NexFlow › Is Trust Wallet safe
Is Trust Wallet safe? The mobile wallet whose browser extension was weaponized
Trust Wallet is the Binance-ecosystem self-custody wallet — keys on your device, ~1M Chrome extension users, tens of millions of mobile installs. Its safety record now has two parts: the mobile app, which has no documented compromise of this class — and December 24, 2025, when a leaked Chrome Web Store API key let an attacker publish a weaponized extension update that drained roughly 2,520 wallets of ~$7M before Christmas. The company reimbursed in full. What the incident proves and doesn't prove is the whole answer.
What Trust Wallet is
Trust Wallet is a non-custodial multi-chain wallet — primarily mobile, plus a browser extension — owned by Binance since 2018. Custody is the standard self-custody shape: keys and recovery phrase live on your device under your passcode/biometric, Trust Wallet holds nothing and cannot recover or freeze anything. The extension carries about a million Chrome Web Store users; the mobile app claims install numbers an order of magnitude larger. Being Binance-adjacent matters for two reasons: the brand inherits the phishing target painted on the biggest name in crypto — and, it turns out, the parent's reimbursement reflex.
December 24, 2025: the extension that shipped itself
The documented incident, per Trust Wallet's own post-incident report and CEO Eowyn Chen's statements: an attacker used a leaked Chrome Web Store API key to publish version 2.68 of the Trust Wallet extension directly to the store — bypassing the company's internal release pipeline entirely — and it passed Google's review at 12:32 UTC on December 24. The malicious build, per SlowMist's analysis, contained code (a bundled `4482.js`) that iterated every wallet stored in the extension, triggered the mnemonic export for each, and exfiltrated the data through a hijacked PostHog analytics channel to an attacker-controlled domain. Critically, SlowMist attributed it to modification of the wallet's own analytics logic — not a poisoned npm dependency: the extension was Trust Wallet code, weaponized.
Impact and response: approximately 2,520 wallet addresses drained, ~$7M stolen (the later vendor update cited ~$8.5M associated with 17 attacker addresses, noting some drains hit non-Trust-Wallet victims too). Within hours: v2.69 shipped clean, all release API keys were expired, the exfiltration domain was suspended by its registrar. CZ posted the Binance-house answer — "TrustWallet will cover. User funds are SAFU" — and the company opened a voluntary reimbursement process for affected users, reporting >5,000 claims against ~2,500 verified victims (fraudulent claims included). The mobile app and the self-custody model were never touched; the browser release pipeline was.
What the incident actually proves
Two readings, both earned. The bad: a leaked publishing credential let an outsider ship arbitrary code to ~1M extension users with Google's store review as the only gate — the nightmare scenario for any extension wallet, executed in public. The good, and it is genuine: detection-to-clean-release inside hours, all release keys rotated, full voluntary reimbursement — the response chain a funded incumbent is supposed to run. For this corpus's purposes the incident sits in the same class as Ledger's Connect Kit: the wallet's keys were never the weak link; the distribution layer was — the code that delivers the wallet, not the wallet that holds the keys.
The honest boundary for users: an extension wallet's exposure is every installed wallet it can enumerate — the 2.68 malware worked because a browser extension, by design, can read all stored wallets once loaded. That is the structural reason the corpus recommends extensions for spending and mobile-or-hardware for holding.
The standing risk profile
Beyond the December incident, Trust Wallet's risk surface is the mobile-wallet standard: brand impersonation (a Binance-adjacent name is a phishing magnet — fake "Trust Wallet" apps and support accounts are a permanent background hum); phrase harvesting — the SRP is the wallet, and every "verification" flow asking for it is hostile by definition; and device-level compromise — a rooted/jailbroken phone running a keyring is the exposure no wallet software can close. One historical footnote: in April 2023 Trust Wallet itself circulated a warning about an alleged iOS/iMessage zero-day targeting crypto holders — never publicly confirmed, included here only as evidence of how the vendor talks about threat intel: cautiously and early.
On the protective side: self-custody means no central honeypot; the app holds standard certifications and audits for the class; and the post-incident release controls (expired API keys, tightened publishing) are now the demonstrated — not promised — posture. The reimbursement precedent is worth more than a policy page: Trust Wallet has now actually paid the claim it advertises.
What actually protects a Trust Wallet user
The habits the record argues for: update discipline on extensions — but verify updates land through the real store channel (v2.68 was a "real" store release; the lesson is to prefer the mobile app for size and treat any extension as a hot surface); phrase quarantine — never typed anywhere, exported only for a deliberate backup; source verification — the real Trust Wallet ships via trustwallet.com and official store listings under the verified publisher; and value segregation — the ~2,520 drained wallets were holding, in a browser extension, what a $7M payout found worth taking. Hardware for the vault remains the standing advice of this entire family.
Frequently asked questions
Was Trust Wallet hacked?
Yes — one documented incident, December 24, 2025: a leaked Chrome Web Store API key let an attacker publish a malicious extension update (v2.68) outside Trust Wallet's release pipeline. The build exfiltrated wallet mnemonics via a hijacked analytics channel (SlowMist: modification of the wallet's own analytics code, not a poisoned dependency). ~2,520 wallets drained, ~$7M+ stolen. The mobile app was never involved. Trust Wallet shipped v2.69 within hours, expired all release keys, and committed to fully reimbursing affected users — "User funds are SAFU," per CZ.
Did Trust Wallet reimburse the hack victims?
Yes — voluntary full reimbursement was announced immediately and a claims process opened: ~2,520 verified affected addresses against >5,000 submitted claims (the vendor noted duplicate/fraudulent submissions in the count). CZ publicly committed "TrustWallet will cover." It is one of the cleaner response-and-compensation records in this corpus's incident set — the comparison set is Unibot's $1.78M refund and Coinbase's 2021 reimbursement, and Trust Wallet's sits in the same column.
Is the Trust Wallet mobile app safer than the extension?
By this incident's evidence, yes — the attack was specific to the browser extension's release pipeline and the extension's ability to enumerate every stored wallet. The mobile app shares neither property. The deeper point is structural: a browser extension is a hot surface with a vendor-controlled update channel — exactly the layer that got weaponized — so the corpus-standard advice applies: extension for spending, mobile or hardware for holding.
Who owns Trust Wallet?
Binance — it has owned Trust Wallet since 2018. Practically this cuts both ways: the wallet inherits the phishing target painted on crypto's biggest brand (fake Trust Wallet apps/support are constant), and it inherits the parent's demonstrated reimbursement capacity — the Dec-2025 payout commitment came from the same playbook as Binance's own SAFU fund. The wallet itself remains non-custodial: Binance doesn't hold your keys, your phrase, or a recovery path.
Can Trust Wallet see or recover your keys?
No — it is non-custodial; keys and the recovery phrase are generated and stored on your device only. There is no account-recovery path: lose the phrase and the wallet is unrecoverable by design. The corollary is the real risk: whoever obtains the phrase obtains everything, which is why the Dec-2025 malware went straight at the extension's stored mnemonic — and why "we never ask for your phrase" is the standing rule for every legitimate Trust Wallet surface.
Is Trust Wallet safe to keep using after the incident?
The honest answer splits by surface. For the mobile app: nothing in the incident touched it — same standing risks as any self-custody hot wallet. For the extension: the company demonstrated a real fix-and-pay loop (clean release in hours, all publishing keys rotated, full reimbursement), which is the strongest available evidence short of never being hit. The residual question the incident leaves is the release-pipeline trust model — a leaked API key beat internal review once; the rotated-key, tightened-controls posture is now the documented counter.