The Trust Wallet Browser Extension Supply Chain Attack
Updated 5 Oct 2026 · Incident date 24 Dec 2025 · browser extension
Trust Wallet Browser Extension 2.67 -> 2.68 (fixed in 2.69)8423.js and 4482.js modified, new 4f8cd8a01d2966c5de9b....Trust Wallet browser extension version 2.68 stole seed phrases from users who unlocked their wallet. The Chrome Web Store carried the bad build in December 2025. Version 2.69 is the fix.
The attackers did not break into the extension code in the source repository. They used a leaked Chrome Web Store API key to upload a build themselves.
What happened
An unauthorized build of version 2.68 reached the Chrome Web Store on 24 December 2025. Trust Wallet says the build was published outside its standard release process and without mandatory review. It says the attacker used a Chrome Web Store API key that leaked in the Shai-Hulud supply chain campaign of November 2025. With that key, the attacker could upload extensions and skip the internal approval controls.
BlockSec describes two changed files. In 8423.js, the code that handles wallet unlock gained new code. After a user unlocked with a password or with biometrics, the code went through all wallets and read the decrypted seed phrases. It stored them in a variable with the misleading name errorMessage. In 4482.js, the PostHog analytics settings now pointed to api.metrics-trustwallet.com. The code packed the seed phrases into analytics events, compressed them with GZIP and sent them by HTTP POST. The domain looks like Trust Wallet infrastructure, but the attacker controls it.
The Hacker News reports that the attack domain was registered on 8 December 2025. It reports a first attack request on 21 December 2025 and a release time of 12:32 UTC on 24 December. It says users who logged in before 11:00 UTC on 26 December were at risk.
The loss figures differ by source. Trust Wallet reports about 8.5 million US dollars across 2,520 verified wallet addresses. The Hacker News reports about 7 million US dollars and 2,596 affected wallets. Trust Wallet says it will reimburse affected users and it received more than 5,000 claims, including fraudulent ones.
Affected versions
- Trust Wallet Browser Extension 2.68. Version 2.67 was the clean release before it.
- Fixed in 2.69.
- At risk: any user who unlocked the wallet while 2.68 was installed. Trust Wallet places the incident between 24 and 26 December 2025.
Indicators of compromise
- Domain:
metrics-trustwallet.com. - Subdomain:
api.metrics-trustwallet.com. It receives GZIP-compressed analytics events. - Changed files in the extension:
8423.jsand4482.js. - A variable named
errorMessagethat holds decrypted seed phrases in8423.js. - Extension version 2.68.
How to check
Open the extensions page in Chrome and read the Trust Wallet version. You can also search the extension files on disk for the attack domain. This command works on macOS. On Linux, use ~/.config/google-chrome instead.
grep -rl "metrics-trustwallet" ~/Library/Application\ Support/Google/Chrome/*/Extensions/ 2>/dev/null
A match means that profile holds the bad build. No output means the folder has no copy. Also review your wallet addresses for transfers you did not make, since the attacker emptied wallets from 25 December 2025.
What to do now
- Update the extension to 2.69 or later.
- If you unlocked the wallet on 2.68, move your funds to a new wallet with a new seed phrase. Trust Wallet advises this step.
- Submit a claim only through the official Trust Wallet support site. Trust Wallet says it never asks for private keys.
- Check wallet history for transfers that you did not start.
- Keep API keys for extension stores out of build systems that run third-party code, and rotate them after any package compromise.
- Vigilance compares a new extension build with the one you trust and reports the file that gained a new capability. Here, 2.67 had no code that reads seed phrases and sends them out, and 2.68 added it.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 83 (1 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE 8423.js It downloads from the internet and reads saved passwords and access keys.
Frequently asked questions
Which Trust Wallet extension version was compromised?
Version 2.68 of the Trust Wallet browser extension. Version 2.69 is the fixed release.
How did attackers publish the Trust Wallet 2.68 extension?
Trust Wallet says the attacker used a leaked Chrome Web Store API key, which let them upload a build outside the normal release and review process.
How much was stolen in the Trust Wallet extension attack?
Trust Wallet reports about 8.5 million US dollars across 2,520 verified wallet addresses. The Hacker News reports about 7 million US dollars.
What should I do if I used Trust Wallet extension 2.68?
Update to 2.69 or later and move your funds to a new wallet with a new seed phrase. Trust Wallet says the old seed phrase may be exposed if you unlocked the wallet on 2.68.
Sources
More supply chain attacks
- Offside Wallet Theft Factory (Firefox add-ons converted from sports-score tools) 9 Mar 2026
- QuickLens / ShotBird ownership-transfer hijack 17 Feb 2026
- RedDirection campaign (Color Picker Geco and 17 others) 27 Jun 2025
- Cyberhaven Chrome extension compromise 25 Dec 2024
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.