Crypto Christmas Heist: Over $6 Million Lost, Trust Wallet Chrome Extension Wallet Hacked Analysis
Original Title: "Christmas Heist | Trust Wallet Browser Extension Wallet Hacked Analysis"
Original Source: SlowMist Technology
Background
Early this morning Beijing time, @zachxbt announced in the channel, "Some Trust Wallet users reported that funds in their wallet addresses have been stolen in the past few hours." Subsequently, Trust Wallet's official X also released an official statement confirming a security vulnerability in Trust Wallet Browser Extension version 2.68, advising all users using version 2.68 to immediately disable this version and upgrade to version 2.69.

Tactics
Upon receiving the intelligence, the SlowMist security team promptly conducted an analysis of the relevant samples. Let's first compare the core code of the previously released 2.67 and 2.68 versions:


By diffing the code of the two versions, we found the malicious code added by the hacker:

The malicious code will traverse all wallets in the plugin, make a "get mnemonic phrase" request for each user's wallet to obtain the user's encrypted mnemonic phrase, and finally use the password or passkeyPassword entered by the user when unlocking the wallet for decryption. If decryption is successful, the user's mnemonic phrase will be sent to the attacker's domain `api.metrics-trustwallet[.]com`.

We also analyzed the attacker's domain information; the attacker used the domain: metrics-trustwallet.com.

Upon investigation, the registration time of this malicious domain was 2025-12-08 02:28:18, and the domain registrar is: NICENIC INTERNATIONA.
Request records targeting api.metrics-trustwallet[.]com began on 2025-12-21.

This timestamp and the implantation of the backdoor with code 12.22 are roughly the same.
We continue to reproduce the entire attack process through code tracking analysis:
Through dynamic analysis, it can be seen that after unlocking the wallet, the attacker filled the mnemonic information into the error in R1.

And the source of this Error data is obtained through the GET_SEED_PHRASE function call. Currently, Trust Wallet supports two ways to unlock: password and passkeyPassword. The attacker, during the unlocking process, obtained the password or passkeyPassword, then called GET_SEED_PHRASE to obtain the wallet's mnemonic phrase (private key as well), and then placed the mnemonic phrase in the "errorMessage".

Below is the code using emit to call GetSeedPhrase to obtain the mnemonic phrase data and fill it into the error.

Traffic analysis performed through BurpSuite shows that after obtaining the mnemonic phrase, it is encapsulated in the request body's errorMessage field and sent to a malicious server (https[://]api[.]metrics-trustwallet[.]com), which is consistent with the previous analysis.

Through the above process, the theft of the mnemonic phrase/private key is completed. In addition, the attacker is also familiar with the source code and utilizes the open-source full-lifecycle product analysis platform PostHogJS to collect user wallet information.
Stolen Asset Analysis

(https://t.me/investigations/296)
According to ZachXBT's disclosed hacker address, we have calculated that as of the time of publication, the total amount of stolen assets on the Bitcoin blockchain is approximately 33 BTC (valued at around 3 million USD), the stolen assets on the Solana blockchain are valued at around 431 USD, and the stolen assets on the Ethereum mainnet and Layer 2 chains are valued at around 3 million USD. After stealing the coins, the hacker used various centralized exchanges and cross-chain bridges to transfer and exchange some of the assets.


Summary
This backdoor incident originated from a malicious code modification to the Trust Wallet extension's internal codebase (analytics service logic), rather than the introduction of a tampered third-party package (such as a malicious npm package). The attacker directly altered the application's own code, using the legitimate PostHog library to redirect analytics data to a malicious server. Therefore, we have reason to believe this was a professional APT attack, where the attacker may have gained control of Trust Wallet-related developers' device or release deployment permissions prior to December 8.
Recommendations:
1. If you have installed the Trust Wallet extension wallet, you should immediately disconnect from the internet as a prerequisite for investigation and actions.
2. Immediately export your private key/mnemonic phrase and uninstall the Trust Wallet extension wallet.
3. After backing up your private key/mnemonic phrase, promptly transfer your funds to another wallet.
You may also like
How AI Helps Crypto Traders Analyze Markets, Manage Risk, and Trade Smarter
Crypto trading is no longer just about having a good idea—it is about executing consistently in a market that never stops. As data volumes and market speed increase, traditional manual analysis reaches its limits. AI helps traders move beyond these limits by transforming how markets are analyzed, how sentiment is interpreted, and how risk is controlled. This article explores how AI is reshaping crypto trading — and what that means for traders today.
WEEX × LALIGA: Seven Stars That Represent a Shared Standard of Excellence
True excellence in football is never accidental. It is built on discipline, consistency, and the ability to deliver under pressure — season after season. The same principles apply in professional trading, where long-term performance matters more than short-lived momentum. As an official regional partner of LALIGA, WEEX highlights seven outstanding players who embody the league’s competitive spirit and global appeal. Each brings a unique style to the pitch, yet all share values that closely align with WEEX’s commitment to stability, precision, and professional execution. This partnership is built on shared standards — where consistency and control define performance under pressure.

Arkstream Capital: When Cryptocurrency Returns to 'Financial Logic' by 2025

The Year Trump Embraced Cryptocurrency

IOSG: Port and New City, Two Cryptoverse Views of BNB Chain and Base
WEEX Partners with LALIGA to Expand Global Reach and Integrate Crypto into Mainstream Sports Culture
Hong Kong, Jan. 1, 2026. WEEX has entered into a new partnership with LALIGA, as an official regional partner of LALIGA in Taiwan and Hong Kong. The agreement brings WEEX into LALIGA’s network of regional collaborators and opens the door to new ways of engaging both fans and traders during the season.

Perpetual Contract Genesis: Pricing Liquidity with a Magic Formula, Transparency Prevents it from Reaching its Full Potential

Decode Stock on Chain: Why Are Crypto Enthusiasts Investing in US Stocks While Wall Street Is Going Blockchain Unfriendly?

Key Market Intelligence as of December 31st, how much did you miss out on?

Long-standing domestic public blockchain NEO sees feud between two co-founders, with opaque finances as the core reason

Hong Kong Virtual Asset Trading Platform New Regulations (Part 2): New Circular Issued, Has the Boundary of Virtual Asset Business Been Redefined?

DeFi 2.0 Explosion Post-Disorderly Restructuring in 2026

Fed's Latest Meeting Minutes: Divergence Persists, But "Most" Officials Advocate Continued Rate Cuts

AI Trading in Crypto: How Traders Actually Apply AI in Real Crypto Markets
Artificial intelligence has moved beyond experimentation in crypto markets. In 2025, AI-driven trading tools are increasingly used by traders who want better discipline, faster execution, and more structured decision-making in volatile markets. This guide explains how AI is actually used in crypto trading, step by step — with a focus on how these strategies are executed in real trading environments.

The first large-scale adoption of a "yield-bearing stablecoin" was in China
Market Update — December 31
From South Korea and the OECD accelerating the implementation of crypto regulation and compliance frameworks, to the simultaneous development of TAO ETFs, privacy technologies, mining, and Bitcoin reserves, while security incidents and financial losses continue to rise, the crypto market has entered a new phase amid multiple challenges of "strong regulation + technological evolution + amplified risks."

Lighter Token Distribution Sparks Controversy, Zama Launches USDT Private Transfers, What is the Overseas Crypto Community Talking About Today?

4 Years of Web3 Entrepreneurship: 7 Key Takeaways
How AI Helps Crypto Traders Analyze Markets, Manage Risk, and Trade Smarter
Crypto trading is no longer just about having a good idea—it is about executing consistently in a market that never stops. As data volumes and market speed increase, traditional manual analysis reaches its limits. AI helps traders move beyond these limits by transforming how markets are analyzed, how sentiment is interpreted, and how risk is controlled. This article explores how AI is reshaping crypto trading — and what that means for traders today.
WEEX × LALIGA: Seven Stars That Represent a Shared Standard of Excellence
True excellence in football is never accidental. It is built on discipline, consistency, and the ability to deliver under pressure — season after season. The same principles apply in professional trading, where long-term performance matters more than short-lived momentum. As an official regional partner of LALIGA, WEEX highlights seven outstanding players who embody the league’s competitive spirit and global appeal. Each brings a unique style to the pitch, yet all share values that closely align with WEEX’s commitment to stability, precision, and professional execution. This partnership is built on shared standards — where consistency and control define performance under pressure.
Arkstream Capital: When Cryptocurrency Returns to 'Financial Logic' by 2025
The Year Trump Embraced Cryptocurrency
IOSG: Port and New City, Two Cryptoverse Views of BNB Chain and Base
WEEX Partners with LALIGA to Expand Global Reach and Integrate Crypto into Mainstream Sports Culture
Hong Kong, Jan. 1, 2026. WEEX has entered into a new partnership with LALIGA, as an official regional partner of LALIGA in Taiwan and Hong Kong. The agreement brings WEEX into LALIGA’s network of regional collaborators and opens the door to new ways of engaging both fans and traders during the season.