Trust Wallet Christmas Hack: Inside the $7M Supply Chain Breach
-

On Dec. 25, Trust Wallet suffered a major security breach that resulted in approximately $7 million in losses across 2,596 wallets. According to the company, the attack stemmed from a “Sha1-Hulud” supply chain compromise, where malicious npm packages were used to leak developer secrets from GitHub and gain access to the wallet’s browser extension source code.
The attacker later uploaded a malicious version of the Trust Wallet Chrome extension, disguised as legitimate software. While the mobile app was unaffected, the browser extension became the entry point for the exploit. Binance, which owns Trust Wallet, agreed to reimburse affected users, as figures like Changpeng Zhao and blockchain adviser Anndy Lian suggested the breach may have involved insider-level knowledge.
-
supply chain attacks are honestly the scariest part of crypto, you can do everything “right” and still get wrecked