Trust Wallet Confirms Browser Extension Vulnerability as Users Lose $6 Million

Trust Wallet issued a security alert on December 26 confirming a vulnerability in its browser extension version 2.68, with on-chain analyst ZachXBT reporting that hundreds of users have lost at least $6 million. The wallet previously faced a WebAssembly flaw affecting new addresses created between November 14 and 23, 2022, resulting in about $170,000 in losses that were later fully reimbursed through a bug bounty process. MetaMask and Phantom were both impacted by the "Demonic" vulnerability in 2022 without known large-scale fund losses, while Chainalysis reported a surge in MetaMask user thefts in 2025 mainly linked to fake malware extensions and phishing. Phantom was named in a 2025 class-action lawsuit in the Southern District of New York over a $500,000 loss that the project has strongly denied, and Rabby Wallet suffered around $200,000 in crypto asset theft in 2022 due to an issue in its Rabby Swap feature rather than the plugin itself.