Trust Wallet has initiated a formal compensation process for users affected by a recent security breach involving its Chrome browser extension. The incident, which saw approximately $7 million in digital assets stolen, was caused by malicious code embedded in version 2.68 of the extension. The company has pledged to reimburse all impacted users and is working diligently to verify claims.
Key Takeaways
-
Trust Wallet is compensating victims of a $7 million browser extension hack.
-
The breach affected version 2.68 of the Chrome extension due to malicious code.
-
Approximately $7 million in Bitcoin, Ether, and Solana assets were stolen.
-
Binance founder Changpeng Zhao confirmed that Trust Wallet will cover all losses.
-
Mobile app users and other browser extension versions were not impacted.
The Security Incident Unveiled
The security vulnerability came to light on Christmas Day when users reported funds being drained shortly after updating the Trust Wallet Chrome extension on December 24th. An investigation by Trust Wallet revealed that a leaked Chrome Web Store API key was used to publish the compromised version, bypassing the usual internal release checks. The malicious code, designed to harvest wallet seed phrases, was embedded within a modified analytics library.
Compensation Process Underway
Trust Wallet has established an official support form on its portal for affected users to submit claims. The process requires victims to provide details such as their email address, country of residence, compromised wallet addresses, the attacker's receiving addresses, and relevant transaction hashes. The company is working around the clock to verify each case meticulously to ensure accuracy and security in the compensation process.
Financial Impact and Binance's Assurance
An estimated $7 million in digital assets, including Bitcoin, Ether, and Solana, were stolen across multiple blockchains. Blockchain security firms noted that a significant portion of the stolen funds was moved through centralized exchanges, complicating tracing efforts. However, Changpeng Zhao, founder of Binance (which acquired Trust Wallet in 2018), publicly assured that the company would cover all affected losses, stating that user funds are "SAFU" (Secure Asset Fund for Users).
Scope of the Breach
It is important to note that the security incident was limited to version 2.68 of the Trust Wallet Chrome browser extension. Users of the mobile application and those running other versions of the browser extension were not affected. Trust Wallet has since released version 2.69 with a fix for the vulnerability.
Sources
-
Trust Wallet launches compensation process for $7 million browser extension hack victims, The Block.
-
Hack: Trust Wallet Begins Compensation Process After Hack, Live Bitcoin News.
This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.
