happened:
Trust Wallet shipped Chrome extension v2.68.0 on 24.12.2025. Shortly after, users who imported or accessed their seed in that version got drained, often within minutes.
🔺What the code allegedly did:
Researchers and trackers describe a malicious JavaScript payload in the extension, commonly referenced as a file like 4482.js, disguised as analytics or a PostHog style integration. The goal was simple: exfiltrate mnemonics to attacker infrastructure such as domains like metrics- trustwallet. com or api. metrics- trustwallet. com, then sweep funds.
🔺Why the drains were so brutal:
If the attacker has your seed, there is no need for approvals, signatures, or phishing popups. They just restore your wallet elsewhere and empty everything across chains that share that seed. That matches the reports: BTC, EVM, SOL, BNB Chain, fast multi hop routing.
🔺On chain money flow highlights:
Tracking reports show a large chunk pushed into services and exchanges. One widely shared breakdown says about 4.25M USD was routed to ChangeNOW, FixedFloat, KuCoin, and HTX. Another tracker post says the attacker drained about 2.8M in crypto across multiple chains. These numbers can overlap depending on snapshot timing and which addresses are included.
🔺Who sounded the alarm:
The first big public warning came from on chain investigator ZachBNB, who connected the drains to the v2.68 update and shared theft addresses while funds were still moving.
🔺Trust Wallet and CZ statements:
Trust Wallet says only browser extension v2.68 was affected, mobile users are not affected, and users should disable v2.68 and upgrade to v2.69. CZ says about 7m USD was affected and Trust Wallet will cover losses, while they investigate how the bad version got submitted. Let's see...
🔺The part that should worry everyone:
The biggest question is not the malware itself. It is how it shipped. If a malicious build can reach the Chrome Web Store under an official wallet brand, then the weakest link is the release pipeline: developer account, build system, CI, signing, third party dependencies, or internal access. CZ explicitly points at the submission path as the open problem.
Delayed warning while users were actively getting wiped No real root cause yet, only scope statements Holiday timing amplified damage and rage Reimbursement helps, but it does not repair trust in the extension model.
@cz_binance acquired the wallet in 2018 through Binance, where he is a majority stakeholder, but did not disclose the purchase price.

#Binance again.
Trust Wallet was acquired by Binance in 2018. Since then, Trust Wallet has operated as a Binance-owned product with its own team and brand, but inside the Binance ecosystem.
CZ is Binance’s founder and largest shareholder, which is why Trust Wallet is often described in media as “CZ-owned”.
Trust Wallet is Binance property.
CZ still controls Binance, even if not officially.

It seems clear that this is either due to incompetence by the Trust Wallet team or simply an inside job.
Looks very bad for Binance and Changpeng Zhao again.
Once more, problems caused by their ecosystem.



