Plugin Wallet Security Incident Overview: Plagued by Fake Software and Phishing Attacks, Fewer Direct Official Vulnerabilities
BlockBeats News, December 26: This morning, Trust Wallet, the largest non-custodial cryptocurrency wallet by user base, issued a security alert confirming a security vulnerability in browser extension version 2.68. On-chain detective ZachXBT revealed that hundreds of Trust Wallet users have had their funds stolen, with losses totaling at least $6 million. Trust Wallet has been downloaded over 2 billion times, with approximately 17 million monthly active users, holding about 35% market share, making this security incident far-reaching. A look back at security incidents encountered by several mainstream browser extensions:
In November 2022, Trust Wallet's browser extension was found to have a WebAssembly vulnerability, affecting only new wallet addresses created between November 14 and 23, 2022. Approximately $170,000 was stolen. Trust Wallet discovered the issue through a bug bounty program, fixed the vulnerability, and fully compensated affected users.
In 2022, MetaMask experienced the "Demonic" vulnerability, impacting older versions before 10.11.3, where private keys could be exposed in the browser's memory. However, no significant fund losses were reported. Subsequently, from 2023 to 2025, MetaMask's official wallet extension operated securely but was frequently targeted by counterfeit extension programs. A Chainalysis report indicated a surge in MetaMask user abnormal theft events in 2025, mainly due to counterfeit malicious software and phishing rather than inherent plugin wallet security. MetaMask now releases monthly security reports, but as a popular Ethereum plugin wallet, it remains a prime target for counterfeiting.
In 2022, Phantom (the primary Solana wallet extension) also faced the "Demonic" vulnerability, with no known significant fund losses. Early 2025 saw a security controversy involving the Phantom wallet extension, where a user lost $500,000 due to private keys being in clear text in memory, leading to a hacker attack and resulting in a class-action lawsuit filed in a southern district court of New York. Phantom's official statement strongly denied all allegations, stating that the lawsuit was "baseless" and emphasizing that Phantom is a non-custodial wallet, placing the responsibility for fund security on the user.
In 2022, Rabby Wallet (a DeFi-friendly extension) suffered a hack where approximately $200,000 in encrypted assets were stolen due to a Rabby Swap vulnerability, which was not from the plugin itself but from the built-in Swap feature.
The most common theft method for browser extension wallets is through counterfeit application downloads. In 2025, there were multiple concentrated outbreaks of such incidents in the Firefox store, affecting several popular crypto extension wallets such as MetaMask, Phantom, and Trust Wallet. On the other hand, direct official vulnerabilities of the extensions are less common. It is recommended that users only download from the official Chrome Web Store to ensure the security of their funds.
You may also like

Key Market Intel Discrepancy on December 26 - A Must-Read! | Alpha Morning Report

30 Predictions, Filtered for Five 2026 Crypto Consensus

Countdown to Midterm Elections: Will the US Crypto Bill Pass the Test?

2025 Crypto Rich List: 12 Big Winners, Who Bet on the Money Maker?

「Macro Master」 Raoul Pal on 30x Growth Under Indexation: Bitcoin Will Eventually Surpass Gold

Base App is now fully open! How was your experience?

Uniswap Pay Dispute Escalates, Maple Finance Loan volume Hits All-Time High, What's the Overseas Crypto Community Talking About Today?

Galaxy's 26 Predictions for Next Year: Bitcoin to Reach New ATH, Stablecoin Transaction Volume to Surpass ACH System

Blockchains Quietly Prepare for Quantum Threat as Bitcoin Debates Timeline
Key Takeaways: Several blockchains, including Ethereum, Solana, and Aptos, are actively preparing for the potential threat posed by…

Former SEC Counsel Explains What It Takes to Make RWAs Compliant
Key Takeaways The SEC’s shifting approach is aiding the growth of Real-World Assets (RWAs), but jurisdictional and yield…

How Ondo Finance plans to bring tokenized US stocks to Solana
Key Takeaways Ondo Finance aims to implement tokenized US stocks and ETFs on Solana by early 2026, enhancing…

Trend Research Quietly Becomes One of Ethereum’s Largest Whales with Major ETH Acquisition
Key Takeaways Trend Research has acquired 46,379 ETH, boosting their total holdings to about 580,000 ETH. The company,…

Aave’s $10M Token Purchase Raises Concerns Over Governance Power
Key Takeaways: Aave founder Stani Kulechov’s $10 million AAVE token purchase sparks debates over governance power concentration. Concerns…

Web3 and DApps in 2026: A Utility-Driven Year for Crypto
Key Takeaways The transition to utility in the crypto sector has set a new path for 2026, emphasizing…

How to Evaluate a Curator?

December 24th Market Key Intelligence, How Much Did You Miss?

Base's 2025 Report Card: Revenue Grows 30X, Solidifies L2 Leadership

From Aave to Ether.fi: Who Captured the Most Value in the On-Chain Credit System?
Key Market Intel Discrepancy on December 26 - A Must-Read! | Alpha Morning Report
30 Predictions, Filtered for Five 2026 Crypto Consensus
Countdown to Midterm Elections: Will the US Crypto Bill Pass the Test?
2025 Crypto Rich List: 12 Big Winners, Who Bet on the Money Maker?
「Macro Master」 Raoul Pal on 30x Growth Under Indexation: Bitcoin Will Eventually Surpass Gold
Base App is now fully open! How was your experience?
Popular coins
Latest Crypto News
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Services:support@weex.com