A crypto hacker in the dark
Trust Wallet Users Report Asset Drains – What Happened?
In Brief
- • Trust Wallet users reported sudden asset drains on December 25th.
- • A recent update may have included hidden code that exfiltrated wallet data or seed phrases.
- • The incident has renewed concerns about Chrome extension security.
Crypto wallet hacks are part of the many ways that funds can be stolen from crypto holders, and a popular wallet may be the next victim. Trust Wallet users have reported recent draining of assets from their wallets in what appears to be an attack.
An X user shared the information today December 25th, at what time funds were being drained from the wallet for many users. No clear cause has been found, but a Chrome extension is being suspected due to a new update it added yesterday. There’s no figure of how much has been lost yet as investigation is still ongoing.
Chrome Extensions Becoming Tool for Fraud
Crypto fraudsters use different means to steal assets from users these days, one of which is the use of Chrome extensions, which is becoming increasingly popular. Criminals have either created fake extensions or hijacked them to steal crypto assets either directly or indirectly, something that has become a major concern.
Just recently, a new Chrome extension wallet was discovered which was used to steal Ethereum seed phrases. The fake wallet extension named Safery: Ethereum Wallet looked like any legitimate Ethereum wallet but experts warned of a back door through which bad actors could steal seed phrases.
While Trust Wallet has been a trusted wallet for many years as the name implies, the new extension update released by developers could have been an avenue through which hackers or other fraudsters may be stealing from users. Further information on the incident shows a possible seed phrase stealing, similar to the Ethereum wallet case.
An expert gave a breakdown in which he said the recent update added hidden code that quietly sends wallet data outside while it pretends to be analytics. The code tracks wallet activity and triggers when a seed phrase is imported. The data was sent to a domain called metrics-trustwallet[.]com which was registered days ago and is now down.
Chrome Needs to Step Up Security
The recurring issues with Chrome extensions needs urgent attention as such incidents can give the browser a bad reputation. Although it has been updated a few times recently, such updates did not tackle the issue of security, just introducing new features and fixes for errors.
Interestingly, Chrome remains a preferred choice for internet browsing above even ChatGPT, but this popularity may not last if the security of crypto assets cannot be guaranteed on the extensions.
More Must-Reads:
How do you rate this article?
Subscribe to our YouTube channel for crypto market insights and educational videos.
Join our Socials
Briefly, clearly and without noise – get the most important crypto news and market insights first.
Most Read Today
Peter Schiff Warns of a U.S. Dollar Collapse Far Worse Than 2008
2Dubai Insurance Launches Crypto Wallet for Premium Payments & Claims
3XRP Whales Buy The Dip While Price Goes Nowhere
4Samsung crushes Apple with over 700 million more smartphones shipped in a decade
5Luxury Meets Hash Power: This $40K Watch Actually Mines Bitcoin
Latest
Most Read Today
MOST ENGAGING
Also read
Similar stories you might like.