Stop overpaying - start transferring money with Ogvio. Sign up, invite friends & grab Rewards now! 🎁
Insider Attack? Trust Wallet Breach Linked to Compromised Build
Key Takeaways
- Trust Wallet’s browser extension v2.68 suffered a $7 million breach due to a backdoor, which affected only desktop users;
- The team fixed the issue in v2.69, urged users to update, and pledged to reimburse all affected wallet holders;
- Investigations suggest insider involvement, with rogue code added in early December and funds stolen starting December 25.
A Trust Wallet browser extension update led to a security breach involving approximately $7 million in losses.
The issue was linked to build 2.68, released on December 25. Only users who had this version on desktop systems were affected, while those using the official mobile application or other plugin versions were not impacted.
After discovering the issue, the development team instructed users to uninstall the vulnerable build and switch to version 2.69 available on the Chrome Web Store.
Did you know?
Subscribe - We publish new crypto explainer videos every week!
Harmony ONE Explained (Beginner-Friendly Animation)
Trust Wallet addressed the breach and will fully cover losses for impacted users. The announcement assured the community that user wallets are considered safe, despite the vulnerability exposed by the browser extension.
According to SlowMist, the browser plugin was compromised with a backdoor. Data was sent to a server under the attacker's control.
Their findings suggested the rogue code might have been introduced on December 8, with the actual backdoor activating around December 22. The theft of funds began on December 25.
Blockchain adviser Anndy Lian described the breach as unlikely to be a random occurrence. He said:
This kind of 'hack' is not natural. The chances of an insider are high.
Changpeng Zhao, co-founder of Binance
Recently, Binance co-CEO Yi He’s WeChat was hacked after her old phone number was reassigned, which led to fake token promotions. How? Read the full story.