Crypto Christmas Heist: Over $6 Million Lost, Trust Wallet Chrome Extension Wallet Hacked Analysis
Original Title: "Christmas Heist | Trust Wallet Browser Extension Wallet Hacked Analysis"
Original Source: SlowMist Technology
Background
Early this morning Beijing time, @zachxbt announced in the channel, "Some Trust Wallet users reported that funds in their wallet addresses have been stolen in the past few hours." Subsequently, Trust Wallet's official X also released an official statement confirming a security vulnerability in Trust Wallet Browser Extension version 2.68, advising all users using version 2.68 to immediately disable this version and upgrade to version 2.69.

Tactics
Upon receiving the intelligence, the SlowMist security team promptly conducted an analysis of the relevant samples. Let's first compare the core code of the previously released 2.67 and 2.68 versions:


By diffing the code of the two versions, we found the malicious code added by the hacker:

The malicious code will traverse all wallets in the plugin, make a "get mnemonic phrase" request for each user's wallet to obtain the user's encrypted mnemonic phrase, and finally use the password or passkeyPassword entered by the user when unlocking the wallet for decryption. If decryption is successful, the user's mnemonic phrase will be sent to the attacker's domain `api.metrics-trustwallet[.]com`.

We also analyzed the attacker's domain information; the attacker used the domain: metrics-trustwallet.com.

Upon investigation, the registration time of this malicious domain was 2025-12-08 02:28:18, and the domain registrar is: NICENIC INTERNATIONA.
Request records targeting api.metrics-trustwallet[.]com began on 2025-12-21.

This timestamp and the implantation of the backdoor with code 12.22 are roughly the same.
We continue to reproduce the entire attack process through code tracking analysis:
Through dynamic analysis, it can be seen that after unlocking the wallet, the attacker filled the mnemonic information into the error in R1.

And the source of this Error data is obtained through the GET_SEED_PHRASE function call. Currently, Trust Wallet supports two ways to unlock: password and passkeyPassword. The attacker, during the unlocking process, obtained the password or passkeyPassword, then called GET_SEED_PHRASE to obtain the wallet's mnemonic phrase (private key as well), and then placed the mnemonic phrase in the "errorMessage".

Below is the code using emit to call GetSeedPhrase to obtain the mnemonic phrase data and fill it into the error.

Traffic analysis performed through BurpSuite shows that after obtaining the mnemonic phrase, it is encapsulated in the request body's errorMessage field and sent to a malicious server (https[://]api[.]metrics-trustwallet[.]com), which is consistent with the previous analysis.

Through the above process, the theft of the mnemonic phrase/private key is completed. In addition, the attacker is also familiar with the source code and utilizes the open-source full-lifecycle product analysis platform PostHogJS to collect user wallet information.
Stolen Asset Analysis

(https://t.me/investigations/296)
According to ZachXBT's disclosed hacker address, we have calculated that as of the time of publication, the total amount of stolen assets on the Bitcoin blockchain is approximately 33 BTC (valued at around 3 million USD), the stolen assets on the Solana blockchain are valued at around 431 USD, and the stolen assets on the Ethereum mainnet and Layer 2 chains are valued at around 3 million USD. After stealing the coins, the hacker used various centralized exchanges and cross-chain bridges to transfer and exchange some of the assets.


Summary
This backdoor incident originated from a malicious code modification to the Trust Wallet extension's internal codebase (analytics service logic), rather than the introduction of a tampered third-party package (such as a malicious npm package). The attacker directly altered the application's own code, using the legitimate PostHog library to redirect analytics data to a malicious server. Therefore, we have reason to believe this was a professional APT attack, where the attacker may have gained control of Trust Wallet-related developers' device or release deployment permissions prior to December 8.
Recommendations:
1. If you have installed the Trust Wallet extension wallet, you should immediately disconnect from the internet as a prerequisite for investigation and actions.
2. Immediately export your private key/mnemonic phrase and uninstall the Trust Wallet extension wallet.
3. After backing up your private key/mnemonic phrase, promptly transfer your funds to another wallet.
You may also like

Don't Just Focus on Trading Volume: A Guide to Understanding the "Fake Real Volume" of Perpetual Contracts

Crypto Price Prediction Today 18 February – XRP, Bitcoin, Ethereum
Key Takeaways XRP’s potential as a replacement for SWIFT is bolstered by regulatory approvals, potentially driving its price…

XRP Price Prediction: XRP is Outpacing Solana and Targeting Binance Coin Next – Should You Invest Now?
Key Takeaways XRP Ledger has moved into the sixth place by tokenized real-world asset value, surpassing Solana and…

New AI Predicts the Price of XRP, Dogecoin, and Solana By 2026
Key Takeaways ChatGPT anticipates significant price increases for XRP, Dogecoin, and Solana by the end of 2026. XRP…

Arthur Hayes Shares Two Scenarios for Bitcoin Price, Calling for a Major Crypto Rally
Key Takeaways Arthur Hayes predicts a significant crypto rally fueled by a $572 billion liquidity injection from the…

Bitcoin Price Prediction: Abu Dhabi Gov Funds Buy $1 Billion in BTC – What Do They Know?
Key Takeaways Abu Dhabi has revealed a $1 billion stake in Bitcoin through major ETF investments, signaling strong…

Bitcoin’s Divergence From Nasdaq Signals Dollar Liquidity Risk, Says Arthur Hayes
Key Takeaways Arthur Hayes highlights a concerning divergence between Bitcoin and the Nasdaq, pointing to a potential dollar…

Lagarde’s Possible Early Exit Could Alter Digital Euro Plans and Stablecoin Oversight
Key Takeaways Christine Lagarde’s potential departure as ECB president may disrupt the digital euro timeline and stablecoin policies.…

HYLQ Strategy Invests in Hyperliquid Quantum Solutions Pioneer qLABS, Acquires 18,333,334 qONE Tokens
Key Takeaways HYLQ Strategy Corp has made a strategic investment in qLABS, purchasing over 18 million qONE tokens…

WLFI Crypto Surges Toward $0.12 as Whale Purchase Precedes Trump-Linked Forum
Key Takeaways Whale accumulation has spurred a rally in WLFI crypto prices, reaching towards $0.12 ahead of a…

Cathie Wood Reverses Path with $6.9 Million Purchase in Coinbase Stock – Is ARK Strategizing a Rebound?
Key Takeaways ARK Invest acquires 41,453 shares of Coinbase, showing renewed interest post recent divestment. This acquisition by…

Crypto Lobby Establishes Working Group to Advocate for Prediction Market Regulatory Clarity
Key Takeaways The Digital Chamber announced the Prediction Markets Working Group to promote federal oversight of prediction markets.…

Peter Thiel Discreetly Withdraws from Ethereum Treasury Venture ETHZilla – A Cautionary Note for the DAT Model?
Key Takeaways Peter Thiel and Founders Fund have completely exited their position in ETHZilla. Thiel’s withdrawal raises questions…

Coin Center Advocates Protecting Crypto Developer Liability
Key Takeaways Coin Center is actively lobbying the U.S. Senate to safeguard crypto developer liability protections. The ongoing…

$150B in US Tax Refunds Could Catalyze Fresh Crypto Inflows, Historical Trends Indicate
Key Takeaways The IRS anticipates distributing approximately $150 billion in tax refunds to U.S. consumers by the end…

Oracle Error Leads DeFi Lender Moonwell to $1.8 Million in Bad Debt
Key Takeaways A critical oracle pricing glitch caused Moonwell to incur nearly $1.8 million in bad debt. The…

Crypto Price Prediction Today 18 February – XRP, Solana, Dogecoin
Key Takeaways XRP targets a $5 move, driven by its role as an alternative to SWIFT for cross-border…

China’s DeepSeek AI Predicts the Price of XRP, PEPE, and Shiba Inu By the End of 2026
Key Takeaways DeepSeek AI suggests significant potential price increases for XRP, PEPE, and Shiba Inu by 2026. XRP…
Don't Just Focus on Trading Volume: A Guide to Understanding the "Fake Real Volume" of Perpetual Contracts
Crypto Price Prediction Today 18 February – XRP, Bitcoin, Ethereum
Key Takeaways XRP’s potential as a replacement for SWIFT is bolstered by regulatory approvals, potentially driving its price…
XRP Price Prediction: XRP is Outpacing Solana and Targeting Binance Coin Next – Should You Invest Now?
Key Takeaways XRP Ledger has moved into the sixth place by tokenized real-world asset value, surpassing Solana and…
New AI Predicts the Price of XRP, Dogecoin, and Solana By 2026
Key Takeaways ChatGPT anticipates significant price increases for XRP, Dogecoin, and Solana by the end of 2026. XRP…
Arthur Hayes Shares Two Scenarios for Bitcoin Price, Calling for a Major Crypto Rally
Key Takeaways Arthur Hayes predicts a significant crypto rally fueled by a $572 billion liquidity injection from the…
Bitcoin Price Prediction: Abu Dhabi Gov Funds Buy $1 Billion in BTC – What Do They Know?
Key Takeaways Abu Dhabi has revealed a $1 billion stake in Bitcoin through major ETF investments, signaling strong…