What Trust Wallet Users Should Know About Recent Security Issues and Compensation Plans

robot
Abstract generation in progress

A significant security incident involving Trust Wallet Browser Extension v2.68 came to light after an API key compromised between December 24 and 26, 2025, allowed malicious code to be injected into the system. The root cause traces back to the Sha1-Hulud supply chain attack from November, when attackers exploited leaked GitHub credentials to gain unauthorized access to the Chrome Web Store API. This vulnerability resulted in direct impact on 2,520 wallet addresses, with approximately $8.5 million in digital assets stolen from affected users.

Trust Wallet’s Response and Compensation Initiative

Rather than deflecting responsibility, Trust Wallet has taken the proactive step to compensate impacted users. The company is currently finalizing its verification process to confirm ownership and authorize reimbursements. Security experts note that this approach stands in contrast to how many platforms have historically handled breaches, making Trust Wallet’s commitment noteworthy for affected users.

The team has initiated outreach to victims who formally reported the incident through official channels. To date, the platform has received over 5,000 claims, and each submission is undergoing individual review to ensure accurate compensation amounts and legitimate ownership verification. Users seeking compensation must transfer their remaining assets to secure new wallets immediately and file their claims using the official submission form provided by Trust Wallet.

Technical Resolution and Next Steps

Trust Wallet released Browser Extension v2.69 with comprehensive security patches and has revoked the compromised publishing permissions and API credentials. This two-pronged approach—both addressing the immediate vulnerability and preventing future unauthorized access—demonstrates efforts to restore user confidence in the platform’s security infrastructure.

For users who experienced losses, the critical actions are clear: move remaining assets to new wallets without delay and submit compensation claims through Trust Wallet’s official portal. The company’s transparent handling of the incident, including detailed explanations of both the breach origins and remediation steps, suggests that affected users who follow proper procedures can expect systematic review of their claims.

This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
  • Pin

Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)