Trust Wallet exploited Christmas vulnerability, causing users to lose approximately $7 million, suspected to be related to insider involvement.
🔷 The Trust Wallet browser extension version 2.68 was found to have a backdoor, mainly affecting desktop users; Trust Wallet recommends updating to v2.89.
🔷 Changpeng Zhao (CZ) – co-founder of Binance (the company that owns Trust Wallet) confirmed that Binance will compensate for all damages.
🔷 According to SlowMist, the attacker prepared from 8/12, installed the backdoor on 22/12, and withdrew funds on Christmas; the malware also collected personal data sent to the attacker’s server.
🔷 ZachXBT stated that hundreds of users were affected; some experts (including Anndy Lian) and CZ believe it is highly likely an inside job, as the attacker could push the infected extension to the website.
🔷 Chainalysis: excluding the $1.4 billion incident at Bybit, personal wallet cases accounted for 37% of the stolen value in 2025 — indicating increasing risks.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Trust Wallet exploited Christmas vulnerability, causing users to lose approximately $7 million, suspected to be related to insider involvement.
🔷 The Trust Wallet browser extension version 2.68 was found to have a backdoor, mainly affecting desktop users; Trust Wallet recommends updating to v2.89.
🔷 Changpeng Zhao (CZ) – co-founder of Binance (the company that owns Trust Wallet) confirmed that Binance will compensate for all damages.
🔷 According to SlowMist, the attacker prepared from 8/12, installed the backdoor on 22/12, and withdrew funds on Christmas; the malware also collected personal data sent to the attacker’s server.
🔷 ZachXBT stated that hundreds of users were affected; some experts (including Anndy Lian) and CZ believe it is highly likely an inside job, as the attacker could push the infected extension to the website.
🔷 Chainalysis: excluding the $1.4 billion incident at Bybit, personal wallet cases accounted for 37% of the stolen value in 2025 — indicating increasing risks.
➡️ Recommendation: Trust Wallet users should upgrade to the latest version immediately, check their computers for (malware), and monitor compensation announcements from Binance/Trust Wallet.#Gate2025AnnualReportComing #ETFLeveragedTokenTradingCarnival $BTC $ETH $XRP