📈 Get daily crypto insights that make you smarter about your money

Trust Wallet Chrome Extension Compromised in Supply Chain Attack Draining $7 Million From User Wallets

Cryptocurrency wallet users woke up to a nightmare on Christmas Eve as Trust Wallet confirmed that a compromised Chrome browser extension update enabled attackers to steal approximately $7 million in digital assets. The incident, which unfolded on December 24, 2023, exposed critical vulnerabilities in software supply chain security within the cryptocurrency ecosystem and sent shockwaves through the non-custodial wallet community.

The Exploit Mechanics

The attack centered on Trust Wallet Chrome extension version 2.68.0, which was released on December 24. Security analyst Akinator, who was among the first to identify the malicious code, discovered that a bundled JavaScript file named 4482.js contained tightly packed malicious logic designed to exfiltrate sensitive wallet data. The code operated under the guise of analytics functionality, secretly capturing seed phrases and transmitting them to an external server hosted at api.metrics-trustwallet[.]com.

The exfiltration mechanism was particularly insidious because it leveraged the normal operation flow of the wallet extension. When users interacted with the extension for routine authorization steps, the malicious code silently captured their seed phrases in the background. This meant that even security-conscious users who followed standard practices were affected, as the compromise occurred at the software distribution level rather than through user error.

In addition to the supply chain attack, researchers identified a coordinated phishing campaign operating through the domain fix-trustwallet[.]com, which was designed to trick users into revealing their recovery phrases directly. This dual-attack vector significantly amplified the potential damage and demonstrated a sophisticated understanding of social engineering tactics.

Affected Systems

Trust Wallet is one of the most widely used non-custodial cryptocurrency wallets, facilitating the storage, management, and interaction with digital assets across multiple blockchains. The Chrome browser extension, specifically targeted in this attack, serves as the primary interface for users interacting with decentralized applications. All users who installed or auto-updated to version 2.68.0 of the Chrome extension were potentially exposed.

With Bitcoin trading at approximately $43,016 and Ethereum at $2,265 on the day of the attack, the $7 million in losses represented a significant sum. Reports from affected users indicated that funds began disappearing immediately after completing what appeared to be routine authorization steps. Initial damage estimates started at $2 million before rapidly climbing to the final figure as more victims came forward.

The Mitigation Strategy

Trust Wallet responded to the incident by releasing version 2.69 of its Chrome extension, which addressed the vulnerability present in the compromised version. The company issued advisories urging all Chrome extension users to immediately update to the patched version and, critically, to move their funds from any potentially compromised wallets to new wallets with fresh seed phrases.

Security researchers emphasized that simply updating the extension was insufficient for users whose seed phrases had already been exfiltrated. Because the attackers had captured recovery phrases, they retained the ability to access affected wallets regardless of subsequent software patches. This underscored the fundamental importance of seed phrase security and the irreversibility of cryptographic key exposure.

Lessons Learned

The Trust Wallet incident highlighted several critical security principles. First, software supply chain attacks represent an escalating threat in the digital asset space, as malicious updates can bypass traditional security measures that rely on user awareness. Second, the attack demonstrated how attackers increasingly combine technical exploits with social engineering, creating multiple pathways to compromise user funds. Third, the speed at which the damage accumulated from initial reports to $7 million in losses within hours illustrates the urgent need for real-time monitoring and rapid response capabilities in wallet software.

User Action Required

If you used Trust Wallet Chrome extension version 2.68.0, immediately create a new wallet with a fresh seed phrase and transfer all funds. Update to version 2.69 or later before using the extension again. Monitor your wallet addresses for unauthorized transactions and report any suspicious activity. Consider using hardware wallets for storing significant amounts of cryptocurrency as an additional layer of protection against software-based supply chain attacks.

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research and consult with security professionals regarding digital asset protection.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

20 thoughts on “Trust Wallet Chrome Extension Compromised in Supply Chain Attack Draining $7 Million From User Wallets”

  1. hardware_only_gang

    4482.js sitting in a chrome extension update stealing seeds on christmas eve. this is why hardware wallets exist. browser extensions are not custody solutions

  2. 4482.js packed into what looked like an analytics module. even paranoid users who check network tabs would see api.metrics-trustwallet and think nothing of it. the lookalike domain was the real weapon

  3. 4482.js hidden inside what looked like analytics. if Akinator hadnt caught it who knows how long the drain would have gone on

  4. a single JS file named 4482.js exfiltrating seed phrases. supply chain attacks are terrifying because users did nothing wrong

    1. a JS file called 4482.js that looked like analytics code actually exfiltrating seed phrases. sushi_chef is right, users literally did nothing wrong besides trusting the extension update

  5. $7m stolen through a fake analytics domain. api.metrics-trustwallet dot com. would you even notice that in the network tab?

    1. update_blind_spot_

      Liam C. $7M through a lookalike domain and Google still hasnt fixed extension update review. same attack vector is open today

      1. update_blind_spot_ Google still not flagging extensions that ping non-vendor domains in 2026. the same attack vector being open 3 years later is wild

    2. ^ thats exactly why i use a separate browser profile for crypto stuff with uBlock origin blocking third party scripts

    3. api.metrics-trustwallet dot com is genius level social engineering. even a security conscious user would skim past that in a network tab

      1. extension_audit_

        nosleep_42 the lookalike domain trick works because browser extension stores dont verify analytics endpoints. google needs to flag extensions that ping non-vendor domains but they wont

      2. extension_para

        api.metrics-trustwallet dot com is the kind of domain that passes every glance test. even paranoid users wouldnt catch that in a network tab

  6. Christmas Eve too. These attackers know exactly when people are distracted. Always verify extension updates manually.

    1. CryptoCarol is right about timing. Christmas Eve deployment means skeleton teams reviewing code and users distracted with family. these attackers plan their windows carefully

      1. Christmas Eve deployment was calculated. skeleton code review teams, users distracted, max damage before anyone notices. $7M in a day

        1. Tariq B. Christmas Eve was strategic on multiple levels. skeleton review teams at Google plus users distracted with family plus crypto twitter on low volume. attackers timed the deployment window perfectly

  7. 4482.js disguised as analytics and exfiltrating seeds on christmas eve. browser extensions are the weakest link in crypto security and nobody treats them that way

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,960.00+0.1%ETH$1,916.11-0.2%SOL$76.74+0.6%BNB$605.90+0.4%XRP$1.03-0.4%ADA$0.1950-0.6%DOGE$0.0699-0.3%DOT$0.8079+0.3%AVAX$6.52+0.8%LINK$8.27-0.3%UNI$4.01+0.7%ATOM$1.38-0.2%LTC$45.34-1.6%ARB$0.0795+2.5%NEAR$1.65+2.7%FIL$0.6999-1.1%SUI$0.6925+0.3%BTC$64,960.00+0.1%ETH$1,916.11-0.2%SOL$76.74+0.6%BNB$605.90+0.4%XRP$1.03-0.4%ADA$0.1950-0.6%DOGE$0.0699-0.3%DOT$0.8079+0.3%AVAX$6.52+0.8%LINK$8.27-0.3%UNI$4.01+0.7%ATOM$1.38-0.2%LTC$45.34-1.6%ARB$0.0795+2.5%NEAR$1.65+2.7%FIL$0.6999-1.1%SUI$0.6925+0.3%
Scroll to Top