ZachXBT Reveals at Least $6 Million Stolen from Trust Wallet Users — Browser Extension Vulnerability at the Core

2025-12-26 04:55:06
Beginner
Quick Reads
Blockchain investigator ZachXBT has revealed that a vulnerability in the Trust Wallet browser extension has resulted in the theft of funds from hundreds of users, with losses surpassing $6 million. He further provided an analysis of the incident's specifics and the related security risks.


Image: https://x.com/DegenerateNews/status/2004283308059083250/photo/1

Incident Background and Latest Disclosures

Recently, on-chain investigator ZachXBT issued a critical security alert through social media and blockchain monitoring tools, revealing a vulnerability in the Trust Wallet browser extension. This flaw enabled the unauthorized transfer and theft of crypto assets from hundreds of users in a short time frame. Preliminary monitoring estimates place the total stolen amount at no less than $6 million.

The news spread rapidly across the crypto community, drawing significant attention from both users and industry professionals. ZachXBT’s monitoring data shows that several wallet addresses experienced suspicious outflows simultaneously. These funds were routed to unknown addresses or intermediary accounts and subsequently moved again.

Analysis of Losses and Impacted User Scale

Recent tracking data indicates that several hundred victims have been identified, with losses spanning multiple blockchains and assets—including, but not limited to, ETH, BTC, and SOL. The irregularities were not isolated to a single chain but were distributed across many wallet addresses, highlighting the event’s substantial scale.

In his latest update, ZachXBT emphasized that the sheer number of affected wallets makes it difficult to verify losses for each address. However, the preliminary estimate already exceeds $6 million, and this figure may rise as additional victims report their losses.

Stolen Funds Flow and Attack Patterns

Current analysis of fund movements suggests these thefts are tied to the browser extension vulnerability, especially when users import private keys or seed phrases, exposing themselves to significant risk. Multiple victims reported that their funds were drained rapidly to unknown accounts, indicating attackers had immediate access.

On-chain data shows that the attacks were highly automated, with stolen funds quickly dispersed and transferred across chains. This pattern differs from traditional hacks and more closely resembles a supply chain exploitation targeting hot wallet extension vulnerabilities.

Trust Wallet Official Response and User Actions


Image: https://x.com/TrustWallet/status/2004316503701958786

Trust Wallet has issued a security alert confirming that version 2.68 of the browser extension contains a critical vulnerability. Users are advised to immediately disable this version and upgrade to 2.69 or higher to mitigate risk. The official statement also clarified that the mobile app and other extension versions are not affected by this vulnerability.

Impacted users should take the following steps:

  • Immediately stop using the outdated extension and upgrade to the latest version \
  • If funds remain in your wallet, transfer them promptly to a cold wallet or another secure solution \
  • Report stolen assets through official support channels and retain all related on-chain evidence for investigation \

Security Lessons and Industry Impact

This incident highlights the ongoing challenge of balancing user experience and security in self-custody wallets. While browser extensions offer convenience, they also raise the risk of private key exposure and malicious activity. When users import mnemonic or seed phrases directly into extensions with vulnerabilities, assets can be drained within minutes.

Industry security experts recommend that users prioritize private key management, use hardware wallets or thoroughly audited security solutions, and avoid entering seed phrases into unverified clients or extensions. This event may also prompt wallet developers to enhance supply chain security assessments and code audits, strengthening overall ecosystem defenses.

Summary

ZachXBT’s latest disclosure of the Trust Wallet browser extension vulnerability underscores the critical need for crypto users to prioritize wallet security and remain vigilant about extension risks. In this incident, hundreds of users lost at least $6 million, prompting the community to re-examine self-custody wallet security. Users should act quickly to implement security measures, monitor official updates, and adopt safer asset management strategies to prevent similar incidents in the future.

Author: Max
Disclaimer
* The information is not intended to be and does not constitute financial advice or any other recommendation of any sort offered or endorsed by Gate.
* This article may not be reproduced, transmitted or copied without referencing Gate. Contravention is an infringement of Copyright Act and may be subject to legal action.

Share

Crypto Calendar
Tokenların Kilidini Aç
Wormhole, 3 Nisan'da 1.280.000.000 W token açacak ve bu, mevcut dolaşımdaki arzın yaklaşık %28,39'unu oluşturacak.
W
-7.32%
2026-04-02
Tokenların Kilidini Aç
Pyth Network, 19 May'da 2.130.000.000 PYTH tokenini serbest bırakacak ve bu, mevcut dolaşım arzının yaklaşık %36,96'sını oluşturacak.
PYTH
2.25%
2026-05-18
Tokenların Kilidini Aç
Pump.fun, 12 Temmuz'da 82,500,000,000 PUMP token'ı kilidini açacak ve bu, mevcut dolaşımdaki arzın yaklaşık %23,31'ini oluşturacak.
PUMP
-3.37%
2026-07-11
Token Kilidi Açma
Succinct, 5 Ağustos'ta mevcut dolaşımdaki arzın yaklaşık %104,17'sini oluşturan 208,330,000 PROVE token'ını serbest bırakacak.
PROVE
2026-08-04
sign up guide logosign up guide logo
sign up guide content imgsign up guide content img
Sign Up

Related Articles

What is Fartcoin? All You Need to Know About FARTCOIN
Intermediate

What is Fartcoin? All You Need to Know About FARTCOIN

Fartcoin (FARTCOIN) is a representative meme coin within the Solana ecosystem based on an AI-driven narrative. Its core concept originated from an experiment aimed at exploring the "boundaries between AI Agents and humor." More than just a digital asset with social attributes, the project deeply couples absurd humor culture with on-chain financial logic by integrating autonomous AI interaction models.
2026-03-04 05:38:51
Gold Price Forecast for the Next Five Years: 2026–2030 Trend Outlook and Investment Implications, Could It Reach $6,000?
Beginner

Gold Price Forecast for the Next Five Years: 2026–2030 Trend Outlook and Investment Implications, Could It Reach $6,000?

Analyze current gold price trends alongside authoritative five-year forecasts, integrating an evaluation of market risks and opportunities. This gives investors insight into the potential trajectory of gold prices and the main drivers expected to shape the market over the next five years.
2026-01-26 03:33:33
2026 Silver Price Forecast: Bull Market Continuation or High-Level Pullback? In-Depth Analysis of Silver Candlestick Chart
Beginner

2026 Silver Price Forecast: Bull Market Continuation or High-Level Pullback? In-Depth Analysis of Silver Candlestick Chart

2026 Silver Price Forecast: Latest Outlook This article integrates current market trends, silver candlestick chart analysis, and momentum factors to assess the potential key support and resistance levels, upside targets, and pullback risks for silver prices. The goal is to help investors make informed, rational decisions.
2026-01-28 08:36:39
Crypto Future Profit Calculator: How to Calculate Your Potential Gains
Beginner

Crypto Future Profit Calculator: How to Calculate Your Potential Gains

Crypto Future Profit Calculator helps traders estimate potential earnings from futures contracts by considering entry price, leverage, fees, and market movement.
2025-02-09 17:28:28
Crypto Futures Calculator: Easily Estimate Your Profits & Risks
Beginner

Crypto Futures Calculator: Easily Estimate Your Profits & Risks

Use a crypto futures calculator to estimate profits, risks, and liquidation prices. Optimize your trading strategy with accurate calculations.
2025-02-11 02:25:44
What is Oasis Network (ROSE)?
Beginner

What is Oasis Network (ROSE)?

The Oasis Network is driving the development of Web3 and AI through smart privacy technology. With its privacy protection, high scalability, and cross-chain interoperability, the Oasis Network is providing new possibilities for the future development of decentralized applications.
2025-05-20 09:41:15