ZachXBT Reveals at Least $6 Million Stolen from Trust Wallet Users — Browser Extension Vulnerability at the Core

Beginner
Quick Reads
Last Updated 2026-03-26 14:52:38
Reading Time: 1m
Blockchain investigator ZachXBT has revealed that a vulnerability in the Trust Wallet browser extension has resulted in the theft of funds from hundreds of users, with losses surpassing $6 million. He further provided an analysis of the incident's specifics and the related security risks.


Image: https://x.com/DegenerateNews/status/2004283308059083250/photo/1

Incident Background and Latest Disclosures

Recently, on-chain investigator ZachXBT issued a critical security alert through social media and blockchain monitoring tools, revealing a vulnerability in the Trust Wallet browser extension. This flaw enabled the unauthorized transfer and theft of crypto assets from hundreds of users in a short time frame. Preliminary monitoring estimates place the total stolen amount at no less than $6 million.

The news spread rapidly across the crypto community, drawing significant attention from both users and industry professionals. ZachXBT’s monitoring data shows that several wallet addresses experienced suspicious outflows simultaneously. These funds were routed to unknown addresses or intermediary accounts and subsequently moved again.

Analysis of Losses and Impacted User Scale

Recent tracking data indicates that several hundred victims have been identified, with losses spanning multiple blockchains and assets—including, but not limited to, ETH, BTC, and SOL. The irregularities were not isolated to a single chain but were distributed across many wallet addresses, highlighting the event’s substantial scale.

In his latest update, ZachXBT emphasized that the sheer number of affected wallets makes it difficult to verify losses for each address. However, the preliminary estimate already exceeds $6 million, and this figure may rise as additional victims report their losses.

Stolen Funds Flow and Attack Patterns

Current analysis of fund movements suggests these thefts are tied to the browser extension vulnerability, especially when users import private keys or seed phrases, exposing themselves to significant risk. Multiple victims reported that their funds were drained rapidly to unknown accounts, indicating attackers had immediate access.

On-chain data shows that the attacks were highly automated, with stolen funds quickly dispersed and transferred across chains. This pattern differs from traditional hacks and more closely resembles a supply chain exploitation targeting hot wallet extension vulnerabilities.

Trust Wallet Official Response and User Actions


Image: https://x.com/TrustWallet/status/2004316503701958786

Trust Wallet has issued a security alert confirming that version 2.68 of the browser extension contains a critical vulnerability. Users are advised to immediately disable this version and upgrade to 2.69 or higher to mitigate risk. The official statement also clarified that the mobile app and other extension versions are not affected by this vulnerability.

Impacted users should take the following steps:

  • Immediately stop using the outdated extension and upgrade to the latest version \
  • If funds remain in your wallet, transfer them promptly to a cold wallet or another secure solution \
  • Report stolen assets through official support channels and retain all related on-chain evidence for investigation \

Security Lessons and Industry Impact

This incident highlights the ongoing challenge of balancing user experience and security in self-custody wallets. While browser extensions offer convenience, they also raise the risk of private key exposure and malicious activity. When users import mnemonic or seed phrases directly into extensions with vulnerabilities, assets can be drained within minutes.

Industry security experts recommend that users prioritize private key management, use hardware wallets or thoroughly audited security solutions, and avoid entering seed phrases into unverified clients or extensions. This event may also prompt wallet developers to enhance supply chain security assessments and code audits, strengthening overall ecosystem defenses.

Summary

ZachXBT’s latest disclosure of the Trust Wallet browser extension vulnerability underscores the critical need for crypto users to prioritize wallet security and remain vigilant about extension risks. In this incident, hundreds of users lost at least $6 million, prompting the community to re-examine self-custody wallet security. Users should act quickly to implement security measures, monitor official updates, and adopt safer asset management strategies to prevent similar incidents in the future.

Author: Max
Disclaimer
* The information is not intended to be and does not constitute financial advice or any other recommendation of any sort offered or endorsed by Gate.
* This article may not be reproduced, transmitted or copied without referencing Gate. Contravention is an infringement of Copyright Act and may be subject to legal action.

Related Articles

AI-Native Settlement Layers: How United Stables Is Building the Next Financial Rail
Beginner

AI-Native Settlement Layers: How United Stables Is Building the Next Financial Rail

Stablecoins were originally designed as dollar substitutes within exchanges, primarily used for asset pricing and trade settlement. As on-chain financial ecosystems have matured, their role has expanded beyond simple payments to include collateral assets, cross-chain liquidity mediums, and unified settlement units. In particular, as AI systems and automated agents begin to participate directly in economic activity, demand has risen sharply for programmable value units capable of instant settlement. This shift is pushing stablecoins toward the role of foundational financial infrastructure.
2026-03-25 03:16:17
The ve(3,3) Flywheel Explained: How AERO Tokenomics Powers Aerodrome’s DeFi Economy
Beginner

The ve(3,3) Flywheel Explained: How AERO Tokenomics Powers Aerodrome’s DeFi Economy

In the competition for DeFi liquidity, high-inflation mining alone is no longer enough to build lasting advantages. Aerodrome applies the ve(3,3) economic model to redesign token emissions, voting mechanisms, and revenue distribution, creating a liquidity flywheel centered on governance and cash flow. This article examines AERO tokenomics, the veAERO locking mechanism, and protocol revenue models to explain how Aerodrome builds a sustainable DeFi economic system.
2026-03-25 06:41:58
Aerodrome Tokenomics: How ve(3,3) Powers Base's Most Profitable DEX
Beginner

Aerodrome Tokenomics: How ve(3,3) Powers Base's Most Profitable DEX

AERO is the native token of Aerodrome Finance, a core decentralized exchange and liquidity protocol in the Base ecosystem. It is primarily used for liquidity incentives and ecosystem operations. veAERO is a governance NFT that users receive by locking AERO, representing both voting power and the right to share protocol revenue. Through a dual track structure of AERO as a utility token and veAERO as a governance credential, Aerodrome separates liquidity usage value from long term governance power, allowing participants to act as liquidity providers, governance decision makers, and revenue sharers within the same system.
2026-03-25 06:40:31
How Does PAXG Work? In-Depth Overview of the Physical Gold Tokenization Mechanism
Beginner

How Does PAXG Work? In-Depth Overview of the Physical Gold Tokenization Mechanism

PAXG (Pax Gold) is a tokenized asset backed by physical gold, issued by the fintech company Paxos and traded on the Ethereum blockchain as an ERC-20 token. The core concept is to tokenize physical gold on-chain, with each PAXG token representing ownership of a certain amount of gold. This structure enables investors to hold and trade gold in the form of a digital asset.
2026-03-24 19:12:51
How is the price of PAXG determined? Pegging mechanism, trading depth, and influencing factors
Beginner

How is the price of PAXG determined? Pegging mechanism, trading depth, and influencing factors

PAXG (Pax Gold) is a tokenized asset backed by physical gold reserves, launched by fintech firm Paxos and issued as an ERC-20 token on the Ethereum blockchain. The core concept is to digitally represent real-world gold assets, allowing investors to hold and trade gold via the blockchain network. Because each PAXG token corresponds to a specific quantity of physical gold, its price is theoretically expected to closely track the global gold market.
2026-03-24 19:11:40
DePIN Identity Network and Real World Applications: How Humanity Protocol Brings on-chain Identity Into the Physical World
Beginner

DePIN Identity Network and Real World Applications: How Humanity Protocol Brings on-chain Identity Into the Physical World

Most Web3 identity systems remain confined to on-chain environments and struggle to achieve meaningful adoption in real world settings. Through a DePIN architecture and physical verification hardware, Humanity Protocol aims to bring decentralized identity into access control systems, hospitality, public services, and offline events, allowing on-chain identity to function not just as a digital credential, but as foundational infrastructure for real world access.
2026-03-25 07:40:53