Plugin Wallet Security Incident Overview: Plagued by Fake Software and Phishing Attacks, Fewer Direct Official Vulnerabilities
BlockBeats News, December 26: This morning, Trust Wallet, the largest non-custodial cryptocurrency wallet by user base, issued a security alert confirming a security vulnerability in browser extension version 2.68. On-chain detective ZachXBT revealed that hundreds of Trust Wallet users have had their funds stolen, with losses totaling at least $6 million. Trust Wallet has been downloaded over 2 billion times, with approximately 17 million monthly active users, holding about 35% market share, making this security incident far-reaching. A look back at security incidents encountered by several mainstream browser extensions:
In November 2022, Trust Wallet's browser extension was found to have a WebAssembly vulnerability, affecting only new wallet addresses created between November 14 and 23, 2022. Approximately $170,000 was stolen. Trust Wallet discovered the issue through a bug bounty program, fixed the vulnerability, and fully compensated affected users.
In 2022, MetaMask experienced the "Demonic" vulnerability, impacting older versions before 10.11.3, where private keys could be exposed in the browser's memory. However, no significant fund losses were reported. Subsequently, from 2023 to 2025, MetaMask's official wallet extension operated securely but was frequently targeted by counterfeit extension programs. A Chainalysis report indicated a surge in MetaMask user abnormal theft events in 2025, mainly due to counterfeit malicious software and phishing rather than inherent plugin wallet security. MetaMask now releases monthly security reports, but as a popular Ethereum plugin wallet, it remains a prime target for counterfeiting.
In 2022, Phantom (the primary Solana wallet extension) also faced the "Demonic" vulnerability, with no known significant fund losses. Early 2025 saw a security controversy involving the Phantom wallet extension, where a user lost $500,000 due to private keys being in clear text in memory, leading to a hacker attack and resulting in a class-action lawsuit filed in a southern district court of New York. Phantom's official statement strongly denied all allegations, stating that the lawsuit was "baseless" and emphasizing that Phantom is a non-custodial wallet, placing the responsibility for fund security on the user.
In 2022, Rabby Wallet (a DeFi-friendly extension) suffered a hack where approximately $200,000 in encrypted assets were stolen due to a Rabby Swap vulnerability, which was not from the plugin itself but from the built-in Swap feature.
The most common theft method for browser extension wallets is through counterfeit application downloads. In 2025, there were multiple concentrated outbreaks of such incidents in the Firefox store, affecting several popular crypto extension wallets such as MetaMask, Phantom, and Trust Wallet. On the other hand, direct official vulnerabilities of the extensions are less common. It is recommended that users only download from the official Chrome Web Store to ensure the security of their funds.
You may also like

President Trump Asserts Imminent Passing of Crypto Market Structure Bill
Key Takeaways Presidential Confirmation: President Trump states the major crypto market structure bill is on the verge of…

Germany Central Bank Head Advocates for European Crypto Stablecoins Under EU MiCA Framework
Key Takeaways Joachim Nagel, head of the Germany Bundesbank, is advocating for the adoption of euro-based crypto stablecoins…

Polygon Surpasses Ethereum in Daily Fees as Polymarket Bets Rocket
Key Takeaways Polygon has outpaced Ethereum in daily transaction fees, a historic shift driven by activity on Polymarket.…

Bitcoin Price Prediction: BTC Short Squeeze Alert – Is a Significant Rebound on the Horizon?
Key Takeaways Recent data indicates Bitcoin shorts have escalated to unprecedented levels reminiscent of a major market low…

Google’s Gemini AI Predicts the Price of XRP, Solana, and Bitcoin by the End of 2026
Key Takeaways XRP’s Potential: Google’s Gemini AI forecasts XRP could reach $10 by 2026, leveraging Ripple’s payment solutions…

Top Analyst Warns Bitcoin Price Could Plummet to $10,000 Amid Deepening Bear Market
Key Takeaways Bitcoin’s value could potentially drop to $10,000 as part of an imploding bubble, suggests a renowned…

Best Crypto to Buy Now February 10 – XRP, Solana, Dogecoin
Key Takeaways XRP is poised for long-term growth with its recent strategic expansions in institutional-grade payments and tokenization.…

Kyle Samani Criticizes Hyperliquid in Explosive Post-Departure Market Commentary
Key Takeaways: Kyle Samani, after leaving Multicoin Capital, criticized Hyperliquid, a decentralized exchange, labeling it as a systemic…

XRP Price Prediction: A 50M Token Sell-Off Just Shook the Market — Is More Loss Imminent?
Key Takeaways Over 50 million XRP hit the market within a span of less than 12 hours, leading…

Strategy Plans to Equitize Convertible Debt Over 3–6 Years: What It Means for BTC
Key Takeaways Strategy, led by Michael Saylor, is equitizing $6 billion in convertible debt as a long-term strategy…

BlockFills Freezes Withdrawals as Bitcoin Declines, Heightening Counterparty Risk Concerns
Key Takeaways BlockFills, an institutional trading firm, has stopped client withdrawals amid rising market volatility and Bitcoin price…

Leading AI Claude Predicts the Price of XRP, Cardano, and Ethereum by the End of 2026
Key Takeaways Claude AI projects substantial growth for XRP, Cardano, and Ethereum by the end of 2026, with…

Crypto Price Forecast for 16 February – XRP, Ethereum, Cardano
Key Takeaways Technical trends and recent developments suggest potential growth for XRP, Ethereum, and Cardano. XRP is targeting…

Bitcoin Price Prediction: Alarming New Research Warns Millions in BTC at Risk of ‘Quantum Freeze’ – Are You Protected?
Key Takeaways Recent market movements have sparked concerns over a potential bear market for Bitcoin, marked by significant…

XRP Price Forecast: Can XRP Truly Surpass Bitcoin and Ethereum? Analyst Argues the Contest Has Already Begun
Key Takeaways XRP has maintained significant support around the $1.40 level despite a 12% decline over the past…

Best Crypto to Purchase Now February 6 – XRP, Solana, Bitcoin
Key Takeaways XRP’s Strength: Ripple’s focus on challenging traditional systems like SWIFT is driving XRP towards a potential…

South Korea Intensifies Crypto Market Investigations Following Bithumb Incident
Key Takeaways A $44 billion mishap at Bithumb has prompted South Korean authorities to step up their scrutiny…

BTC Traders Eye $50K as Possible Bottom: Key Metrics to Watch This Week
Key Takeaways Bitcoin’s price fluctuations lead traders to eye $50,000 as a critical bottom. Despite a recent rally…
President Trump Asserts Imminent Passing of Crypto Market Structure Bill
Key Takeaways Presidential Confirmation: President Trump states the major crypto market structure bill is on the verge of…
Germany Central Bank Head Advocates for European Crypto Stablecoins Under EU MiCA Framework
Key Takeaways Joachim Nagel, head of the Germany Bundesbank, is advocating for the adoption of euro-based crypto stablecoins…
Polygon Surpasses Ethereum in Daily Fees as Polymarket Bets Rocket
Key Takeaways Polygon has outpaced Ethereum in daily transaction fees, a historic shift driven by activity on Polymarket.…
Bitcoin Price Prediction: BTC Short Squeeze Alert – Is a Significant Rebound on the Horizon?
Key Takeaways Recent data indicates Bitcoin shorts have escalated to unprecedented levels reminiscent of a major market low…
Google’s Gemini AI Predicts the Price of XRP, Solana, and Bitcoin by the End of 2026
Key Takeaways XRP’s Potential: Google’s Gemini AI forecasts XRP could reach $10 by 2026, leveraging Ripple’s payment solutions…
Top Analyst Warns Bitcoin Price Could Plummet to $10,000 Amid Deepening Bear Market
Key Takeaways Bitcoin’s value could potentially drop to $10,000 as part of an imploding bubble, suggests a renowned…