The Trust Wallet Browser Extension Supply Chain Attack

Updated 5 Oct 2026 · Incident date 24 Dec 2025 · browser extension

PackageTrust Wallet Browser Extension 2.67 -> 2.68 (fixed in 2.69)
File8423.js and 4482.js modified, new 4f8cd8a01d2966c5de9b....

Trust Wallet browser extension version 2.68 stole seed phrases from users who unlocked their wallet. The Chrome Web Store carried the bad build in December 2025. Version 2.69 is the fix.

The attackers did not break into the extension code in the source repository. They used a leaked Chrome Web Store API key to upload a build themselves.

What happened

An unauthorized build of version 2.68 reached the Chrome Web Store on 24 December 2025. Trust Wallet says the build was published outside its standard release process and without mandatory review. It says the attacker used a Chrome Web Store API key that leaked in the Shai-Hulud supply chain campaign of November 2025. With that key, the attacker could upload extensions and skip the internal approval controls.

BlockSec describes two changed files. In 8423.js, the code that handles wallet unlock gained new code. After a user unlocked with a password or with biometrics, the code went through all wallets and read the decrypted seed phrases. It stored them in a variable with the misleading name errorMessage. In 4482.js, the PostHog analytics settings now pointed to api.metrics-trustwallet.com. The code packed the seed phrases into analytics events, compressed them with GZIP and sent them by HTTP POST. The domain looks like Trust Wallet infrastructure, but the attacker controls it.

The Hacker News reports that the attack domain was registered on 8 December 2025. It reports a first attack request on 21 December 2025 and a release time of 12:32 UTC on 24 December. It says users who logged in before 11:00 UTC on 26 December were at risk.

The loss figures differ by source. Trust Wallet reports about 8.5 million US dollars across 2,520 verified wallet addresses. The Hacker News reports about 7 million US dollars and 2,596 affected wallets. Trust Wallet says it will reimburse affected users and it received more than 5,000 claims, including fraudulent ones.

Affected versions

Indicators of compromise

How to check

Open the extensions page in Chrome and read the Trust Wallet version. You can also search the extension files on disk for the attack domain. This command works on macOS. On Linux, use ~/.config/google-chrome instead.

grep -rl "metrics-trustwallet" ~/Library/Application\ Support/Google/Chrome/*/Extensions/ 2>/dev/null

A match means that profile holds the bad build. No output means the folder has no copy. Also review your wallet addresses for transfers you did not make, since the attacker emptied wallets from 25 December 2025.

What to do now

  1. Update the extension to 2.69 or later.
  2. If you unlocked the wallet on 2.68, move your funds to a new wallet with a new seed phrase. Trust Wallet advises this step.
  3. Submit a claim only through the official Trust Wallet support site. Trust Wallet says it never asks for private keys.
  4. Check wallet history for transfers that you did not start.
  5. Keep API keys for extension stores out of build systems that run third-party code, and rotate them after any package compromise.
  6. Vigilance compares a new extension build with the one you trust and reports the file that gained a new capability. Here, 2.67 had no code that reads seed phrases and sends them out, and 2.68 added it.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old Extension-2.67 --new Extension-2.68
files scanned: 83 (1 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   8423.js
           It downloads from the internet and reads saved passwords and access keys.

Frequently asked questions

Which Trust Wallet extension version was compromised?

Version 2.68 of the Trust Wallet browser extension. Version 2.69 is the fixed release.

How did attackers publish the Trust Wallet 2.68 extension?

Trust Wallet says the attacker used a leaked Chrome Web Store API key, which let them upload a build outside the normal release and review process.

How much was stolen in the Trust Wallet extension attack?

Trust Wallet reports about 8.5 million US dollars across 2,520 verified wallet addresses. The Hacker News reports about 7 million US dollars.

What should I do if I used Trust Wallet extension 2.68?

Update to 2.69 or later and move your funds to a new wallet with a new seed phrase. Trust Wallet says the old seed phrase may be exposed if you unlocked the wallet on 2.68.

Sources

  1. trustwallet.com/blog/announcements/trust-wallet-browser-extension-v268-incident-community-update
  2. blocksec.com/blog/trust-wallet-incident-a-stolen-api-key-turns-the-official-update-channel-into-a-backdoor
  3. thehackernews.com/2025/12/trust-wallet-chrome-extension-bug.html

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free