Crypto Theft Attack on Trust Wallet: Implications for North East India
Overview of the Attack
In a significant cybersecurity incident, Trust Wallet, a popular cryptocurrency wallet used by over 200 million people worldwide, was targeted by attackers who drained approximately $7 million from nearly 3,000 wallets. The attack occurred on December 24, 2025, when the browser extension was compromised.
The Compromised Extension
The attackers added a malicious JavaScript file to version 2.68.0 of the Chrome extension, which exfiltrated sensitive wallet data. Trust Wallet confirmed the hack after being contacted by BleepingComputer and advised users to immediately update to version 2.69 to block further crypto theft attempts.
Investigation and Response
Trust Wallet expired all release APIs to block any attempts to release new versions over the next two weeks. They also reported the malicious exfiltration domain to NiceNIC, the registrar, which promptly suspended it. However, the attackers launched a phishing campaign to take advantage of the ensuing panic.
Reimbursement and User Safety
Trust Wallet has revealed that the attackers stole cryptocurrency from nearly 3,000 wallets and plans to reimburse all affected users. They have started reimbursing affected users and have cautioned them against sharing private keys, seed phrases, or passwords.
Relevance to North East India and Broader Indian Context
As cryptocurrency adoption grows in India, including in the North East region, such incidents underscore the need for heightened cybersecurity measures. Users are advised to verify links, never share their recovery phrases, and only use official communication channels.
Looking Forward
The investigation into the Trust Wallet attack is ongoing, and it serves as a reminder for all cryptocurrency users to prioritize their digital security. Trust Wallet has warned users about the increasing number of scams and impersonations, emphasizing the importance of vigilance in the digital age.