Yesterday, just before Christmas, Trust Wallet
Namely, on December 24, they released a vulnerable wallet extension for Chrome, and on December 25, it turned out to be compromised. As a result, this resulted in losses of over $6 million (including ETH, SOL, and BTC)🫠
The attack took place without user involvement: there was no need to import or interact with suspicious dApps. It was enough for a person to simply open a wallet, and the money was instantly debited, so quickly that the user did not have time to react and cancel the transaction.
I, like many others, quickly determined that it was a supply chain attack, as it occurred suspiciously soon after the update was released🦠
In this attack, the attackers embedded payload in the update. Most likely, through a compromised developer account or insiders
Trust Wallet has not officially disclosed the details of exactly how the attack occurred, but there is information from independent researchers that a malicious script is to blame 4482.js , which masqueraded as analytics.
This code monitored the wallet's activity and was activated at the time of importing the seed phrase or opening the extension with already saved data.
As soon as the seed got into the local storage
After receiving the seed, the attackers' system automatically generated and signed transactions on behalf of the user
I noticed that the records on the blockchain show the high speed of these transactions: bitcoin, ethereum, and BNB were lost in value, and in all reported cases, funds were transferred almost instantly. After the initial launch, the funds were moved between several wallets
Trust Wallet responded pretty fast: they officially confirmed the incident, emphasizing that the problem affected only the browser extension version 2.68. Mobile applications, desktop and other versions are fine.
Now activists like @zachxbt are investigating exactly what happened, and you can join them, in particular, analyze the addresses and transactions where the funds went🔎
Here is their list:
Ethereum and other EVM networks:
0x3b09A3c9aDD7D0262e6E9724D7e823Cd767a0c74
0x463452C356322D463B84891eBDa33DAED274cB40
0xa42297ff42a3b65091967945131cd1db962afae4
0xe072358070506a4DDA5521B19260011A490a5aaA
0xc22b8126ca21616424a22bf012fd1b7cf48f02b1
0x109252d00b2fa8c79a74caa96d9194eef6c99581
0x30cfa51ffb82727515708ce7dd8c69d121648445
0x4735fbecf1db342282ad5baef585ee301b1bce25
0xf2dd8eb79625109e2dd87c4243708e1485a85655
Bitcoin:
bc1qjj7mj50s2e38m4nn7pt2j0ffddxmuxh2g8tyd8
bc1ql9r9a4uxmsdwkenjwx7t5clslsf62gxt8ru7e8
bc1q4g8u7kctk6f2x3f6nh43x76qm4fd0xyv3jugdy
bc1qw7s35umfzgcc7nmjdj9wsyuy9z3g6kqjr0vc7w
bc1qgccgl9d0wzxxnvklj4j55wqeqczgkn6qfcgjdg
bc1q3ykewj0xu0wrwxd2dy4g47yp75gxxm565kaw6
Solana:
HoQ6z1wW3LUnEGHnseC3ND3PoC6i6RghMCphHhK42FEH
In the end, I'll give you some advice🛠: alas, browser extensions even from the official developers of the most reliable wallets can pose a threat. Therefore, for large amounts, switch to hardware wallets, check for updates manually, and never import a seed phrase into browser plugins🔒❤️
That's all that's known at the moment✒️
Let's see how the situation develops and how Trust Wallet reacts to this incident, especially given the relatively recent incident on Binance (which Trust Wallet owns).
#blockchain #bitcoin #crypto #crypto_wallet #crypto_protection #cve #web #attacks #news #chrome_extension #Trust_Wallet #supply_chain



