Trust Wallet CEO Confirms v2.68 Extension Incident Impacted 2,596 Addresses

Trust Wallet CEO Confirms v2.68 Extension Incident Impacted 2,596 Addresses

Trust Wallet’s v2.68 browser extension breach, tied to a supply-chain attack, stole $8.5 million from 2,520 wallets; version 2.69 deployed and victim compensation underway.

Fact Check
The evidence strongly and consistently supports the statement. Multiple sources with high-to-medium authority explicitly state that the Trust Wallet v2.68 extension incident impacted exactly 2,596 addresses. A post on Binance Square, a platform owned by Trust Wallet's parent company, directly confirms this number. This is corroborated by a crypto news outlet, which attributes the figure to a Trust Wallet executive, as well as by a crypto exchange blog, an investment analysis article, and a blockchain service provider. The highest authority source, Trust Wallet's official X account, confirms the security incident with version 2.68, which lends credibility to the more specific reports. Crucially, there is no conflicting evidence among the provided sources; no source suggests a different number of affected addresses or refutes the claim. The widespread agreement across various types of reputable sources makes the statement highly likely to be true.
Summary

Trust Wallet reported that its v2.68 browser extension was uploaded to the Chrome store without internal review and contained malicious code enabling unauthorized transactions and data theft. The breach impacted 2,520 wallet addresses and caused losses of approximately $8.5 million. The plugin has been rolled back to v2.69, and compensation for victims has begun through its official process. A discrepancy remains between earlier CEO-reported figures of 2,596 affected addresses and the latest count, with ownership verification continuing to prevent fraudulent claims.

Terms & Concepts
  • Wallet address: A unique identifier used to send and receive cryptocurrency transactions.
  • Browser extension: A wallet add-on for web browsers that enables on-chain actions and can be a security risk if compromised.
  • Ownership verification: The process of confirming a claimant controls the affected wallet before compensation is issued.