Trust Wallet suffered a major security vulnerability! Do not import mnemonic phrases and upgrade to 2.69 as soon as possible, at least $6 million has been stolen

ðŸ‘Ī transfer001@Penny 📅 2026-04-04 14:46:05

Trust Wallet confirmed this morning that browser extension version 2.68 has a fatal vulnerability, which will cause on-chain losses and users must immediately upgrade to 2.69.
(Preliminary summary: CZ retweet detonated the Trust Wallet token TWT soaring by 40%; pointing to the era of 1 billion Web3 users)
(Background supplement: What is the "Wallet as a Service" WaaS launched by Trust Wallet, analysis of advantages and disadvantages, can it become mainstream in the future? )

Cryptocurrency wallet Trust Wallet A major security alert was issued at around 6 a.m. today (26th), confirming that version 2.68 of its browser extension has a serious vulnerability, leading to the outflow of user assets. On-chain detective ZachXBT tracking shows that the number of victims has reached hundreds, and the loss was first estimated at about $6 million.

For users who haven't already updated to Extension version 2.69, please do not open the Browser Extension until you have updated. This may help to ensure the security of your wallet and prevent further issues.

— Trust Wallet (@TrustWallet) December 26, 2025

Vulnerability details and loss scale

The official notice pointed out that the affected objects are users who have installed version 2.68 extensions on the mobile version. Trust Wallet emphasized in the announcement:

"We have released a patch for version 2.69, please all browser extension users to upgrade immediately."

If you are also a Trust Wallet user and have installed version 2.68, "Please do not import the mnemonic phrase" and it is best to upgrade through the official link of the Chrome Online App Store. Mnemonic phrases imported in a contaminated environment are best treated as leaks, and it is best to create a new wallet and migrate the balance (it is recommended that assets be transferred to other brand wallets before the official problem is completely solved).

The malicious script 4482.js sneaked in through official updates

It is understood that the attacker inserted a file named 4482.js during the packaging process and claimed to be used for "Analytics". When it detects that the user enters the mnemonic phrase, it sends the data to the registered domain metrics-trustwallet.com, and then uses automated scripts to quickly withdraw assets from the EVM compatible chain, Bitcoin and Solana.

At present, individual victims have reported losses ranging from tens of thousands to hundreds of thousands of dollars. We will continue to track the official next step for potential compensation.

Labelïžš
shareïžš
FB X YT IG
transfer001@Penny

transfer001@Penny

Blockchain and cryptoassets editor, focusing onpolicyDomain content analysis and insights

Comment (10)

āđ€āļĢāļēāļ­āļēāļˆāļ›āļĢāļ°āđ€āļĄāļīāļ™āļœāļĨāļāļĢāļ°āļ—āļšāļĢāļ°āļĒāļ°āļŠāļąāđ‰āļ™āļ‚āļ­āļ‡āđ€āļ—āļ„āđ‚āļ™āđ‚āļĨāļĒāļĩāļŠāļđāļ‡āđ€āļāļīāļ™āđ„āļ› āđāļĨāļ°āļ›āļĢāļ°āđ€āļĄāļīāļ™āļœāļĨāļāļĢāļ°āļ—āļšāļĢāļ°āļĒāļ°āļĒāļēāļ§āļ•āđˆāļģāđ„āļ›
āļ•āļĨāļēāļ”āļĒāļąāļ‡āļ­āļĒāļđāđˆāđƒāļ™āļŠāđˆāļ§āļ‡āļœāļąāļ™āļœāļ§āļ™
āļĄāļļāļĄāļĄāļ­āļ‡āļ™āļąāđ‰āļ™āļĨāļķāļāļ‹āļķāđ‰āļ‡āļĄāļēāļāđāļĨāļ°āļ­āļ™āļēāļ„āļ•āļ‚āļ­āļ‡āļšāļĨāđ‡āļ­āļāđ€āļŠāļ™āļāđ‡āļ„āļļāđ‰āļĄāļ„āđˆāļēāļ—āļĩāđˆāļˆāļ°āļĢāļ­āļ„āļ­āļĒ
āļĄāļĩāļāļēāļĢāļžāļđāļ”āļ„āļļāļĒāļāļąāļ™āļ–āļķāļ‡āļāļēāļĢāļ›āļĢāļ°āļĒāļļāļāļ•āđŒāđƒāļŠāđ‰āļ„āļļāļ“āļŠāļĄāļšāļąāļ•āļīāļ›āđ‰āļ­āļ‡āļāļąāļ™āļāļēāļĢāļ‡āļąāļ”āđāļ‡āļ°āđƒāļ™āļāļēāļĢāļ•āļĢāļ§āļˆāļŠāļ­āļšāļĒāđ‰āļ­āļ™āļāļĨāļąāļš
āļ‚āđ‰āļ­āđ„āļ”āđ‰āđ€āļ›āļĢāļĩāļĒāļšāļ”āđ‰āļēāļ™āļ„āļ§āļēāļĄāđ‚āļ›āļĢāđˆāļ‡āđƒāļŠāļ‚āļ­āļ‡āļšāļĨāđ‡āļ­āļ„āđ€āļŠāļ™āđ„āļ”āđ‰āļĢāļąāļšāļāļēāļĢāđāļŠāļ”āļ‡āđƒāļŦāđ‰āđ€āļŦāđ‡āļ™āļ­āļĒāđˆāļēāļ‡āđ€āļ•āđ‡āļĄāļ—āļĩāđˆāđāļĨāđ‰āļ§
āđƒāļ™āļ­āļ™āļēāļ„āļ•āļˆāļ°āļĄāļĩāļ„āļ§āļēāļĄāļāđ‰āļēāļ§āļŦāļ™āđ‰āļēāļ—āļēāļ‡āđ€āļ—āļ„āđ‚āļ™āđ‚āļĨāļĒāļĩāļĄāļēāļāļ‚āļķāđ‰āļ™
āļāļēāļĢāļāđˆāļ­āļŠāļĢāđ‰āļēāļ‡āđ€āļŠāļīāļ‡āļ™āļīāđ€āļ§āļĻāļ‚āļ­āļ‡āļ™āļąāļāļžāļąāļ’āļ™āļēāļ–āļ·āļ­āđ€āļ›āđ‡āļ™āļĢāļēāļāļāļēāļ™āļ—āļĩāđˆāļŠāļģāļ„āļąāļ āļāļĨāđˆāļēāļ§āļāļąāļ™āļ§āđˆāļē
āļĄāļĩāļ„āļ§āļēāļĄāļ•āļķāļ‡āđ€āļ„āļĢāļĩāļĒāļ”āđ‚āļ”āļĒāļ˜āļĢāļĢāļĄāļŠāļēāļ•āļīāļĢāļ°āļŦāļ§āđˆāļēāļ‡āđ‚āļ­āđ€āļžāđˆāļ™āļ‹āļ­āļĢāđŒāļŠāđāļĨāļ°āļāļēāļĢāļ„āđ‰āļē
āļĒāļąāļ‡āļ„āļ‡āļĄāļĩāđ‚āļ­āļāļēāļŠāļŠāļģāļŦāļĢāļąāļšāļ™āļ§āļąāļ•āļāļĢāļĢāļĄāđƒāļ™āļ•āļĨāļēāļ”
āļ 78days ago
āļ„āļ§āļēāļĄāļŠāļąāļĄāļžāļąāļ™āļ˜āđŒāļĢāļ°āļŦāļ§āđˆāļēāļ‡ Web3 āđāļĨāļ° blockchain āļ„āļ·āļ­āļ­āļ°āđ„āļĢ?

Add comment

Popular content

Dunamu āļšāļĢāļīāļĐāļąāļ—āđāļĄāđˆāļ‚āļ­āļ‡ Upbit āļ–āļđāļāļ›āļĢāļąāļšāđ€āļ›āđ‡āļ™āđ€āļ‡āļīāļ™ 35.2 āļžāļąāļ™āļĨāđ‰āļēāļ™āļ§āļ­āļ™ āļ‹āļķāđˆāļ‡āļ–āļ·āļ­āđ€āļ›āđ‡āļ™āļ„āđˆāļēāļ›āļĢāļąāļšāļ—āļĩāđˆāđāļžāļ‡āļ—āļĩāđˆāļŠāļļāļ”āđƒāļ™āļ›āļĢāļ°āļ§āļąāļ•āļīāļĻāļēāļŠāļ•āļĢāđŒāļ‚āļ­āļ‡āļŠāļāļļāļĨāđ€āļ‡āļīāļ™āļ”āļīāļˆāļīāļ—āļąāļĨāļ‚āļ­āļ‡āđ€āļāļēāļŦāļĨāļĩ

Dunamu āļšāļĢāļīāļĐāļąāļ—āđāļĄāđˆāļ‚āļ­āļ‡ Upbit āļ–āļđāļāļ›āļĢāļąāļšāđ€āļ›āđ‡āļ™āđ€āļ‡āļīāļ™ 35.2 āļžāļąāļ™āļĨāđ‰āļēāļ™āļ§āļ­āļ™ āļ‹āļķāđˆāļ‡āļ–āļ·āļ­āđ€āļ›āđ‡āļ™āļ„āđˆāļēāļ›āļĢāļąāļšāļ—āļĩāđˆāđāļžāļ‡āļ—āļĩāđˆāļŠāļļāļ”āđƒāļ™āļ›āļĢāļ°āļ§āļąāļ•āļīāļĻāļēāļŠāļ•āļĢāđŒāļ‚āļ­āļ‡āļŠāļāļļāļĨāđ€āļ‡āļīāļ™āļ”āļīāļˆāļīāļ—āļąāļĨāļ‚āļ­āļ‡āđ€āļāļēāļŦāļĨāļĩ

2026-04-04
āļžāļīāļžāļēāļāļĐāļēāļˆāļģāļ„āļļāļāđ€āļžāļĩāļĒāļ‡ 3 āļ›āļĩ! āļžāđˆāļ­āļ‚āļ­āļ‡āļ—āļ™āļēāļĒāļ„āļ§āļēāļĄāļ§āļąāļĒ 31 āļ›āļĩāđ€āļ›āđ‡āļ™āļœāļđāđ‰āļžāļīāļžāļēāļāļĐāļē āđāļĨāļ°āđ€āļ‚āļēāļĢāđˆāļ§āļĄāļĄāļ·āļ­āļāļąāļšāđ€āļĻāļĢāļĐāļāļĩāļĢāļļāđˆāļ™āļ—āļĩāđˆāļŠāļ­āļ‡āļ—āļĩāđˆāļŠāļąāđˆāļ§āļĢāđ‰āļēāļĒāđ€āļžāļ·āđˆāļ­

āļžāļīāļžāļēāļāļĐāļēāļˆāļģāļ„āļļāļāđ€āļžāļĩāļĒāļ‡ 3 āļ›āļĩ! āļžāđˆāļ­āļ‚āļ­āļ‡āļ—āļ™āļēāļĒāļ„āļ§āļēāļĄāļ§āļąāļĒ 31 āļ›āļĩāđ€āļ›āđ‡āļ™āļœāļđāđ‰āļžāļīāļžāļēāļāļĐāļē āđāļĨāļ°āđ€āļ‚āļēāļĢāđˆāļ§āļĄāļĄāļ·āļ­āļāļąāļšāđ€āļĻāļĢāļĐāļāļĩāļĢāļļāđˆāļ™āļ—āļĩāđˆāļŠāļ­āļ‡āļ—āļĩāđˆāļŠāļąāđˆāļ§āļĢāđ‰āļēāļĒāđ€āļžāļ·āđˆāļ­ "āļ‰āđ‰āļ­āđ‚āļāļ‡āđ€āļ‡āļīāļ™ 400 āļĨāđ‰āļēāļ™" āđāļĨāļ°āđ€āļ‰āļĨāļīāļĄāļ‰āļĨāļ­āļ‡āļ„āļ§āļēāļĄāļŠāļģāđ€āļĢāđ‡āļˆāļ”āđ‰āļ§āļĒāļāļēāļĢāļāļīāļ™āļĒāļēāđāļĨāļ°āļˆāļąāļ”āļ›āļēāļĢāđŒāļ•āļĩāđ‰āđ€āļ‹āđ‡āļāļŠāđŒ

2026-04-04
āļŦāđ‰āļ­āļ‡āđ€āļĢāļĩāļĒāļ™āļāļēāļĢāđ€āļ‡āļīāļ™

āļŦāđ‰āļ­āļ‡āđ€āļĢāļĩāļĒāļ™āļāļēāļĢāđ€āļ‡āļīāļ™" "Digital New Taiwan Dollar" āļ‚āļ­āļ‡āļ˜āļ™āļēāļ„āļēāļĢāļāļĨāļēāļ‡āļˆāļ°āļ–āļđāļāļ—āļ”āļĨāļ­āļ‡āđƒāļŠāđ‰āđƒāļ™āđ€āļ”āļ·āļ­āļ™āļāļĢāļāļŽāļēāļ„āļĄ! āļ—āļģāļ„āļ§āļēāļĄāđ€āļ‚āđ‰āļēāđƒāļˆāļ§āđˆāļē CBDC āļ„āļ·āļ­āļ­āļ°āđ„āļĢāđāļĨāļ°āđƒāļŠāđ‰āļ‡āļēāļ™āļ­āļĒāđˆāļēāļ‡āđ„āļĢ

2026-04-04
āļ„āļ“āļ°āļāļĢāļĢāļĄāļāļēāļĢāļāļģāļāļąāļšāļŦāļĨāļąāļāļ—āļĢāļąāļžāļĒāđŒāđāļĨāļ°āļŠāļąāļāļāļēāļ‹āļ·āđ‰āļ­āļ‚āļēāļĒāļĨāđˆāļ§āļ‡āļŦāļ™āđ‰āļēāļ‚āļ­āļ‡āļŪāđˆāļ­āļ‡āļāļ‡āđ€āļ•āļ·āļ­āļ™: FoFund, Fo Coin āđāļĨāļ° Taohuayuan NFT āđ€āļ›āđ‡āļ™

āļ„āļ“āļ°āļāļĢāļĢāļĄāļāļēāļĢāļāļģāļāļąāļšāļŦāļĨāļąāļāļ—āļĢāļąāļžāļĒāđŒāđāļĨāļ°āļŠāļąāļāļāļēāļ‹āļ·āđ‰āļ­āļ‚āļēāļĒāļĨāđˆāļ§āļ‡āļŦāļ™āđ‰āļēāļ‚āļ­āļ‡āļŪāđˆāļ­āļ‡āļāļ‡āđ€āļ•āļ·āļ­āļ™: FoFund, Fo Coin āđāļĨāļ° Taohuayuan NFT āđ€āļ›āđ‡āļ™ "āļœāļĨāļīāļ•āļ āļąāļ“āļ‘āđŒāļ—āļĩāđˆāļ™āđˆāļēāļŠāļ‡āļŠāļąāļĒ" āđāļĨāļ°āļ™āļąāļāļĨāļ‡āļ—āļļāļ™āļ•āđ‰āļ­āļ‡āļĢāļ°āļĄāļąāļ”āļĢāļ°āļ§āļąāļ‡

2026-04-04
āđ€āļ„āļŠāđāļĢāļāđƒāļ™āđ„āļ•āđ‰āļŦāļ§āļąāļ™! Commonwealth Bank āļĢāđˆāļ§āļĄāļĄāļ·āļ­āļāļąāļš MaiCoin āđ€āļ›āļīāļ”āļ•āļąāļ§

āđ€āļ„āļŠāđāļĢāļāđƒāļ™āđ„āļ•āđ‰āļŦāļ§āļąāļ™! Commonwealth Bank āļĢāđˆāļ§āļĄāļĄāļ·āļ­āļāļąāļš MaiCoin āđ€āļ›āļīāļ”āļ•āļąāļ§ "āļ˜āļļāļĢāļāļīāļˆāļ™āļģāļĢāđˆāļ­āļ‡āļāļēāļĢāļ”āļđāđāļĨāļŠāļīāļ™āļ—āļĢāļąāļžāļĒāđŒāđ€āļŠāļĄāļ·āļ­āļ™" āļ­āļĒāđˆāļēāļ‡āđ€āļ›āđ‡āļ™āļ—āļēāļ‡āļāļēāļĢ

2026-04-04
Youtube āļ›āļĢāļ°āļāļēāļĻāļ§āđˆāļē

Youtube āļ›āļĢāļ°āļāļēāļĻāļ§āđˆāļē "āļŦāđ‰āļēāļĄāļāļēāļĢāđ‚āļ›āļĢāđ‚āļĄāļ•āđ‚āļ—āđ€āļ„āđ‡āļ™āļ—āļĩāđˆāđ€āļāļĩāđˆāļĒāļ§āļ‚āđ‰āļ­āļ‡āļāļąāļšāļāļēāļĢāļžāļ™āļąāļ™āđāļĨāļ° NFT" āļ—āļģāđƒāļŦāđ‰āđ€āļāļīāļ”āļāļēāļĢāļ›āļĢāļ°āļ—āđ‰āļ§āļ‡āļˆāļēāļāļœāļđāđ‰āļĄāļĩāļ­āļīāļ—āļ˜āļīāļžāļĨāļ”āđ‰āļēāļ™ crypto: āļžāļ§āļāđ€āļ‚āļēāļˆāļ°āđ€āļ›āļĨāļĩāđˆāļĒāļ™āļ­āļēāļŠāļĩāļžāļŦāļĢāļ·āļ­āđ„āļĄāđˆ?

2026-04-04

Related sections

Popular content

āđāļžāļĨāļ•āļŸāļ­āļĢāđŒāļĄāļžāļĨāļąāļ‡āļ‡āļēāļ™ trx āļžāļĨāļąāļ‡āļ‡āļēāļ™āđ€āļ„āļĢāļ·āļ­āļ‚āđˆāļēāļĒāļ•āļĢāļ­āļ™ āļāļēāļĢāļ‚āļēāļĒāļžāļĨāļąāļ‡āļ‡āļēāļ™āļ‚āļ­āļ‡ TRON āļ‹āļ·āđ‰āļ­ TRX āļāļēāļĢāđāļĨāļāđ€āļ›āļĨāļĩāđˆāļĒāļ™āļžāļĨāļąāļ‡āļ‡āļēāļ™āļ‚āļ­āļ‡ TRON āļ—āļĩāļ­āļēāļĢāđŒāđ€āļ­āđ‡āļāļ‹āđŒ āđ€āļ­āđ‡āļ™āđ€āļ™āļ­āļĢāđŒāļˆāļĩ āđ€āļ‹āļ­āļĢāđŒāļ§āļīāļŠ āļšāļĢāļīāļāļēāļĢāļžāļĨāļąāļ‡āļ‡āļēāļ™āļ•āļĢāļ­āļ™ āļŠāļģāļ™āļąāļāļ‡āļēāļ™āļžāļĨāļąāļ‡āļ‡āļēāļ™āļ•āļĢāļ­āļ™ āļŠāļąāļāļāļēāđ€āļŠāđˆāļēāļžāļĨāļąāļ‡āļ‡āļēāļ™ TRX āļāļēāļĢāđ€āļŠāđˆāļēāļžāļĨāļąāļ‡āļ‡āļēāļ™āļ‚āļ­āļ‡ TRON āļāļēāļĢāđāļĨāļāđ€āļ›āļĨāļĩāđˆāļĒāļ™āļžāļĨāļąāļ‡āļ‡āļēāļ™ TRX āļāļēāļĢāļ‚āļēāļĒāļžāļĨāļąāļ‡āļ‡āļēāļ™ TRX TRX āļĨāļĩāļŠāļ‹āļīāđˆāļ‡āļžāļĨāļąāļ‡āļ‡āļēāļ™ āļŦāļļāđˆāļ™āļĒāļ™āļ•āđŒāļĨāļīāļŠāļ‹āļīāđˆāļ‡ āđ‚āļ­āļ™ USDT āļŸāļĢāļĩ āļ„āđˆāļēāļ˜āļĢāļĢāļĄāđ€āļ™āļĩāļĒāļĄāļāļēāļĢāđ‚āļ­āļ™ USDT āļŸāļĢāļĩ āļšāļđāļĢāļ“āļēāļāļēāļĢāđāļžāļĨāļ•āļŸāļ­āļĢāđŒāļĄāļžāļĨāļąāļ‡āļ‡āļēāļ™ āļžāļĨāļąāļ‡āļ‡āļēāļ™āļ•āļĢāļ­āļ™āļŠāļģāļŦāļĢāļąāļšāļāļēāļĢāļ–āđˆāļēāļĒāđ‚āļ­āļ™ āļ•āļĨāļēāļ”āļžāļĨāļąāļ‡āļ‡āļēāļ™ TRX TRX āļžāļĨāļąāļ‡āļ‡āļēāļ™āđƒāļŦāđ‰āđ€āļŠāđˆāļē