Trust Wallet Extension Bug Triggers $6M+ Crypto Losses, Forces Emergency Upgrade to Version 2.69
Key Takeaways: Trust Wallet confirmed a security incident affecting only Browser Extension version 2.68, prompting an urgent shutdown and upgrade. Reports from on-chain analysts link the flaw to over $6 million in stolen...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Key Takeaways:
- Trust Wallet confirmed a security incident affecting only Browser Extension version 2.68, prompting an urgent shutdown and upgrade.
- Reports from on-chain analysts link the flaw to over $6 million in stolen crypto across EVM chains, Solana, and Bitcoin.
- Mobile users and other extension versions remain unaffected, but the case raises broader concerns about wallet security and supply-chain risks in crypto.
Trust Wallet has issued an urgent warning after detecting a security incident tied to a specific version of its browser extension. The issue has triggered fund losses for some desktop users and forced the company to roll out an immediate fix.
Read More: Trust Wallet Launches New Loyalty Program for TWT, Targeting Mass Web3 Adoption
We’ve identified a security incident affecting Trust Wallet Browser Extension version 2.68 only. Users with Browser Extension 2.68 should disable and upgrade to 2.69.
Please refer to the official Chrome Webstore link here: https://t.co/V3vMq31TKb
Please note: Mobile-only users…
— Trust Wallet (@TrustWallet) December 25, 2025
Trust Wallet Confirms Security Incident in Browser ExtensionTrust Wallet disclosed that it identified a security incident affecting Trust Wallet Browser Extension version 2.68 only. The company urged all users running that version to stop using it immediately and upgrade to version 2.69, which is now live on the official Chrome Web Store.
According to Trust Wallet, the incident does not impact:
- Mobile-only users
- Desktop users running extension versions other than 2.68
The team emphasized that the wallet’s core infrastructure remains intact and that the problem is isolated to a single desktop extension release.
Trust Wallet also instructed users who have not yet upgraded to avoid opening the extension entirely until version 2.69 is installed. Customer support teams are already engaging with affected users to provide next steps.
Reports of Stolen Funds Spark Community AlarmThe revelation came as the crypto community began to take a closer note of the matter when independent on-chain researcher ZachXBT published a series of user loss stories where users had interacted with the Trust Wallet Chrome extension and had lost their money soon after.
Some of the affected users reported that assets were emptied as soon as they were authorizing transactions in the extension. The first estimates provided to blockchain researchers indicate that they can lose a sum up to $6 million, and hundreds of wallets can be affected.
Some of the reported funds moved across:
- Ethereum and other EVM-compatible chains
- Solana
- Bitcoin
Although Trust Wallet has not ascertained the amount lost, the time scales of the thefts, immediately after version 2.68 was published caused a strong suspicion of the update process.
How the Vulnerability May Have Been Exploited Possible Supply-Chain WeaknessEven though Trust Wallet has not published complete technical information, multiple security experts believe there is a supply-chain vulnerability added as part of the extension update operation. The malicious code may have been introduced or injected at the build or distribution stage, in this case, the attackers will be able to intercept sensitive wallet activities, like the signing of transactions or authorizing a session.
This theory is in line with user reports of transfer of funds anonymously to an unknown address after wallet authorization without incident. Trust Wallet has also established that it is under investigation and that it will publish more results after the analysis is over.
Read More: Trust Wallet Enables Direct Access to BNB Meme Rush, CZ’s Post Hits 650K Views
Official Response and Mandatory Upgrade StepsTrust Wallet provided a concise list of guidelines to ensure the security of the users and avoid additional losses. The company emphasized that prior to reopening the extension, these steps were to be undertaken.
Key actions include:
- Turning off the Trust Wallet extension in Chrome
- Enabling Developer Mode
- Forcing a manual update to version 2.69
- Verifying the installed version number before use
The company once again repeated that users must not download updates through other sites or links but only through the official Chrome Web Store, which the company said was their official store.
What This Incident Reveals About Wallet SecurityThe Trust Wallet case indicates a systematic danger in crypto: even non-custodial wallets may fall prey to attacks in case their distribution channels are compromised.
Browser extensions continue to be particularly appealing targets since they:
- Interact directly with private keys and signing requests
- Operate in environments exposed to phishing and malicious scripts
- Depend on frequent updates that expand the attack surface
And, in contrast to smart contract exploits, wallet level hacks, in many cases, do not even utilize on-chain protection, and losses cannot be reversed or traced.
This incident is among the larger wallet-related security incidents in recent years, as Trust Wallet has more than 220 million users all over the world. Although the extent may seem to be limited to one version, the reputational effects may reach wider.
The post Trust Wallet Extension Bug Triggers $6M+ Crypto Losses, Forces Emergency Upgrade to Version 2.69 appeared first on CryptoNinjas.
Why this matters
This blockchain story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on CryptoNinjasRelated market context
Trezor Data Breach Exposes 13,689 Users, Crypto Wallets Remain Safe From Attack
Key Takeaways: Through a leak in the software of its shipping partner ShipMonk, Trezor disclosed private information related to ap...
CyberWallet users have until Aug. 15 before crypto withdrawals become a smart contract recovery job
Crypto company Cyber is telling CyberWallet and Cyber Passkey Wallet users to move their assets ahead of an Aug. 15 shutdown that...
MyEtherWallet (MEW) Integrates Ondo Perps, Unlocking 24/7 Leveraged Trading for Onchain Equities, & ETFs.
Los Angeles, United States, August 13th, 2026, Chainwire MyEtherWallet (MEW), the world’s most intuitive digital wallet, today ann...
With violent crypto home invasions surging, a data breach exposing over 10,000 Trezor owners puts physical safety on the line
On Aug. 13, Trezor said a breach at the fulfillment provider ShipMonk exposed customer data for about 13,689 hardware wallet buyer...
Bitdeer Mines 2,694 BTC in Q2 as Revenue Jumps 47% to $228.8M Despite Losses
Key Takeaways: Bitdeer mined 2694 BTC in Q2, almost five times as much a year ago. The revenue rose by 47% to $228.8 million, and...
How a public crypto firm’s 4.3% AI gain hides millions in balance sheet losses
SRX Global reported a 4.3% EMJX gain that the company labels hypothetical, but its first post-acquisition disclosures still leave...