Plugin Wallet Security Incident Overview: Plagued by Fake Software and Phishing Attacks, Fewer Direct Official Vulnerabilities
BlockBeats News, December 26: This morning, Trust Wallet, the largest non-custodial cryptocurrency wallet by user base, issued a security alert confirming a security vulnerability in browser extension version 2.68. On-chain detective ZachXBT revealed that hundreds of Trust Wallet users have had their funds stolen, with losses totaling at least $6 million. Trust Wallet has been downloaded over 2 billion times, with approximately 17 million monthly active users, holding about 35% market share, making this security incident far-reaching. A look back at security incidents encountered by several mainstream browser extensions:
In November 2022, Trust Wallet's browser extension was found to have a WebAssembly vulnerability, affecting only new wallet addresses created between November 14 and 23, 2022. Approximately $170,000 was stolen. Trust Wallet discovered the issue through a bug bounty program, fixed the vulnerability, and fully compensated affected users.
In 2022, MetaMask experienced the "Demonic" vulnerability, impacting older versions before 10.11.3, where private keys could be exposed in the browser's memory. However, no significant fund losses were reported. Subsequently, from 2023 to 2025, MetaMask's official wallet extension operated securely but was frequently targeted by counterfeit extension programs. A Chainalysis report indicated a surge in MetaMask user abnormal theft events in 2025, mainly due to counterfeit malicious software and phishing rather than inherent plugin wallet security. MetaMask now releases monthly security reports, but as a popular Ethereum plugin wallet, it remains a prime target for counterfeiting.
In 2022, Phantom (the primary Solana wallet extension) also faced the "Demonic" vulnerability, with no known significant fund losses. Early 2025 saw a security controversy involving the Phantom wallet extension, where a user lost $500,000 due to private keys being in clear text in memory, leading to a hacker attack and resulting in a class-action lawsuit filed in a southern district court of New York. Phantom's official statement strongly denied all allegations, stating that the lawsuit was "baseless" and emphasizing that Phantom is a non-custodial wallet, placing the responsibility for fund security on the user.
In 2022, Rabby Wallet (a DeFi-friendly extension) suffered a hack where approximately $200,000 in encrypted assets were stolen due to a Rabby Swap vulnerability, which was not from the plugin itself but from the built-in Swap feature.
The most common theft method for browser extension wallets is through counterfeit application downloads. In 2025, there were multiple concentrated outbreaks of such incidents in the Firefox store, affecting several popular crypto extension wallets such as MetaMask, Phantom, and Trust Wallet. On the other hand, direct official vulnerabilities of the extensions are less common. It is recommended that users only download from the official Chrome Web Store to ensure the security of their funds.
You may also like

Lido DAO’s Increased Development and Market Dynamics Elevate LDO Price
Key Takeaways Lido DAO’s development activities have surged by 690%, signifying substantial growth. The Lido DAO token (LDO)…

Hyperliquid Whales Shift Strategies: BTC Longs Decline, ETH Shorts Dominate
Key Takeaways A significant reduction in Bitcoin long positions has been observed on Hyperliquid, with large holders decreasing…

December 26th Market Key Intelligence, How Much Did You Miss?

Crypto Christmas Heist: Over $6 Million Lost, Trust Wallet Chrome Extension Wallet Hacked Analysis

Trust Wallet Browser Extension Security Incident Leads to Losses
Key Takeaways Trust Wallet identified a significant security breach in its browser extension version 2.68. Approximately over $6…

Ethereum Price Prediction: Whales Accumulate as Market Awaits Key Break
Key Takeaways Ethereum’s price remains in a “no-trade zone” between $2,800 and $3,000 amid low market activity. Whale…

Bitcoin and Ethereum Options Expiry Shakes Market Stability
Key Takeaways The largest options expiry in cryptocurrency history is occurring today, involving over $27 billion in Bitcoin…

Trust Wallet Hack Results in $3.5 Million Loss for Major Wallet Holder
Key Takeaways A significant Trust Wallet hack led to the theft of $3.5 million from an inactive wallet.…

PancakeSwap Launches LP Rewards on Base Network
Key Takeaways PancakeSwap has introduced liquidity provider (LP) rewards for 12 v3 pools on the Base network, facilitated…

Ethereum in 2026: Glamsterdam and Hegota Forks, Layer 1 Scaling, and More
Key Takeaways Ethereum is poised for crucial developments in 2026, particularly with the Glamsterdam and Hegota forks. Glamsterdam…

Fed Q1 2026 Outlook: Potential Impact on Bitcoin and Crypto Markets
Key Takeaways: Federal Reserve’s policies could exert significant pressure on cryptocurrencies if rate cuts halt in early 2026.…

Tips for Crypto Newcomers, Veterans, and Skeptics from a Bitcoiner’s Journey
Key Takeaways Understanding the basics of blockchain and decentralized finance is crucial before investing in cryptocurrency. Newcomers should…

Trust Wallet to Reimburse $7 Million Lost in Christmas Hack: An Inside Job?
Key Takeaways Trust Wallet’s browser extension was compromised, leading to a $7 million loss on Christmas Day. The…

Ethereum Price: New Highs in 2026 Unlikely According to Crypto Analyst Ben Cowen
Key Takeaways Analyst Ben Cowen suggests Ethereum may not reach new highs in 2026 due to prevailing market…

Blockchains Quietly Brace for Quantum Threat Amid Bitcoin Debate
Key Takeaways Cryptocurrency networks, especially altcoins, are enhancing security to prepare for potential quantum computing threats. Bitcoin faces…

Vitalik Buterin Discusses Grok’s Impact on X’s Truthfulness
Key Takeaways Grok, an AI chatbot, is praised by Vitalik Buterin for enhancing the truthfulness of the social…

Canton Token Surges Amid DTCC’s Tokenized Treasury Plans
Key Takeaways Canton Coin has surged by approximately 27% due to growing institutional interest and DTCC’s announcement to…

Trust Wallet to Compensate $7M Loss from Christmas Day Hack
Key Takeaways Trust Wallet users suffered a loss of $7 million on Christmas Day due to a planned…
Lido DAO’s Increased Development and Market Dynamics Elevate LDO Price
Key Takeaways Lido DAO’s development activities have surged by 690%, signifying substantial growth. The Lido DAO token (LDO)…
Hyperliquid Whales Shift Strategies: BTC Longs Decline, ETH Shorts Dominate
Key Takeaways A significant reduction in Bitcoin long positions has been observed on Hyperliquid, with large holders decreasing…
December 26th Market Key Intelligence, How Much Did You Miss?
Crypto Christmas Heist: Over $6 Million Lost, Trust Wallet Chrome Extension Wallet Hacked Analysis
Trust Wallet Browser Extension Security Incident Leads to Losses
Key Takeaways Trust Wallet identified a significant security breach in its browser extension version 2.68. Approximately over $6…
Ethereum Price Prediction: Whales Accumulate as Market Awaits Key Break
Key Takeaways Ethereum’s price remains in a “no-trade zone” between $2,800 and $3,000 amid low market activity. Whale…
Popular coins
Latest Crypto News
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Services:support@weex.com