Skip to main content

Trust Wallet Suffers $7M Hack on Christmas Day, Binance's CZ Commits to Full User Reimbursement



On December 25, 2025, Trust Wallet Browser Extension users were targeted by a sophisticated hack that resulted in the theft of approximately $7 million worth of cryptocurrency.

The breach primarily targeted version 2.68 of the Chrome extension and was based on a hacker-developed backdoor that stole the private keys and mnemonic data of affected individuals, subsequently exporting the information to the hacker's server.

According to on-chain analyst ZachXBT, who reported that the attack affected hundreds of individuals and compiled a list of theft addresses spanning EVM chains, Bitcoin, and Solana.

The hacker behind the attack is said to have started preparations for the attack as early as December 8, 2025, and gained access to Trust Wallet's source code repository. On December 22, the malicious code was integrated into the update for the extension, which was then labeled with harmless-sounding “analytics” features.

The backdoor was then set to activate on Christmas Day, when the extraction of funds from affected wallets began. The malware code had warning signs, including connections to a dubious domain, "https://trustwallets.org," which experts believe should have been flagged by basic automated audits or manual checks.

A security researcher pointed out that this domain was rather fishy, pointing toward the lack of protection against calls from external URL addresses.

Trust Wallet identified the issue on December 25, 2025. In an official statement, the company announced, "We advise those affected to turn off their client v2.68 and update to v2.89 via the official Chrome Web Store."

The hack only affected desktop browser extension users, leaving mobile app users and other extension versions untouched.

Analysts from SlowMist and blockchain expert Anndy Lian believed that the attacker is well familiar with Trust Wallet's codebase, suspecting it's probably an insider job. Binance co-founder Changpeng Zhao (CZ) shared similar beliefs and assessments in a response on X, labeling it "most likely an inside attack."

The attack is a testament to the vulnerabilities in crypto wallets, where individual compromises represented 37% of stolen value in 2025, not counting major exchange breaches like Bybit's $1.4 billion loss in February 2025. It serves as another example of aggressive hacking tactics in the decentralized finance ecosystem.

Response, Reimbursement, and Broader Implications


Following the attack, CZ stated on December 26, 2025, that Trust Wallet would fully compensate the $7 million in losses.

This decision is in line with the user-protecting culture at Binance, as CZ stated that there were still investigations to determine how such an ‘evil’ version was submitted to the Chrome Store.

According to ZachXBT, he had been contacted directly by several victims with whom he compiled information on the scam addresses. While the quick reimbursement was seen as a positive step by some victims, other community members disagreed and criticized the decision over inconsistencies in handling similar attacks from 2023.

Trust Wallet's team is still investigating the attack, as CZ suggested potential insider collusion could be a reason to make internal changes within the organization.

Some community members are pushing for improved security measures, including compulsory code audits and advanced phishing detection in updates. Following the hack, there have been debates on the dangers of using browser extensions versus mobile wallets, with suggestions to switch to mobile wallets for better security.

https://www.cryptobreaking.com/trust-wallet-suffers-7m-hack/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Trust%20Wallet%20Suffers%20$7M%20Hack%20on%20Christmas%20Day,%20Binance's%20CZ%20Commits%20to%20Full%20User%20Reimbursement%20

Comments

Popular posts from this blog

Coinbase's x402 launches AI agents app store for payments

Coinbase-backed x402 has unveiled Agentic.market, a dedicated marketplace aimed at increasing the usefulness of AI agents by aggregating thousands of apps and services that agents can access without any API keys. The rollout positions the platform as a central hub for agents to discover, evaluate, and deploy capabilities across a standardized payments layer. Coinbase product lead Nick Prince described Agentic.market in a video posted on X as a storefront for discovering, comparing, and using x402 services. The marketplace is designed to give both humans and their AI agents access to a wide range of tools—from data feeds to consumer apps—without the friction of managing API credentials. A storefront for discovering, comparing, and using x402 services. Thousands of services. Zero API keys. Powered by x402. Prince added that the market offers a web interface for humans to browse and assess services, alongside a programming layer that lets AI agents autonomously search, filter, and integra...

Top Cryptocurrencies to Watch: BTC, ETH, BNB, XRP, Solana, Dogecoin & More

Market Analysis and Price Predictions for Key Cryptocurrencies Recent market dynamics reveal a cautious sentiment across the cryptocurrency landscape, with Bitcoin struggling to maintain levels above $90,000 and many major altcoins facing downward pressure. Indicators point toward reduced participation from both institutional and retail investors, raising concerns about a potential consolidation phase after notable gains earlier in the year. Bitcoin has fallen below $87,000, reflecting waning demand at higher price points. Institutional fund flows into BTC and ETH ETFs have turned negative, indicating a period of subdued market activity. Active addresses and Binance deposit/withdrawal activities are at annual lows, suggesting market indecision. Most leading altcoins are approaching support levels, with some poised for potential breakdowns. Tickers mentioned: Bitcoin, Ethereum, Binance Coin, XRP, Solana, Dogecoin, Cardano, Bitcoin Cash, Chainlink, Hyperliquid Sentiment: Neutral to Sli...

Analyst: Bitcoin can reclaim $100K without a new narrative

Bitcoin has stalled below the $100,000 threshold, marking a run of almost five months without a breakout above that level. As of the latest market close, BTC hovered around $78,250 after a February nadir of about $60,000, underscoring a slow, grinding recovery amid broader market dynamics. In parallel, tech markets—especially AI-focused equities—have captured the spotlight, with investors rotating capital away from crypto in search of different risk-reward profiles. Nvidia (NVDA), the leading AI stock by market cap, has gained about 5.08% since the start of the year, while Bitcoin has faced a roughly 10% dip over the same period, illustrating a diverging performance within risk assets. MN Trading Capital founder Michael van de Poppe suggested that Bitcoin may not require a fresh narrative to push back above $100,000. In a post on X, he asked what narrative would drive BTC to the milestone and concluded that “price moves upwards, and the narrative will create itself.” He continued that ...