A serious cryptocurrency wallet security incident has erupted during the Christmas period. Trust Wallet browser extension (version 2.68) was found to have a major vulnerability, allowing hackers to steal over $6 million worth of crypto assets in a short period.



The victim cases are shocking. The largest compromised wallet lost coins worth $3.5 million, and this address has been dormant for over a year. The second affected wallet also lost $1.4 million, with a dormant period of up to two years. What does this mean? It means that even if you haven't moved your assets for a long time and are completely offline, as long as your mnemonic phrase was generated with a vulnerable version, hackers can bypass geographical and temporal restrictions to directly threaten your asset security.

This is not just a simple network intrusion. Experts' analysis points to a more serious possibility: the Trust Wallet development environment or code repository has been compromised, with malicious code directly injected into official updates. The source of private key generation has already been contaminated.

Currently, hackers have transferred over $4 million of illicit funds to various centralized exchanges, attempting to obscure the source of the funds through dispersed transfers. Tracking the funds has become more difficult.

If you are currently using the Trust Wallet browser extension, now is the time to act. Immediately disconnect from the internet and transfer your assets to a new wallet generated through other reliable methods. This is not alarmism but a fact-based recommendation. In the future, when choosing any wallet tool, do not unconditionally trust code that has not undergone rigorous third-party audits. Security always comes first.

This incident serves as a reminder to all crypto asset holders: no matter how long your assets have been untouched or how secure they seem, risks always exist. Regularly check your wallet security, update security practices promptly, and stay alert to any code from unknown sources — these are essential lessons for survival in the crypto world.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 8
  • Repost
  • Share
Comment
0/400
SchrodingerPrivateKeyvip
· 1h ago
Wow... I generated it with version 2.68 last year, and now everyone is stunned. But luckily, there's not much in my wallet haha
View OriginalReply0
RuntimeErrorvip
· 3h ago
Damn, wallets that have been dormant for a year or two can be hacked? How outrageous is that, it seems there's really no such thing as absolute security. Oh my god, the source of private key generation has been compromised, so everything is useless now. Hurry up and transfer the funds, don't wait, this is not a joke. Trust Wallet really sucks this time, can we even trust the official updates? This batch of hackers is getting more professional, directly attacking upstream. Tracing back the 4 million into the exchange will be even more difficult in the future, on-chain tracing has failed. I'm going to check my own wallet version, it's pretty scary. Is this still called Web3 security? Laughing to death.
View OriginalReply0
WhaleSurfervip
· 3h ago
Wow, this is too outrageous. Wallets that have been dormant for one or two years can also be drained? The real despair is the source contamination.
View OriginalReply0
notSatoshi1971vip
· 3h ago
Wow, even dormant wallets can be exploited? The security is really outrageous. Now I understand, choosing a wallet has to be more cautious than choosing a wife. Trust Wallet really let me down this time; source contamination with such operations is unbelievable. Offline isn't even safe? How can we survive then? You have to generate your own private key to feel secure. 4 million into an exchange is black eating black; tracking difficulty skyrockets. Honestly, I'm a bit scared now. I need to check my wallets immediately.
View OriginalReply0
quiet_lurkervip
· 3h ago
Wow, wallets that have been dormant for over a year can still be hacked? This isn't an intrusion issue, it's source contamination... Trustworthiness directly drops to -100, I don't even dare to move my money anymore. The mnemonic phrase was tampered with during generation, who can prevent this? Trust Wallet really blew up this time, it feels like everyone needs to re-evaluate their wallet security. Six million, the hacker must be laughing their head off. Wait, does this mean we need more than just offline wallets, but a fundamental auditing system?
View OriginalReply0
SolidityJestervip
· 3h ago
Wow, getting hacked after being dormant for a year or two, is this still called a cold wallet? It has directly become a hacker's ATM.
View OriginalReply0
GateUser-00be86fcvip
· 3h ago
Damn, Trust Wallet can be penetrated? The wallet that I slept on for two years is gone, how outrageous is that? --- It's about time to abandon these mainstream wallets. Just thinking about the source of private key generation being compromised is terrifying. --- Another bloody lesson learned: you really have to control your own seed phrase. --- Six million dollars just disappeared, no wonder big influencers use air-gapped offline signing. --- Trust Wallet's move feels like the entire ecosystem's confidence is about to collapse. --- The problem is now you have to be extremely cautious when changing wallets. How can we trust a tool? --- Hardware wallets are indeed great, but I haven't bought one because of the hassle. --- I was so scared that I quickly uninstalled the browser extension. These kinds of things shouldn't be touched. --- The idea that the development environment is controlled sounds a bit... how should I put it? It sounds very dark.
View OriginalReply0
POAPlectionistvip
· 3h ago
Wow, this is too outrageous. $6 million just gone like that? How can Trust Wallet be like this? Being exploited even after being offline for more than a year, what's the point of playing anymore? Source pollution, huh? Then there's really no hope. Wake up, everyone. Quickly check if you've used version 2.68. Don't wait any longer. This time, the defenses are completely broken. Which wallet can you still trust?
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)