No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Monday, January 19, 2026
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home Market Research Cryptocurrency

Hidden script caught harvesting private keys as Trust Wallet issues emergency warning for Chrome users

by TheAdviserMagazine
3 weeks ago
in Cryptocurrency
Reading Time: 4 mins read
A A
Hidden script caught harvesting private keys as Trust Wallet issues emergency warning for Chrome users
Share on FacebookShare on TwitterShare on LInkedIn


Trust Wallet told users to disable its Chrome browser extension version 2.68 after the company acknowledged a security incident and pushed version 2.69 on Dec. 25, following reports of wallet drains tied to the Dec. 24 update.

According to BleepingComputer, victims and researchers began flagging thefts soon after 2.68 rolled out. Early public tallies placed losses in a $6 million to $7 million-plus range across multiple chains.

The Chrome Web Store listing shows Trust Wallet extension version 2.69 as “Updated: December 25, 2025,” anchoring the vendor’s patch timing to the day the incident entered wider circulation.

The same listing displays about 1,000,000 users. That frames a worst-case ceiling for reach.

Practical exposure hinges on how many people installed 2.68 and entered sensitive data while it was active.

Trust Wallet’s guidance focused on the browser extension release. The outlet said mobile users and other versions of the extension were unaffected.

Reporting to date has concentrated on a specific user action during the 2.68 window.

Researchers flag elevated risks tied to Trust Wallet browser extension update

BleepingComputer said researchers and incident trackers tied the highest risk to users who imported or entered a seed phrase after installing the affected version. A seed phrase can unlock current and future addresses derived from it.

The outlet also reported that researchers reviewing the 2.68 bundle flagged suspicious logic in a JavaScript file, including references to a file labeled “4482.js.”

They said the logic could transmit wallet secrets to an external host. Researchers also cautioned that technical indicators were still being assembled as investigators published their findings.

The same coverage warned of secondary scams, including copycat “fix” domains. Those lures attempt to trick users into handing over recovery phrases under the guise of remediation.

For users, the difference between upgrading and remediating matters.

Updating to 2.69 can remove suspected malicious or unsafe behavior from the extension going forward. It does not automatically protect assets if a seed phrase or private key was already exposed.

In that case, standard incident response steps include moving funds to new addresses created from a new seed phrase. Users should also check for and revoke token approvals where feasible.

Users should treat any system that handled the phrase as suspect until it is rebuilt or verified clean.

Those actions can be operationally costly for retail users. They require re-establishing positions across chains and applications.

In some cases, they also force a choice between speed and precision when gas costs and bridging risks are part of the recovery path.

The episode also puts focus on the browser extension trust model.

Extensions sit at a sensitive seam between web apps and signing flows

Any compromise can target the same inputs users rely on to verify a transaction.

BC Game

Academic research on Chrome Web Store extension detection has described how malicious or compromised extensions can evade automated review. It has also described how detection can degrade as attacker tactics change over time.

According to an arXiv paper on supervised machine-learning detection of malicious extensions, “concept drift” and evolving behaviors can erode the effectiveness of static approaches. That point becomes more concrete when a wallet extension update is suspected of harvesting secrets through obfuscated client-side logic.

Trust Wallet’s next disclosures will set the boundaries for how the story settles.

A vendor post-mortem that documents root cause, publishes verified indicators (domains, hashes, bundle identifiers), and clarifies scope would help wallet providers, exchanges, and security teams develop targeted checks and user instructions.

Absent that, incident totals tend to remain unstable. Victim reports can arrive late, on-chain clustering can be refined, and investigators can still be resolving whether separate drainers share infrastructure or are opportunistic copycats.

Token markets reflected the news with movement but not a single-direction repricing.

The latest quoted figures provided for Trust Wallet Token (TWT) showed a last price of $0.83487, up $0.01 (0.02%) from the prior close. The figures showed an intraday high of $0.8483 and an intraday dip to $0.767355.

Trust Wallet Token PriceTWT metricValue (USD)Last price$0.83487Change vs. prior close+$0.01 (+0.02%)Intraday high$0.8483Intraday low$0.767355

Loss accounting remains in flux. The current best-public anchor is the $6 million to $7 million-plus range reported in the first 48 to 72 hours after 2.68 circulated.

That range can still shift for routine reasons in theft investigations

Those include delayed victim reporting, address reclassification, and improved visibility into cross-chain swaps and cash-out routes.

A practical forward range over the next two to eight weeks can be framed as scenarios tied to measurable swing variables. Those include whether the compromise path was confined to seed entry on 2.68, whether additional capture paths are confirmed, and how quickly copycat “fix” lures are removed.

Forward-looking projectionsScenario (next 2–8 weeks)Working loss rangeShareContained$6M–$12M40%Moderate expansion$15M–$25M35%Severe revision> $25M25%

The incident lands amid broader scrutiny of how retail-facing crypto software handles secrets on general-purpose devices.

2025 theft reporting has been large enough to draw policy and platform attention.

Incidents tied to software distribution also reinforce calls for build integrity controls, including reproducible builds, split-key signing, and clearer rollback options when a hotfix is needed.

For wallet extensions, the near-term practical outcome is simpler. Users must decide whether they ever entered a seed phrase while 2.68 was installed, because that single action determines whether upgrading is enough or whether they need to rotate secrets and move funds.

Trust Wallet’s guidance remains to disable the 2.68 extension and upgrade to 2.69 from the Chrome Web Store.

Users who imported or entered a seed phrase while running 2.68 should treat that seed as compromised and migrate assets to a new wallet.

Trust Wallet has now confirmed that approximately $7 million was impacted in the v2.68 Chrome extension incident and that it will refund all affected users.

In a statement posted on X, the company said it is finalizing the refund process and will share instructions on next steps “soon.” Trust Wallet also urged users not to interact with messages that do not come from its official channels, warning that scammers may attempt to impersonate the team during the remediation effort.

Mentioned in this article



Source link

Tags: caughtChromeemergencyHarvestingHiddenissuesKeysprivateScriptTrustUsersWalletwarning
ShareTweetShare
Previous Post

Jack Kellogg’s #1 Advice For Traders

Next Post

Stock Market Hits Highs On Nvidia, GDP Data: Weekly Review

Related Posts

edit post
US Bitcoin ETFs Post Strongest Weekly Inflows Since Last October — Details

US Bitcoin ETFs Post Strongest Weekly Inflows Since Last October — Details

by TheAdviserMagazine
January 18, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Spot Bitcoin ETFs (exchange-traded funds) in the...

edit post
NFTs Weekly Sales Surge By 2% To M – InsideBitcoins

NFTs Weekly Sales Surge By 2% To $61M – InsideBitcoins

by TheAdviserMagazine
January 18, 2026
0

Join Our Telegram channel to stay up to date on breaking news coverage The global non-fungible token market has begun...

edit post
Trump announces 10% tariff on Denmark and key European allies over Greenland dispute

Trump announces 10% tariff on Denmark and key European allies over Greenland dispute

by TheAdviserMagazine
January 17, 2026
0

Key Takeaways President Trump announced a 10% tariff on eight European countries over the Greenland issue. The tariffs will affect...

edit post
Fed Independence at Risk? Lummis and Hassett on Powell Probe

Fed Independence at Risk? Lummis and Hassett on Powell Probe

by TheAdviserMagazine
January 12, 2026
0

White House economic adviser Kevin Hassett defended the DOJ scrutiny linked to Fed Chair Jerome Powell and framed it as...

edit post
Bitcoin liquidity is about to get crunched by a new Korean law that legally excludes 99% of buyers

Bitcoin liquidity is about to get crunched by a new Korean law that legally excludes 99% of buyers

by TheAdviserMagazine
January 12, 2026
0

On paper, South Korea has been one of the world’s loudest crypto markets for years. In practice, it has been...

edit post
Scam-Yourself Attacks Are Spreading – and AI Is Making Them Harder to Spot

Scam-Yourself Attacks Are Spreading – and AI Is Making Them Harder to Spot

by TheAdviserMagazine
January 12, 2026
0

Cybercrime is increasingly targeting people, not devices. Attackers are using so-called “scam-yourself” techniques across everyday channels such as SMS, email,...

Next Post
edit post
Stock Market Hits Highs On Nvidia, GDP Data: Weekly Review

Stock Market Hits Highs On Nvidia, GDP Data: Weekly Review

edit post
9 quiet signs someone is silently judging your every move, according to psychology

9 quiet signs someone is silently judging your every move, according to psychology

  • Trending
  • Comments
  • Latest
edit post
Most People Buy Mansions But This Virginia Lottery Winner Took the Lump Sum From a 8 Million Jackpot and Bought a Zero-Turn Lawn Mower Instead

Most People Buy Mansions But This Virginia Lottery Winner Took the Lump Sum From a $348 Million Jackpot and Bought a Zero-Turn Lawn Mower Instead

January 10, 2026
edit post
Utility Shutoff Policies Are Changing in Several Midwestern States

Utility Shutoff Policies Are Changing in Several Midwestern States

January 9, 2026
edit post
80-year-old Home Depot rival shuts down location, no bankruptcy

80-year-old Home Depot rival shuts down location, no bankruptcy

January 4, 2026
edit post
Tennessee theater professor reinstated, with 0,000 settlement, after losing his job over a Charlie Kirk-related social media post

Tennessee theater professor reinstated, with $500,000 settlement, after losing his job over a Charlie Kirk-related social media post

January 8, 2026
edit post
Warren Buffett retires on December 31 and leaves behind a manual for a life in investing

Warren Buffett retires on December 31 and leaves behind a manual for a life in investing

December 27, 2025
edit post
Elon Musk Left DOGE… But He Hasn’t Left Washington

Elon Musk Left DOGE… But He Hasn’t Left Washington

January 2, 2026
edit post
Best high-yield savings interest rates today, January 18, 2026 (Earn up to 4% APY)

Best high-yield savings interest rates today, January 18, 2026 (Earn up to 4% APY)

0
edit post
A Key Stat Just Crossed a Major Milestone—And It Could Have a Major Impact on the Housing Market

A Key Stat Just Crossed a Major Milestone—And It Could Have a Major Impact on the Housing Market

0
edit post
A Look at Google’s Attempt to Control the Real Estate Market

A Look at Google’s Attempt to Control the Real Estate Market

0
edit post
What is Competition? – Econlib

What is Competition? – Econlib

0
edit post
5 Best Investing Apps for Beginners in 2026

5 Best Investing Apps for Beginners in 2026

0
edit post
NFTs Weekly Sales Surge By 2% To M – InsideBitcoins

NFTs Weekly Sales Surge By 2% To $61M – InsideBitcoins

0
edit post
After a tough 2025, 2026 looks more constructive for smallcaps: Anupam Tiwari

After a tough 2025, 2026 looks more constructive for smallcaps: Anupam Tiwari

January 18, 2026
edit post
Trump is charging world leaders  billion each for their countries to permanently join Gaza ‘Board of Peace’

Trump is charging world leaders $1 billion each for their countries to permanently join Gaza ‘Board of Peace’

January 18, 2026
edit post
BOJ keeps Yen watchers on edge as hike signals loom

BOJ keeps Yen watchers on edge as hike signals loom

January 18, 2026
edit post
An AI-generated version of Trump’s voice is used an ad that promises an ‘all new Fannie Mae’

An AI-generated version of Trump’s voice is used an ad that promises an ‘all new Fannie Mae’

January 18, 2026
edit post
US Bitcoin ETFs Post Strongest Weekly Inflows Since Last October — Details

US Bitcoin ETFs Post Strongest Weekly Inflows Since Last October — Details

January 18, 2026
edit post
Leviathan partners to invest .36b to expand production

Leviathan partners to invest $2.36b to expand production

January 18, 2026
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • After a tough 2025, 2026 looks more constructive for smallcaps: Anupam Tiwari
  • Trump is charging world leaders $1 billion each for their countries to permanently join Gaza ‘Board of Peace’
  • BOJ keeps Yen watchers on edge as hike signals loom
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.