The post Trust Wallet Begins Compensation for Victims of $7 Million Browser Extension Hack appeared on BitcoinEthereumNews.com. When a wallet provider says selfThe post Trust Wallet Begins Compensation for Victims of $7 Million Browser Extension Hack appeared on BitcoinEthereumNews.com. When a wallet provider says self

Trust Wallet Begins Compensation for Victims of $7 Million Browser Extension Hack

When a wallet provider says self custody, users expect the software layer to be airtight. That trust took a hit this week after Trust Wallet confirmed a malicious update to its Chrome browser extension led to the theft of roughly $7 million in digital assets. Now, the company says it is moving fast to make affected users whole.

Two days after discovering the breach, Trust Wallet announced it has launched a formal compensation process for victims impacted by the compromised version 2.68 of its Chrome extension.

How the Compensation Process Works

Trust Wallet has opened an official claims portal where affected users can submit details related to the attack. The form asks for basic identification information such as email address and country, along with technical evidence including compromised wallet addresses, attacker receiving addresses, and transaction hashes.

The company says every submission will be individually reviewed. According to Trust Wallet, this verification is essential to prevent errors, false claims, or further abuse of the situation.

In a public statement, the company said it is working around the clock to finalize compensation and ensure accuracy while maintaining security throughout the process.

What Was Stolen and Where the Funds Went

The breach resulted in losses across multiple blockchains, including Bitcoin, Ethereum, and Solana. Blockchain security firm PeckShield estimates that over $4 million of the stolen funds have already passed through centralized exchanges such as ChangeNOW, FixedFloat, and KuCoin.

As of the latest onchain data, roughly $2.8 million remains in wallets controlled by the attacker.

Adding reassurance for users, Changpeng Zhao, founder of Binance, confirmed publicly that all verified losses will be covered.

In a post on X, Zhao stated that approximately $7 million was affected and that Trust Wallet will fully compensate users, emphasizing that user funds remain SAFU.

How the Attack Happened

The incident first surfaced after onchain investigator ZachXBT warned on Telegram that multiple Trust Wallet users were reporting drained balances shortly after installing the December 24 update.

Trust Wallet’s internal investigation revealed that a leaked Chrome Web Store API key was used to publish the malicious extension update at 12:32 p.m. UTC on December 24. This allowed the attackers to bypass the company’s internal release controls.

Security firm SlowMist later identified the malicious code, which leveraged a modified open source analytics library to harvest wallet seed phrases. Once compromised, attackers could quickly drain funds without further user interaction.

Who Was Affected and Who Was Not

Only users of the Chrome extension running version 2.68 were impacted. Trust Wallet pushed a patched release, version 2.69, on December 25. According to CEO Eowyn Chen, users who logged into the extension before December 26 at 11 a.m. UTC were potentially exposed.

Mobile app users and those using other browser versions of the extension were not affected. The Chrome extension alone has close to one million users, according to its Web Store listing.

Warning Against Fake Compensation Scams

Trust Wallet is also urging users to stay alert. In the aftermath of the breach, fake compensation forms and impersonation scams have already begun circulating. The company stressed that claims should only be submitted through its official support portal and warned users not to share recovery phrases or private keys under any circumstances.

What This Means Going Forward

This incident is a reminder that even well known wallet providers remain exposed to supply chain risks, especially through browser extensions. While Trust Wallet’s decision to fully compensate users helps restore confidence, the breach underscores how a single leaked credential can cascade into millions in losses.

For users, the lesson is simple but uncomfortable. Updates matter, verification matters, and browser extensions remain one of the softest targets in the crypto ecosystem.

Source: https://cryptoticker.io/en/trust-wallet-begins-compensation-for-victims-of-dollar7-million-browser-extension-hack/

Market Opportunity
Intuition Logo
Intuition Price(TRUST)
$0.1095
$0.1095$0.1095
-2.31%
USD
Intuition (TRUST) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Trump’s Tactics Reignite Crypto’s SEC Dialogue

Trump’s Tactics Reignite Crypto’s SEC Dialogue

Prior to Donald Trump’s influence, cryptocurrency companies primarily encountered the Securities and Exchange Commission (SEC) through legal battles. Under the leadership of former SEC Chair Gary Gensler, the lack of clear guidance from the commission bred a climate of apprehension, leaving businesses in a perplexed state.Continue Reading:Trump’s Tactics Reignite Crypto’s SEC Dialogue
Share
Coinstats2025/09/18 04:08
UK Regulator Proposes New Crypto Rules to Protect Consumers

UK Regulator Proposes New Crypto Rules to Protect Consumers

UK’s FCA proposes crypto rules to boost transparency, protect consumers, and balance innovation with regulation; consultation open until 2026. The United Kingdom has taken a new step toward regulating the fast-growing crypto sector. On Wednesday, the Financial Conduct Authority (FCA) released a consultation paper that sets out how the existing financial rules should apply to […] The post UK Regulator Proposes New Crypto Rules to Protect Consumers appeared first on Live Bitcoin News.
Share
LiveBitcoinNews2025/09/18 15:30
FCA, crackdown on crypto

FCA, crackdown on crypto

The post FCA, crackdown on crypto appeared on BitcoinEthereumNews.com. The regulation of cryptocurrencies in the United Kingdom enters a decisive phase. The Financial Conduct Authority (FCA) has initiated a consultation to set minimum standards on transparency, consumer protection, and digital custody, in order to strengthen market confidence and ensure safer operations for exchanges, wallets, and crypto service providers. The consultation was published on May 2, 2025, and opened a public discussion on operational responsibilities and safeguarding requirements for digital assets (CoinDesk). The goal is to make the rules clearer without hindering the sector’s evolution. According to the data collected by our regulatory monitoring team, in the first weeks following the publication, the feedback received from professionals and operators focused mainly on custody, incident reporting, and insurance requirements. Industry analysts note that many responses require technical clarifications on multi-sig, asset segregation, and recovery protocols, as well as proposals to scale obligations based on the size of the operator. FCA Consultation: What’s on the Table The consultation document clarifies how to apply rules inspired by traditional finance to the crypto perimeter, balancing innovation, market integrity, and user protection. In this context, the goal is to introduce minimum standards for all firms under the supervision of the FCA, an essential step for a more transparent and secure sector, with measurable benefits for users. The proposed pillars Obligations towards consumers: assessment on the extension of the Consumer Duty – a requirement that mandates companies to provide “good outcomes” – to crypto services, with outcomes for users that are traceable and verifiable. Operational resilience: introduction of continuity requirements, incident response plans, and periodic testing to ensure the operational stability of platforms even in adverse scenarios. Financial Crime Prevention: strengthening AML/CFT measures through more stringent transaction monitoring and structured counterpart checks. Custody and safeguarding: definition of operational methods for the segregation of client assets, secure…
Share
BitcoinEthereumNews2025/09/18 05:40