Plugin Wallet Security Incident Overview: Plagued by Fake Software and Phishing Attacks, Fewer Direct Official Vulnerabilities
BlockBeats News, December 26: This morning, Trust Wallet, the largest non-custodial cryptocurrency wallet by user base, issued a security alert confirming a security vulnerability in browser extension version 2.68. On-chain detective ZachXBT revealed that hundreds of Trust Wallet users have had their funds stolen, with losses totaling at least $6 million. Trust Wallet has been downloaded over 2 billion times, with approximately 17 million monthly active users, holding about 35% market share, making this security incident far-reaching. A look back at security incidents encountered by several mainstream browser extensions:
In November 2022, Trust Wallet's browser extension was found to have a WebAssembly vulnerability, affecting only new wallet addresses created between November 14 and 23, 2022. Approximately $170,000 was stolen. Trust Wallet discovered the issue through a bug bounty program, fixed the vulnerability, and fully compensated affected users.
In 2022, MetaMask experienced the "Demonic" vulnerability, impacting older versions before 10.11.3, where private keys could be exposed in the browser's memory. However, no significant fund losses were reported. Subsequently, from 2023 to 2025, MetaMask's official wallet extension operated securely but was frequently targeted by counterfeit extension programs. A Chainalysis report indicated a surge in MetaMask user abnormal theft events in 2025, mainly due to counterfeit malicious software and phishing rather than inherent plugin wallet security. MetaMask now releases monthly security reports, but as a popular Ethereum plugin wallet, it remains a prime target for counterfeiting.
In 2022, Phantom (the primary Solana wallet extension) also faced the "Demonic" vulnerability, with no known significant fund losses. Early 2025 saw a security controversy involving the Phantom wallet extension, where a user lost $500,000 due to private keys being in clear text in memory, leading to a hacker attack and resulting in a class-action lawsuit filed in a southern district court of New York. Phantom's official statement strongly denied all allegations, stating that the lawsuit was "baseless" and emphasizing that Phantom is a non-custodial wallet, placing the responsibility for fund security on the user.
In 2022, Rabby Wallet (a DeFi-friendly extension) suffered a hack where approximately $200,000 in encrypted assets were stolen due to a Rabby Swap vulnerability, which was not from the plugin itself but from the built-in Swap feature.
The most common theft method for browser extension wallets is through counterfeit application downloads. In 2025, there were multiple concentrated outbreaks of such incidents in the Firefox store, affecting several popular crypto extension wallets such as MetaMask, Phantom, and Trust Wallet. On the other hand, direct official vulnerabilities of the extensions are less common. It is recommended that users only download from the official Chrome Web Store to ensure the security of their funds.
You may also like

Guarding billions in assets, yet unable to sustain itself: Tally bids a dignified farewell after five years

SEC’s Stance on Crypto Assets: Most Not Considered Securities
Key Takeaways: The SEC’s new interpretation categorizes most crypto assets as non-securities under federal law. This move aims…

South Korea’s New Crypto Seizure Guidelines After Asset Mismanagement Incidents
Key Takeaways: South Korea’s National Police Agency (KNPA) has drafted guidelines for crypto seizure, with a focus on…

Institutional Confidence in Crypto’s 2026 Growth Trajectory
Key Takeaways: A significant 73% of institutional investors plan to increase their crypto holdings by 2026. Exchange-traded products…

Ethereum Reduces Bridge Times by 98% with Fast Confirmation Rule
Key Takeaways: Ethereum introduces the Fast Confirmation Rule (FCR) aiming to cut bridge times from L1 to L2…

Crypto Firms Advocate DeFi Education in US Colleges
Key Takeaways: Twenty-one crypto organizations have called on US colleges to integrate decentralized finance (DeFi) into their curricula…

RedotPay Reorganizes Amidst Funding Tries and IPO Goals
Key Takeaways: RedotPay is facing leadership changes and concerns over its connections with mainland China while eyeing a…

Bitcoin ETF Streak Nears October Highs While Inflows Lag Behind
Key Takeaways: US spot Bitcoin ETFs have continued their inflow streak for seven straight days, accumulating $1.2 billion…

Connecticut Suspends Bitcoin Depot as Revenue Prospects for 2026 Worsen
Key Takeaways: Connecticut halts Bitcoin Depot’s operations, citing regulatory breaches related to the Money Transmission Act. Bitcoin Depot…

DAO Governance Platform Tally Shuts Down Due to Market Challenges
Key Takeaways: Tally, after operating for five years, is shutting down due to a lack of viable business…

Trump Memecoin Shows Volatility Amid Mar-a-Lago Event
Key Takeaways: TRUMP memecoin holders surpassed 83 wallets with over one million tokens after a luncheon announcement with…

Bitcoin Surge in Australian E-commerce Faces Banking Hurdles: In-depth Analysis
Key Takeaways: Cryptocurrency usage in Australia for purchasing goods and services doubled from 6% to 12% in 2026.…

Meta Shuts Down Horizon Worlds VR for Mobile-Centric Strategy
Key Takeaways: Meta is transitioning Horizon Worlds from a VR to a mobile-centric platform starting June 2026. The…

Bitcoin Exchange Inflows Surge Amidst $75,000 Resistance
Key Takeaways: Bitcoin inflows to exchanges have spiked to 6,100 BTC, hinting at potential selling pressure. The large…

Bitrefill Identifies Lazarus Group Behind Cyberattack and Stolen Funds
Key Takeaways: Bitrefill suffered a cyberattack on March 1, likely orchestrated by the infamous Lazarus Group using sophisticated…

Coin Center Advocates for Rulemaking Over No-Action Letters in Crypto Regulation
Key Takeaways: Coin Center challenges the SEC’s reliance on no-action letters, promoting a shift toward comprehensive rulemaking in…

On the eve of the Fed meeting, are traders starting to bet on a rate hike?

Can AI Make $200 a Day with Weather Forecasting?
Guarding billions in assets, yet unable to sustain itself: Tally bids a dignified farewell after five years
SEC’s Stance on Crypto Assets: Most Not Considered Securities
Key Takeaways: The SEC’s new interpretation categorizes most crypto assets as non-securities under federal law. This move aims…
South Korea’s New Crypto Seizure Guidelines After Asset Mismanagement Incidents
Key Takeaways: South Korea’s National Police Agency (KNPA) has drafted guidelines for crypto seizure, with a focus on…
Institutional Confidence in Crypto’s 2026 Growth Trajectory
Key Takeaways: A significant 73% of institutional investors plan to increase their crypto holdings by 2026. Exchange-traded products…
Ethereum Reduces Bridge Times by 98% with Fast Confirmation Rule
Key Takeaways: Ethereum introduces the Fast Confirmation Rule (FCR) aiming to cut bridge times from L1 to L2…
Crypto Firms Advocate DeFi Education in US Colleges
Key Takeaways: Twenty-one crypto organizations have called on US colleges to integrate decentralized finance (DeFi) into their curricula…