ZachXBT Reveals at Least $6 Million Stolen from Trust Wallet Users — Browser Extension Vulnerability at the Core

2025-12-26 04:55:06
Beginner
Quick Reads
Blockchain investigator ZachXBT has revealed that a vulnerability in the Trust Wallet browser extension has resulted in the theft of funds from hundreds of users, with losses surpassing $6 million. He further provided an analysis of the incident's specifics and the related security risks.


Image: https://x.com/DegenerateNews/status/2004283308059083250/photo/1

Incident Background and Latest Disclosures

Recently, on-chain investigator ZachXBT issued a critical security alert through social media and blockchain monitoring tools, revealing a vulnerability in the Trust Wallet browser extension. This flaw enabled the unauthorized transfer and theft of crypto assets from hundreds of users in a short time frame. Preliminary monitoring estimates place the total stolen amount at no less than $6 million.

The news spread rapidly across the crypto community, drawing significant attention from both users and industry professionals. ZachXBT’s monitoring data shows that several wallet addresses experienced suspicious outflows simultaneously. These funds were routed to unknown addresses or intermediary accounts and subsequently moved again.

Analysis of Losses and Impacted User Scale

Recent tracking data indicates that several hundred victims have been identified, with losses spanning multiple blockchains and assets—including, but not limited to, ETH, BTC, and SOL. The irregularities were not isolated to a single chain but were distributed across many wallet addresses, highlighting the event’s substantial scale.

In his latest update, ZachXBT emphasized that the sheer number of affected wallets makes it difficult to verify losses for each address. However, the preliminary estimate already exceeds $6 million, and this figure may rise as additional victims report their losses.

Stolen Funds Flow and Attack Patterns

Current analysis of fund movements suggests these thefts are tied to the browser extension vulnerability, especially when users import private keys or seed phrases, exposing themselves to significant risk. Multiple victims reported that their funds were drained rapidly to unknown accounts, indicating attackers had immediate access.

On-chain data shows that the attacks were highly automated, with stolen funds quickly dispersed and transferred across chains. This pattern differs from traditional hacks and more closely resembles a supply chain exploitation targeting hot wallet extension vulnerabilities.

Trust Wallet Official Response and User Actions


Image: https://x.com/TrustWallet/status/2004316503701958786

Trust Wallet has issued a security alert confirming that version 2.68 of the browser extension contains a critical vulnerability. Users are advised to immediately disable this version and upgrade to 2.69 or higher to mitigate risk. The official statement also clarified that the mobile app and other extension versions are not affected by this vulnerability.

Impacted users should take the following steps:

  • Immediately stop using the outdated extension and upgrade to the latest version \
  • If funds remain in your wallet, transfer them promptly to a cold wallet or another secure solution \
  • Report stolen assets through official support channels and retain all related on-chain evidence for investigation \

Security Lessons and Industry Impact

This incident highlights the ongoing challenge of balancing user experience and security in self-custody wallets. While browser extensions offer convenience, they also raise the risk of private key exposure and malicious activity. When users import mnemonic or seed phrases directly into extensions with vulnerabilities, assets can be drained within minutes.

Industry security experts recommend that users prioritize private key management, use hardware wallets or thoroughly audited security solutions, and avoid entering seed phrases into unverified clients or extensions. This event may also prompt wallet developers to enhance supply chain security assessments and code audits, strengthening overall ecosystem defenses.

Summary

ZachXBT’s latest disclosure of the Trust Wallet browser extension vulnerability underscores the critical need for crypto users to prioritize wallet security and remain vigilant about extension risks. In this incident, hundreds of users lost at least $6 million, prompting the community to re-examine self-custody wallet security. Users should act quickly to implement security measures, monitor official updates, and adopt safer asset management strategies to prevent similar incidents in the future.

Author: Max
Disclaimer
* The information is not intended to be and does not constitute financial advice or any other recommendation of any sort offered or endorsed by Gate.
* This article may not be reproduced, transmitted or copied without referencing Gate. Contravention is an infringement of Copyright Act and may be subject to legal action.

Share

Crypto Calendar
OM Token Göçü Sona Erdi
MANTRA Chain, kullanıcıları OM token'larını 15 Ocak'tan önce MANTRA Chain ana ağına taşımaları için bir hatırlatma yayınladı. Taşıma işlemi, $OM'nin yerel zincirine geçişi sırasında ekosistemdeki katılıma devam edilmesini sağlar.
OM
-4.32%
2026-01-14
CSM Fiyat Değişikliği
Hedera, Ocak 2026'dan itibaren KonsensüsSubmitMessage hizmeti için sabit USD ücretinin $0.0001'den $0.0008'e yükseleceğini duyurdu.
HBAR
-2.94%
2026-01-27
Vesting Kilidi Gecikti
Router Protocol, ROUTE tokeninin Hakediş kilidinin 6 aylık bir gecikme ile açılacağını duyurdu. Ekip, projenin Open Graph Architecture (OGA) ile stratejik uyum sağlamak ve uzun vadeli ivmeyi koruma hedefini gecikmenin başlıca nedenleri olarak belirtiyor. Bu süre zarfında yeni kilit açılımları gerçekleşmeyecek.
ROUTE
-1.03%
2026-01-28
Tokenların Kilidini Aç
Berachain BERA, 6 Şubat'ta yaklaşık 63,750,000 BERA tokenini serbest bırakacak ve bu, mevcut dolaşımdaki arzın yaklaşık %59.03'ünü oluşturacaktır.
BERA
-2.76%
2026-02-05
Tokenların Kilidini Aç
Wormhole, 3 Nisan'da 1.280.000.000 W token açacak ve bu, mevcut dolaşımdaki arzın yaklaşık %28,39'unu oluşturacak.
W
-7.32%
2026-04-02
sign up guide logosign up guide logo
sign up guide content imgsign up guide content img
Sign Up

Related Articles

Crypto Future Profit Calculator: How to Calculate Your Potential Gains
Beginner

Crypto Future Profit Calculator: How to Calculate Your Potential Gains

Crypto Future Profit Calculator helps traders estimate potential earnings from futures contracts by considering entry price, leverage, fees, and market movement.
2025-02-09 17:28:28
Crypto Futures Calculator: Easily Estimate Your Profits & Risks
Beginner

Crypto Futures Calculator: Easily Estimate Your Profits & Risks

Use a crypto futures calculator to estimate profits, risks, and liquidation prices. Optimize your trading strategy with accurate calculations.
2025-02-11 02:25:44
What is Oasis Network (ROSE)?
Beginner

What is Oasis Network (ROSE)?

The Oasis Network is driving the development of Web3 and AI through smart privacy technology. With its privacy protection, high scalability, and cross-chain interoperability, the Oasis Network is providing new possibilities for the future development of decentralized applications.
2025-05-20 09:41:15
The $50M Crypto Scam Nobody Is Talking About
Beginner

The $50M Crypto Scam Nobody Is Talking About

This investigation uncovers an elaborate over-the-counter (OTC) trading scheme that defrauded multiple institutional investors, revealing the mastermind "Source 1" and exposing critical vulnerabilities in crypto's gray-market dealings.
2025-06-26 11:12:31
What Are Crypto Options?
Beginner

What Are Crypto Options?

For many newcomers, options may seem a bit complex, but as long as you grasp the basic concepts, you can understand their value and potential in the entire encryption financial system.
2025-06-09 09:04:49
Gate Teams Up with Oracle Red Bull Racing to Launch the "Red Bull Racing Tour": Win Exclusive F1 Ticket & Share up to 5,000 GT in Prizes
Beginner

Gate Teams Up with Oracle Red Bull Racing to Launch the "Red Bull Racing Tour": Win Exclusive F1 Ticket & Share up to 5,000 GT in Prizes

On June 9, 2025, Gate, a global leading digital asset trading platform, officially launched the first phase of the “Red Bull Racing Tour”, a high-octane campaign that fuses the speed of F1 with the excitement of Web3. Combining trading competitions and interactive missions, this event gives users a chance to win an exclusive F1 Grand Prix ticket worth thousands of dollars, while competing to share a dynamic prize pool of up to 5,000 GT—bringing fans a triple win: watch, win, and earn.
2025-06-11 01:56:27