📈 Get daily crypto insights that make you smarter about your money

Trust Wallet Chrome Extension Supply Chain Attack Exposes 2,520 Wallets and .5 Million in Crypto

The cryptocurrency security landscape faced a stark reminder of supply chain vulnerabilities on January 7, 2026, as the full extent of the Trust Wallet Chrome Extension compromise became publicly known. Attackers infiltrated the browser extension release pipeline in late November 2025, ultimately deploying a malicious version (2.68) on December 24, 2025. By January 7, the attack had drained $8.5 million from 2,520 wallets, with stolen funds exfiltrated to attacker-controlled infrastructure at a domain mimicking Trust Wallet metrics collection.

The Exploit Mechanics

The Trust Wallet supply chain attack represents a sophisticated multi-stage intrusion into the extension development and distribution pipeline. Attackers first obtained GitHub secrets and a Chrome Web Store API key, giving them the ability to push updates directly through what appeared to be an official channel. The malicious version 2.68 contained code that intercepted wallet private keys and seed phrases during routine user operations, quietly transmitting them to metrics-trustwallet[.]com — a domain designed to blend in with legitimate analytics traffic.

What made this attack particularly dangerous was its stealth. The compromised extension functioned normally for everyday wallet operations. Users could send and receive tokens, check balances, and interact with dApps without any visible indication that their credentials were being siphoned. The exfiltration was designed to be gradual, avoiding the sudden large transactions that typically trigger security alerts.

Affected Systems

The attack primarily impacted users of the Trust Wallet Chrome browser extension who had updated to version 2.68 between December 24, 2025, and January 7, 2026. With Bitcoin trading at approximately $91,308 and Ethereum at $3,167 on the day the breach was publicly disclosed, the $8.5 million in losses represented a significant blow to affected users. The attack underscores a broader vulnerability in browser-based crypto wallets, which rely on extension marketplace security that is often beyond the wallet developer direct control.

This incident also coincided with the disclosure of n8n CVE-2026-21858 (Ni8mare), a maximum-severity CVSS 10.0 remote code execution vulnerability in the n8n workflow automation platform. While unrelated to Trust Wallet directly, the n8n flaw affected 26,500 internet-exposed instances and highlighted how interconnected developer tooling creates cascading risks across the cryptocurrency ecosystem.

The Mitigation Strategy

Trust Wallet responded by revoking the compromised Chrome Web Store API credentials, pulling the malicious extension version, and pushing a clean update through the restored pipeline. Users were advised to immediately migrate their funds to fresh wallet addresses generated on a trusted version of the extension or, ideally, on a hardware wallet. The company also implemented additional code-signing verification steps and multi-party approval requirements for future extension updates.

Security researchers recommended that affected users treat all credentials associated with the compromised extension as fully exposed, even if funds had not yet been moved. The gradual nature of the exfiltration meant that some private keys may have been harvested but not yet used by attackers.

Lessons Learned

The Trust Wallet breach demonstrates that even well-established crypto products are vulnerable to supply chain attacks when their distribution infrastructure is compromised. The $8.5 million loss from 2,520 wallets shows that attackers can achieve significant returns by targeting the update mechanisms rather than the wallet software itself. This attack occurred within a month where cryptocurrency losses reached approximately $385 million across all attack vectors, with the Trust Wallet incident ranking among the most significant supply chain compromises in crypto history.

Key Takeaways:

  • Supply chain attacks target the distribution infrastructure, not the product code
  • Browser extensions remain a high-risk attack surface for cryptocurrency users
  • Gradual exfiltration can delay detection by weeks
  • API key and GitHub secret hygiene is critical for all crypto projects
  • Users should verify extension versions and monitor for unauthorized updates

User Action Required

If you used Trust Wallet Chrome Extension version 2.68 between December 24, 2025, and January 7, 2026, immediately move all funds to a new wallet address generated on a verified clean installation. Check your transaction history for any unauthorized transfers. Consider switching to a hardware wallet for long-term storage of significant cryptocurrency holdings. Enable additional security notifications through Trust Wallet mobile app and monitor your wallet addresses on blockchain explorers for any unexpected activity.

This article is for informational purposes only and does not constitute financial or security advice. Always consult with qualified security professionals for specific guidance.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

24 thoughts on “Trust Wallet Chrome Extension Supply Chain Attack Exposes 2,520 Wallets and .5 Million in Crypto”

  1. 2,520 wallets drained over two weeks and nobody flagged it until $8.5M was gone. supply chain attacks are the silent killer most people dont even think about

    1. ^ the metrics-trustwallet dot com domain is what gets me. exfiltrating keys through a domain that looks like normal analytics traffic is next level opsec

      1. the fake analytics domain was the cleverest part honestly. metrics-trustwallet dot com blends right into any network traffic log. whoever built this knew exactly what they were doing

    2. ext_perm_audit_

      dumpster_fi 2520 wallets over two weeks means roughly 180 drains per day. trust wallet had zero monitoring on their own chrome store listing. thats the real failure here

    3. two weeks of draining and trust wallet didnt notice because the malicious domain blended with analytics traffic. supply chain attacks dont need zero days, they need good disguises

  2. getting both github secrets AND the chrome web store API key means this was either an inside job or a very targeted phishing campaign. supply chain attacks dont happen by accident

    1. seed_phrase_audit_

      cws_api_leak_ getting both GitHub secrets AND the Chrome Web Store API key screams targeted phishing or insider access. supply chain attacks at this level dont happen by accident

  3. 2520 wallets at 3400 average per victim. they specifically kept amounts small to stay under exchange AML thresholds. brutal efficiency

    1. ext_reviewer_ the $3400 average was probably calculated to avoid triggering manual review at major exchanges. these were not amateurs

  4. sat on github secrets since november and waited for christmas eve to push the malicious build. premeditated barely covers it

    1. Soren B. sitting on github secrets since november then pushing the malicious build on christmas eve. they specifically chose a date when devs would be on holiday. surgical timing

    1. ext_pragmatist

      LedgerMike is right. browser extensions are not wallets. but telling people to buy hardware wallets is like telling people to buy a safe when they keep losing their house keys

  5. $8.5M from 2520 wallets averages out to like $3400 per victim. small enough that most people wouldnt even notice for weeks. brutal design

    1. 2520 wallets drained at 3400 dollars average per victim. small enough amounts to dodge exchange alerts for weeks. the attackers optimized for stealth not size

  6. version 2.68 pushed through the official chrome store. no amount of personal opsec protects you when the update channel itself is compromised

    1. supplychain_ghost

      the chrome store is supposed to be a trusted distribution channel. when the update pipeline itself is compromised, individual user opsec is meaningless

  7. xmas_eve_breach

    pushing the malicious build on christmas eve was calculated. security teams skeleton staffed, users installing updates before traveling. every detail was optimized for maximum dwell time

    1. xmas_eve_breach two weeks of draining before anyone noticed. 180 wallets per day and not a single alert from Trust Wallet monitoring. they didnt even watch their own chrome store listing

      1. Chen L. exactly. they kept individual drains small on purpose to avoid triggering exchange withdrawal alerts. 180 wallets a day at $3400 each is pure guerrilla warfare

        1. metrics-trustwallet dot com is such a basic social engineering trick. any security team reviewing DNS logs weekly would have caught this

  8. metrics-trustwallet dot com blended into network traffic so cleanly that no monitoring flagged it for two weeks. the domain naming alone was masterclass social engineering

  9. 2520 wallets at 3400 average per victim. they kept each drain small enough to dodge exchange withdrawal thresholds. whoever designed this studied AML triggers

    1. crx_oracle_ keeping drains at 3400 average to dodge AML thresholds means this crew studied exchange compliance frameworks. this was a professional operation not a script kiddie job

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$65,184.00+1.1%ETH$1,962.45+4.2%SOL$76.39+1.7%BNB$571.66+0.2%XRP$1.11+0.7%ADA$0.1650+0.1%DOGE$0.0726-0.9%DOT$0.8107-2.2%AVAX$6.61-1.5%LINK$8.78+4.3%UNI$3.91+6.1%ATOM$1.38-0.9%LTC$46.91-0.6%ARB$0.0818-0.7%NEAR$1.84+2.2%FIL$0.7390-1.3%SUI$0.7161-0.3%BTC$65,184.00+1.1%ETH$1,962.45+4.2%SOL$76.39+1.7%BNB$571.66+0.2%XRP$1.11+0.7%ADA$0.1650+0.1%DOGE$0.0726-0.9%DOT$0.8107-2.2%AVAX$6.61-1.5%LINK$8.78+4.3%UNI$3.91+6.1%ATOM$1.38-0.9%LTC$46.91-0.6%ARB$0.0818-0.7%NEAR$1.84+2.2%FIL$0.7390-1.3%SUI$0.7161-0.3%
Scroll to Top