Plugin Wallet Security Incident Overview: Plagued by Fake Software and Phishing Attacks, Fewer Direct Official Vulnerabilities
BlockBeats News, December 26: This morning, Trust Wallet, the largest non-custodial cryptocurrency wallet by user base, issued a security alert confirming a security vulnerability in browser extension version 2.68. On-chain detective ZachXBT revealed that hundreds of Trust Wallet users have had their funds stolen, with losses totaling at least $6 million. Trust Wallet has been downloaded over 2 billion times, with approximately 17 million monthly active users, holding about 35% market share, making this security incident far-reaching. A look back at security incidents encountered by several mainstream browser extensions:
In November 2022, Trust Wallet's browser extension was found to have a WebAssembly vulnerability, affecting only new wallet addresses created between November 14 and 23, 2022. Approximately $170,000 was stolen. Trust Wallet discovered the issue through a bug bounty program, fixed the vulnerability, and fully compensated affected users.
In 2022, MetaMask experienced the "Demonic" vulnerability, impacting older versions before 10.11.3, where private keys could be exposed in the browser's memory. However, no significant fund losses were reported. Subsequently, from 2023 to 2025, MetaMask's official wallet extension operated securely but was frequently targeted by counterfeit extension programs. A Chainalysis report indicated a surge in MetaMask user abnormal theft events in 2025, mainly due to counterfeit malicious software and phishing rather than inherent plugin wallet security. MetaMask now releases monthly security reports, but as a popular Ethereum plugin wallet, it remains a prime target for counterfeiting.
In 2022, Phantom (the primary Solana wallet extension) also faced the "Demonic" vulnerability, with no known significant fund losses. Early 2025 saw a security controversy involving the Phantom wallet extension, where a user lost $500,000 due to private keys being in clear text in memory, leading to a hacker attack and resulting in a class-action lawsuit filed in a southern district court of New York. Phantom's official statement strongly denied all allegations, stating that the lawsuit was "baseless" and emphasizing that Phantom is a non-custodial wallet, placing the responsibility for fund security on the user.
In 2022, Rabby Wallet (a DeFi-friendly extension) suffered a hack where approximately $200,000 in encrypted assets were stolen due to a Rabby Swap vulnerability, which was not from the plugin itself but from the built-in Swap feature.
The most common theft method for browser extension wallets is through counterfeit application downloads. In 2025, there were multiple concentrated outbreaks of such incidents in the Firefox store, affecting several popular crypto extension wallets such as MetaMask, Phantom, and Trust Wallet. On the other hand, direct official vulnerabilities of the extensions are less common. It is recommended that users only download from the official Chrome Web Store to ensure the security of their funds.
You may also like

On the eve of the Fed meeting, are traders starting to bet on a rate hike?

Can AI Make $200 a Day with Weather Forecasting?

The Pentagon and the Market Have Simultaneously Sentenced Anthropic | Rewire News Evening Report

Aster Deepens Strategic Partnership with WLFI, Launches USD1-Valued Perpetual Contract Market

Overnight, the crypto tycoons were severely played by Vanity Fair
Auto Earn Crypto Passive Income: Staking Rewards Up to 8% APR
Start earning crypto passive income with auto earn. Get up to 8% APR on BTC and higher yields on stablecoins. Compare staking rewards and maximize your returns today.

Interview with Hyperliquid Founder Jeff Yan: Crypto and DeFi Are in Our DNA, Never Compromising on Trust

$1 Billion Free Lottery, Kalshi Launches Prediction Challenge

SlowMist: Is it Really Safe to Entrust Your Money to an AI Agent like "Lobster"?

Regulation, Insiderism, and Essence: The Story Behind Kalshi's $20 Billion Valuation

You Have Been Training Google's AI for Free for 15 Years, and You Didn't Even Know
Best AI Crypto Trading Bot? Inside the AI Trading System That Ranked Top 3 on WEEX
Discover the best AI crypto trading bot on WEEX. Learn how AI trading works, how to trade automatically, and why this system stands out among top AI trading apps.

How to Trade Cryptocurrency Without App Store: Instant Browser Crypto Trading on WEEX
Trade crypto instantly without downloading an app. Use WEEX H5 to access spot and futures trading directly in your browser with fast execution, real-time risk control, and seamless experience across mobile, tablet, and desktop. Supports Bitcoin, Ethereum, and more.

From OKX to Bybit, exchanges are changing tires on the highway at high speed

A Brief History and Future of Perpetual Contracts

AI Agent Gets ID and Wallet on the Same Day | Rewire News Morning Brief

IOSG: Power Flexibility Paradigm Shift: From Macro Assets to Distributed Intelligence Layer

Murata 35% Price Increase Explained: A Capacitor that Gives AI Empire a Cold
On the eve of the Fed meeting, are traders starting to bet on a rate hike?
Can AI Make $200 a Day with Weather Forecasting?
The Pentagon and the Market Have Simultaneously Sentenced Anthropic | Rewire News Evening Report
Aster Deepens Strategic Partnership with WLFI, Launches USD1-Valued Perpetual Contract Market
Overnight, the crypto tycoons were severely played by Vanity Fair
Auto Earn Crypto Passive Income: Staking Rewards Up to 8% APR
Start earning crypto passive income with auto earn. Get up to 8% APR on BTC and higher yields on stablecoins. Compare staking rewards and maximize your returns today.