Vendor News

Trust Wallet promises refunds after $7M hack

By Zenobia Carrington August 15, 2026
Trust Wallet promises refunds after $7M hack - trust wallet hack
Trust Wallet promises refunds after $7M hack

Trust Wallet said it will reimburse users who lost funds in a security breach that exposed the browser extension version 2.68 on Christmas Day, according to statements posted on the platform’s X account.

Details of the breach and immediate response

The incident, first reported on December 25, involved a malicious modification to the extension’s internal analytics code. Attackers redirected data to a server they controlled, allowing them to steal assets from wallets that were still running the vulnerable version. Users who had already upgraded to version 2.69 were not affected, and the company emphasized that mobile‑only wallets and other extension versions remained safe.

Trust Wallet’s announcement noted that the breach resulted in losses exceeding $7 million. The next day, the team confirmed the figure and promised to refund every affected user. A follow‑up post said the company was “actively finalizing the process to refund the impacted users” and would soon share instructions for the next steps.

Refund process and user guidance

On December 26, Trust Wallet published a guide outlining how victims can begin the compensation process. The guide instructed users to disable the compromised extension, install the newer version, and submit a claim through the official support channel. The wallet’s support team said it was reviewing submissions “around the clock” and that each case would be verified carefully to prevent further errors.

Trust Wallet also warned users to ignore any messages that do not originate from its official communication channels, noting that scammers often exploit such incidents to target victims with phishing attempts.

Related: Asian Stocks Rise on Fed Rate Cut Hopes

Binance co‑founder Changpeng Zhao confirmed the reimbursement plan in a separate post, reinforcing the commitment to return the stolen funds.

The breach was examined by the blockchain security firm SlowMist, which released a technical report describing the attack vector. According to the report, the threat actor altered the extension’s analytics logic directly, rather than inserting a compromised third‑party library. The attacker then used the legitimate PostHog analytics service to funnel data to an unauthorized server.

From a practical standpoint, the situation highlights how quickly a small code change can jeopardize millions of dollars held in self‑custody wallets. Users who rely on browser extensions for daily transactions may find themselves exposed if they do not keep software up to date, showing the importance of prompt updates in the crypto space.

Trust Wallet’s compensation effort will be coordinated directly with victims, the company said, and updates will be posted on its official channels. The wallet reiterated its apology for the disruption and emphasized that protecting user assets remains a top priority.

Leave a Reply

© 2026 Vem Que Tem. All rights reserved.