Tag: Trust Wallet

  • The Worm in the Code: How the Shai-Hulud npm Attack Hijacked Trust Wallet

    The Worm in the Code: How the Shai-Hulud npm Attack Hijacked Trust Wallet

    A large-scale supply chain compromise known as Shai-Hulud has been linked to the recent theft of approximately USD 8.5 million in cryptocurrency from more than 2,500 Trust Wallet accounts. The company’s team has concluded that the December incident was not an isolated event, but rather a continuation of a sweeping attack on the npm ecosystem…

  • How a Hidden Backdoor Drained $7M from Trust Wallet

    How a Hidden Backdoor Drained $7M from Trust Wallet

    A dangerous vulnerability has been discovered in the Trust Wallet browser extension, potentially allowing attackers to steal users’ cryptocurrency. The issue affected version 2.68, and the wallet’s team officially urged everyone who had installed it to immediately disable the extension and update to version 2.69. The first complaints were reported by researcher ZachXBT, who wrote…

  • The Christmas Drain: How a Backdoor in Trust Wallet v2.68 Stole $7M

    The Christmas Drain: How a Backdoor in Trust Wallet v2.68 Stole $7M

    Blockchain investigator ZachXBT reported on December 25 that, over the preceding hours, numerous Trust Wallet users had experienced unauthorized withdrawals. Affected individuals claimed their assets were drained from their wallets without any form of confirmation. ZachXBT noted that complaints began surfacing shortly after the release of an update to the browser extension. Preliminary estimates, based…

  • Firefox Crypto Wallet Alert: Over 40 Malicious Extensions Found Stealing Seed Phrases & Funds

    Firefox Crypto Wallet Alert: Over 40 Malicious Extensions Found Stealing Seed Phrases & Funds

    Experts at Koi Security have identified over 40 malicious extensions for the Mozilla Firefox browser, specifically crafted to steal data from cryptocurrency wallets. These add-ons pose a significant threat to the security of users’ digital assets. The attackers disguised their malware-laden extensions as official tools of widely used crypto wallets. Among the impersonated services were…