Binance-Owned Trust Wallet Hit by $7 Million Hack
Trust Wallet, the popular cryptocurrency wallet owned by global crypto exchange Binance, has suffered a security breach resulting in the loss of approximately $7 million, the company confirmed. The incident has raised fresh concerns about digital asset security, even as the firm assured users that affected funds would be fully compensated and that corrective measures were already in place.
According to an official statement, the breach was limited to a specific version of the Trust Wallet browser extension, version 2.68. The vulnerability did not affect users of the mobile application or other browser extension versions, the company clarified.
Trust Wallet disclosed the security incident on December 26 through its official account on X (formerly Twitter). The company said it had identified unusual activity related to the browser extension and immediately launched an internal investigation.
“We’ve identified a security issue impacting Trust Wallet Browser Extension version 2.68 only,” the company said. “Users should disable this version immediately and upgrade to version 2.69 via the official Chrome Web Store.”
The company added that malicious actors attempted to exploit the vulnerability to siphon digital assets from affected wallets, leading to losses estimated at around $7 million.
Binance Response and User Protection
Binance CEO Changpeng Zhao addressed the incident, assuring users that the situation was under control and that customer funds would be fully covered.
“We are actively working to contain the issue and protect users,” Zhao said. “Affected users will be compensated, and additional security measures are being implemented to prevent similar incidents.”
Trust Wallet also emphasized that it is cooperating with cybersecurity experts and blockchain analysts to trace stolen funds and prevent further exploitation.
Importantly, the company confirmed that:
Only Trust Wallet browser extension version 2.68 was affected
Mobile-only users were not impacted
Other browser extension versions remain secure
The clarification aimed to prevent panic and misinformation spreading among the platform’s millions of users worldwide.
Following the breach, Trust Wallet warned users to be cautious of phishing attempts and fake support accounts attempting to exploit the situation. The company urged users to rely solely on official communication channels and avoid clicking on suspicious links or sharing private keys.
Security teams are also working to identify and block fraudulent addresses linked to the incident, as part of broader damage control efforts.
The incident underscores ongoing security challenges within the cryptocurrency ecosystem, where wallets, exchanges, and protocols continue to face sophisticated cyber threats. Despite advances in blockchain security, vulnerabilities in software components remain a critical risk area.
Industry experts note that while decentralised finance platforms have matured, user education and software security remain key to preventing large-scale losses.
Trust Wallet said it is conducting a comprehensive review of its security infrastructure and development processes. The company reiterated its commitment to protecting users and maintaining transparency throughout the investigation.
“The safety of our users is our top priority,” the company said. “We are taking all necessary steps to strengthen our systems and ensure this type of incident does not happen again.”
The incident serves as a reminder for users to keep applications updated, verify official communication sources, and remain vigilant in an increasingly complex digital asset environment.