Trust Wallet Chrome extension restored after $8.5M supply‑chain exploit; reimbursement process tightened
Trust Wallet has restored its Chrome browser extension after a December supply‑chain attack that led to roughly $8.5 million stolen from about 2,520 wallets. Attackers pushed a malicious extension (v2.68) on December 24; most thefts occurred December 25–26. Trust Wallet links the compromise to the November Shai‑Hulud npm registry breach and says attackers prepared infrastructure as early as December 8. White‑hat defenders deployed DDoS countermeasures that helped limit further losses. The incident affected only the Chrome extension; Trust Wallet’s mobile apps were not impacted. Trust Wallet identified 2,596 affected addresses but received more than 5,000 reimbursement claims, prompting a stricter verification process. The restored extension (v2.71.0) adds a verification‑code feature to authenticate claimants and reduce duplicates/fraud. CEO Eowyn Chen and Binance founder Changpeng Zhao confirmed plans to reimburse verified victims. Users are advised to remove any suspicious Trust Wallet extensions, update only from the official Chrome Web Store listing, and take standard wallet safety steps (use hardware wallets for large balances, avoid browser extensions for custodial keys).
Bearish
The exploit directly undermines trust in Trust Wallet’s Chrome extension and browser‑connected hot wallets, increasing perceived custody risk. In the short term this is bearish for Trust Wallet–related activity: users may withdraw funds from browser wallets, reduce on‑extension trading, and prefer self‑custody via hardware wallets, lowering on‑chain activity tied to the extension. The reimbursement plan and restored extension mitigate long‑term reputational damage, but market confidence will recover slowly. Because the incident concerns the wallet provider and not a native token with tradable supply, the price impact is limited to reduced usage and flows associated with the extension rather than a native token crash; still, negative sentiment and reduced transaction volume tied to the extension are expected in the near term.