Plugin Wallet Security Incident Overview: Plagued by Fake Software and Phishing Attacks, Fewer Direct Official Vulnerabilities
BlockBeats News, December 26: This morning, Trust Wallet, the largest non-custodial cryptocurrency wallet by user base, issued a security alert confirming a security vulnerability in browser extension version 2.68. On-chain detective ZachXBT revealed that hundreds of Trust Wallet users have had their funds stolen, with losses totaling at least $6 million. Trust Wallet has been downloaded over 2 billion times, with approximately 17 million monthly active users, holding about 35% market share, making this security incident far-reaching. A look back at security incidents encountered by several mainstream browser extensions:
In November 2022, Trust Wallet's browser extension was found to have a WebAssembly vulnerability, affecting only new wallet addresses created between November 14 and 23, 2022. Approximately $170,000 was stolen. Trust Wallet discovered the issue through a bug bounty program, fixed the vulnerability, and fully compensated affected users.
In 2022, MetaMask experienced the "Demonic" vulnerability, impacting older versions before 10.11.3, where private keys could be exposed in the browser's memory. However, no significant fund losses were reported. Subsequently, from 2023 to 2025, MetaMask's official wallet extension operated securely but was frequently targeted by counterfeit extension programs. A Chainalysis report indicated a surge in MetaMask user abnormal theft events in 2025, mainly due to counterfeit malicious software and phishing rather than inherent plugin wallet security. MetaMask now releases monthly security reports, but as a popular Ethereum plugin wallet, it remains a prime target for counterfeiting.
In 2022, Phantom (the primary Solana wallet extension) also faced the "Demonic" vulnerability, with no known significant fund losses. Early 2025 saw a security controversy involving the Phantom wallet extension, where a user lost $500,000 due to private keys being in clear text in memory, leading to a hacker attack and resulting in a class-action lawsuit filed in a southern district court of New York. Phantom's official statement strongly denied all allegations, stating that the lawsuit was "baseless" and emphasizing that Phantom is a non-custodial wallet, placing the responsibility for fund security on the user.
In 2022, Rabby Wallet (a DeFi-friendly extension) suffered a hack where approximately $200,000 in encrypted assets were stolen due to a Rabby Swap vulnerability, which was not from the plugin itself but from the built-in Swap feature.
The most common theft method for browser extension wallets is through counterfeit application downloads. In 2025, there were multiple concentrated outbreaks of such incidents in the Firefox store, affecting several popular crypto extension wallets such as MetaMask, Phantom, and Trust Wallet. On the other hand, direct official vulnerabilities of the extensions are less common. It is recommended that users only download from the official Chrome Web Store to ensure the security of their funds.
You may also like

WEEX AI Trading Hackathon Finals: The World's Biggest AI Trading Competition Is Live
WEEX AI Trading Hackathon Finals are live. 37 finalists compete for $1M+ prizes & a Bentley Bentayga S. Hubble AI powers 10 finalists. Watch live PnL leaderboards and see who wins the ultimate AI trading competition.

Key Market Information Discrepancy on February 11th – A Must-See! | Alpha Morning Report

February 11 Market Key Intelligence, How Much Did You Miss?

Analyzing the Impact of Technological Trends in 2026
Key Takeaways The rapid evolution of technology continues to reshape industries, creating both opportunities and challenges. Understanding the…

Navigating Crypto Content Challenges in a Digital World
Key Takeaways Effective content management in the crypto industry involves addressing usage limits and optimizing resources. Staying informed…

Cryptocurrency Exchanges: Current Trends and Future Outlook
Key Takeaways The cryptocurrency exchange market continues to expand, influenced by various global economic trends. User experience and…

Untitled
I’m sorry, but I can’t generate a rewritten article without access to specific content for rewriting. If you…

Crypto Market Dynamics: An In-depth Overview
Market fluctuations provide insights into the volatility and dynamics of cryptocurrency trading. Key market participants play significant roles…

Predicting High-Frequency Trading Strategies in the Market, How to Ensure a Guaranteed $100,000 Profit?

This might be the average person's final opportunity to get ahead of AI

A Day Gathering Wall Street's Old Money: LayerZero's "Mainnet Transition" Narrative

Full Text of CZ's New Interview: From Ordinary Programmer to Richest Chinese, Involvement with FTX, Going to Jail, Doing Charity, Publishing a Book, What is CZ Focus on Now?

Mr. Beast is officially entering the world of finance, the Gen Z's new banker

SBF Appeals from Prison, Files 35-Page Motion Accusing Trial of "Collusion"

Robinhood 2025 Report Card: Earned $45 Billion, Why Did the Stock Price Drop by Half?

$1M+ AI Trading Finals: Hubble AI & WEEX Spotlight the Future of Crypto Trading
The WEEX AI Trading Hackathon Finals are now live, featuring real-time PnL leaderboards, daily rankings, and in-depth AMA sessions. Explore how top AI trading strategies perform under real market volatility and follow the competition as it unfolds.

WEEX Alpha Awakens Final Round Has Officially Begun
Day 1 of the WEEX AI Trading Hackathon Final Round is now live! Watch top algorithmic trading strategies compete with real capital. Follow the action from Feb 3–16, 2026, with $880K+ in prizes. Tune in live now. #AITrading #TradingHackathon

WLFI Team Meeting, Ally Meeting, Seaside Villa Cryptocurrency Business Kickoff
WEEX AI Trading Hackathon Finals: The World's Biggest AI Trading Competition Is Live
WEEX AI Trading Hackathon Finals are live. 37 finalists compete for $1M+ prizes & a Bentley Bentayga S. Hubble AI powers 10 finalists. Watch live PnL leaderboards and see who wins the ultimate AI trading competition.
Key Market Information Discrepancy on February 11th – A Must-See! | Alpha Morning Report
February 11 Market Key Intelligence, How Much Did You Miss?
Analyzing the Impact of Technological Trends in 2026
Key Takeaways The rapid evolution of technology continues to reshape industries, creating both opportunities and challenges. Understanding the…
Navigating Crypto Content Challenges in a Digital World
Key Takeaways Effective content management in the crypto industry involves addressing usage limits and optimizing resources. Staying informed…
Cryptocurrency Exchanges: Current Trends and Future Outlook
Key Takeaways The cryptocurrency exchange market continues to expand, influenced by various global economic trends. User experience and…