Summary
Trust Wallet is a widely-used non-custodial mobile and browser cryptocurrency wallet, originally acquired by Binance in 2018 and later divested as an independent entity. It has been the subject of multiple documented security incidents spanning 2022–2025, including a critical WebAssembly entropy vulnerability (CVE-2024-23660), a supply-chain compromise of its Chrome extension in December 2025 that resulted in approximately $8.5 million in user losses, and a historical low-entropy key generation flaw exploited in 2023. Blockchain investigator ZachXBT flagged the December 2025 browser extension incident and documented hundreds of victims.
Connected Entities
1 entities- + 5 more
Timeline(15 events)
2018-02-01
Trust Wallet iOS app introduces low-entropy key generation flaw using trezor-crypto-ios v0.0.4, seeding PRNG with Unix timestamp only
2018-07-16
Low-entropy flaw patched in trezor-crypto-ios v0.0.7, but wallets created during the vulnerable window remain exposed
2022-11-14
Trust Wallet browser extension begins generating wallets using weak Mersenne Twister PRNG; vulnerability window opens
2022-11-23
Browser extension WebAssembly vulnerability window closes; researcher later discloses flaw via bug bounty
2023-04-22
Trust Wallet publicly discloses WebAssembly PRNG vulnerability, confirms $170,000 in user losses, announces reimbursement
2023-07-12
Attackers exploit 2018-era low-entropy iOS flaw against 2,100+ Ethereum addresses; over 1,360 ETH stolen across multiple chains
2024-02-01
NIST formally adds Trust Wallet iOS vulnerability to National Vulnerability Database as CVE-2024-23660 (CVSS 7.5 High)
2025-01-01
TrustWalletPanel phishing operation (tttadmin.com) begins 14-month campaign targeting Trust Wallet users; at least $239,000 stolen
2025-11-01
Sha1-Hulud supply chain attack exposes Trust Wallet GitHub secrets, including Chrome Web Store API credentials
2025-12-24
Malicious Trust Wallet browser extension v2.68 published to Chrome Web Store via leaked API key; mnemonic exfiltration begins
Decision Log
- hash: 2MsWpDZZNjK6KHVWbjSF663H12ZF3Q9ZZCjxvrBpvowm
- hash: 2eK2drxTgarTZ5JKdztYXnbESAwDss8Hy1pXBGrXuanu
- hash: 91Y1D8dvMX6Wq93K3eyRTP2QopR1b8bvBgeeK9c5tJWc
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet
generated: 5/4/2026, 2:54:19 AM
last updated: 6/14/2026, 11:15:56 PM
avoid.net — verified advice for a post-truth world