Plugin Wallet Security Incident Overview: Plagued by Fake Software and Phishing Attacks, Fewer Direct Official Vulnerabilities
BlockBeats News, December 26: This morning, Trust Wallet, the largest non-custodial cryptocurrency wallet by user base, issued a security alert confirming a security vulnerability in browser extension version 2.68. On-chain detective ZachXBT revealed that hundreds of Trust Wallet users have had their funds stolen, with losses totaling at least $6 million. Trust Wallet has been downloaded over 2 billion times, with approximately 17 million monthly active users, holding about 35% market share, making this security incident far-reaching. A look back at security incidents encountered by several mainstream browser extensions:
In November 2022, Trust Wallet's browser extension was found to have a WebAssembly vulnerability, affecting only new wallet addresses created between November 14 and 23, 2022. Approximately $170,000 was stolen. Trust Wallet discovered the issue through a bug bounty program, fixed the vulnerability, and fully compensated affected users.
In 2022, MetaMask experienced the "Demonic" vulnerability, impacting older versions before 10.11.3, where private keys could be exposed in the browser's memory. However, no significant fund losses were reported. Subsequently, from 2023 to 2025, MetaMask's official wallet extension operated securely but was frequently targeted by counterfeit extension programs. A Chainalysis report indicated a surge in MetaMask user abnormal theft events in 2025, mainly due to counterfeit malicious software and phishing rather than inherent plugin wallet security. MetaMask now releases monthly security reports, but as a popular Ethereum plugin wallet, it remains a prime target for counterfeiting.
In 2022, Phantom (the primary Solana wallet extension) also faced the "Demonic" vulnerability, with no known significant fund losses. Early 2025 saw a security controversy involving the Phantom wallet extension, where a user lost $500,000 due to private keys being in clear text in memory, leading to a hacker attack and resulting in a class-action lawsuit filed in a southern district court of New York. Phantom's official statement strongly denied all allegations, stating that the lawsuit was "baseless" and emphasizing that Phantom is a non-custodial wallet, placing the responsibility for fund security on the user.
In 2022, Rabby Wallet (a DeFi-friendly extension) suffered a hack where approximately $200,000 in encrypted assets were stolen due to a Rabby Swap vulnerability, which was not from the plugin itself but from the built-in Swap feature.
The most common theft method for browser extension wallets is through counterfeit application downloads. In 2025, there were multiple concentrated outbreaks of such incidents in the Firefox store, affecting several popular crypto extension wallets such as MetaMask, Phantom, and Trust Wallet. On the other hand, direct official vulnerabilities of the extensions are less common. It is recommended that users only download from the official Chrome Web Store to ensure the security of their funds.
You may also like
AI Trading's Ultimate Test: Empower Your AI Strategy with Tencent Cloud to Win $1.88M & a Bentley
AI traders! Win $1.88M & a Bentley by crushing WEEX's live-market challenge. Tencent Cloud powers your AI Trading bot - can it survive the Feb 9 finals?

Russia’s Largest Bitcoin Miner BitRiver Faces Bankruptcy Crisis – What Went Wrong?
Key Takeaways BitRiver, the largest Bitcoin mining operator in Russia, faces a bankruptcy crisis due to unresolved debts…

Polymarket Predicts Over 70% Chance Bitcoin Will Drop Below $65K
Key Takeaways Polymarket bettors forecast a 71% chance for Bitcoin to fall below $65,000 by 2026. Strong bearish…

BitMine Reports 4.285M ETH Holdings, Expands Staked Position With Massive Reward Outlook
Key Takeaways BitMine Immersion Technologies holds 4,285,125 ETH, which is approximately 3.55% of Ethereum’s total supply. The company…

US Liquidity Crisis Sparked $250B Crash, Not a ‘Broken’ Crypto Market: Analyst
Key Takeaways: A massive $250 billion crash shook the cryptocurrency markets, attributed largely to liquidity issues in the…

Vitalik Advocates for Anonymous Voting in Ethereum’s Governance — A Solution to Attacks?
Key Takeaways Vitalik Buterin proposes a two-layer governance framework utilizing anonymous voting to address collusion and capture attacks,…

South Korea Utilizes AI to Pursue Unfair Crypto Trading: Offenders Face Severe Penalties
Key Takeaways South Korea is intensifying its use of AI to crack down on unfair cryptocurrency trading practices.…

Average Bitcoin ETF Investor Turns Underwater After Major Outflows
Key Takeaways: U.S. spot Bitcoin ETFs hold approximately $113 billion in assets, equivalent to around 1.28 million BTC.…

Japan’s Biggest Wealth Manager Adjusts Crypto Strategy After Q3 Setbacks
Key Takeaways Nomura Holdings, Japan’s leading wealth management firm, scales back its crypto involvement following significant third-quarter losses.…

CFTC Regulatory Shift Could Unlock New Opportunities for Coinbase Prediction Markets
Key Takeaways: The U.S. Commodity Futures Trading Commission (CFTC) is focusing on clearer regulations for crypto-linked prediction markets,…

Hong Kong Set to Approve First Stablecoin Licenses in March — Who’s In?
Key Takeaways Hong Kong’s financial regulator, the Hong Kong Monetary Authority (HKMA), is on the verge of approving…

BitRiver Founder and CEO Igor Runets Detained Over Tax Evasion Charges
Key Takeaways: Russian authorities have detained Igor Runets, CEO of BitRiver, on allegations of tax evasion. Runets is…

Crypto Investment Products Struggle with $1.7B Outflows Amid Market Turmoil
Key Takeaways: The recent $1.7 billion outflow in the crypto investment sector represents a second consecutive week of…

Why Is Crypto Down Today? – February 2, 2026
Key Takeaways: The crypto market has seen a downturn today, with a significant decrease of 2.9% in the…

Nevada Court Temporarily Bars Polymarket From Offering Contracts in the State
Key Takeaways A Nevada state court has temporarily restrained Polymarket from offering event contracts in the state, citing…

Bitcoin Falls Below $80K As Warsh Named Fed Chair, Triggers $2.5B Liquidation
Key Takeaways Bitcoin’s price tumbled below the crucial $80,000 mark following the announcement of Kevin Warsh as the…

Strategy’s Bitcoin Holdings Face $900M in Losses as BTC Slips Below $76K
Key Takeaways Strategy Inc., led by Michael Saylor, faces over $900 million in unrealized losses as Bitcoin price…

Trump-Linked Crypto Company Secures $500M UAE Investment, Sparking Conflict Concerns
Key Takeaways A Trump-affiliated crypto company, World Liberty Financial, has garnered $500 million from UAE investors, igniting conflict…
AI Trading's Ultimate Test: Empower Your AI Strategy with Tencent Cloud to Win $1.88M & a Bentley
AI traders! Win $1.88M & a Bentley by crushing WEEX's live-market challenge. Tencent Cloud powers your AI Trading bot - can it survive the Feb 9 finals?
Russia’s Largest Bitcoin Miner BitRiver Faces Bankruptcy Crisis – What Went Wrong?
Key Takeaways BitRiver, the largest Bitcoin mining operator in Russia, faces a bankruptcy crisis due to unresolved debts…
Polymarket Predicts Over 70% Chance Bitcoin Will Drop Below $65K
Key Takeaways Polymarket bettors forecast a 71% chance for Bitcoin to fall below $65,000 by 2026. Strong bearish…
BitMine Reports 4.285M ETH Holdings, Expands Staked Position With Massive Reward Outlook
Key Takeaways BitMine Immersion Technologies holds 4,285,125 ETH, which is approximately 3.55% of Ethereum’s total supply. The company…
US Liquidity Crisis Sparked $250B Crash, Not a ‘Broken’ Crypto Market: Analyst
Key Takeaways: A massive $250 billion crash shook the cryptocurrency markets, attributed largely to liquidity issues in the…
Vitalik Advocates for Anonymous Voting in Ethereum’s Governance — A Solution to Attacks?
Key Takeaways Vitalik Buterin proposes a two-layer governance framework utilizing anonymous voting to address collusion and capture attacks,…