Crypto wallet provider Trust Wallet said it has identified a security incident affecting a specific version of its browser extension, with onchain sleuth ZachXBT estimating initial losses of more than $6 million.
The incident came to light after ZachXBT issued a community alert on Telegram on Thursday, warning that multiple Trust Wallet users had reported funds being drained from their wallet addresses over a short period of time. The investigator said the exact root cause remained unclear, but noted that the reports coincided with a recent update to the Trust Wallet Chrome browser extension.
Based on an initial list of theft addresses, ZachXBT reported that the attacker stole over $6 million from hundreds of users.
In a Thursday post on X, Trust Wallet confirmed that it had identified a security incident impacting Trust Wallet Browser Extension version 2.68, and urged users to immediately upgrade to version 2.69.
“Users with Browser Extension 2.68 should disable and upgrade to 2.69,” said Trust Wallet.
Trust Wallet noted that mobile-only users and all other browser extension versions are not impacted. The team also advised users who have not yet updated to Extension version 2.69 to avoid opening the browser extension until the upgrade is complete, warning that doing so could help prevent further issues.
“We understand how concerning this is and our team is actively working on the issue,” Trust Wallet added. “We’ll keep sharing updates as soon as possible.”
The Block has reached out to Trust Wallet for further information.
The incident comes amid a surge in high-profile exploits and phishing campaigns. Cryptocurrency theft totaled over $3.41 billion from January through early December, up from $3.38 billion last year, according to estimates from Chainalysis.
© 2025 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.