Trust Wallet Hack: $8.5M Drained via Shai-Hulud Supply Chain Attack
These articles are AI-generated summaries. Please check the original sources for full details.
Trust Wallet Chrome Extension Hack
Trust Wallet confirmed a supply chain attack, linked to the Shai-Hulud campaign, compromised its Chrome extension, resulting in the theft of $8.5 million from 2,520 wallets. The attacker gained access through exposed GitHub secrets and used the Chrome Web Store API to deploy a malicious update.
Why This Matters
Ideal software development relies on secure dependencies and robust access controls, but real-world scenarios frequently expose vulnerabilities. The Trust Wallet incident highlights the catastrophic potential of supply chain attacks, where compromised components can lead to significant financial losses; in this case, $8.5 million in stolen cryptocurrency demonstrates the scale of potential damage.
Key Insights
- Shai-Hulud Campaign, 2025: A widespread software supply chain attack targeting multiple sectors, including cryptocurrency.
- GitHub Secrets Exposure: Leaked developer credentials enabled unauthorized access to source code and the Chrome Web Store API.
- Chrome Web Store API Abuse: Attackers bypassed standard release processes by directly uploading malicious builds using the compromised API key.
Practical Applications
- Use Case: Cryptocurrency wallet providers like Trust Wallet must implement stringent security measures for their browser extensions, including robust secret management and release validation.
- Pitfall: Relying solely on automated build and deployment pipelines without sufficient manual review and monitoring can create opportunities for attackers to inject malicious code.
References:
Continue reading
Next article
U.S. Treasury Removes Sanctions on Intellexa-Linked Individuals
Related Content
Trust Wallet Chrome Extension Hack Results in $7 Million Crypto Loss
Trust Wallet suffered a security breach in its Chrome extension v2.68, resulting in approximately $7 million in cryptocurrency losses for users.
Fake Chrome Extension 'Safery' Steals Ethereum Wallet Seed Phrases Using Sui Blockchain
Malicious Chrome extension 'Safery' exfiltrates Ethereum seed phrases via Sui blockchain microtransactions, still available as of November 2025.
npm Worm Shai-Hulud Strikes Again, Compromising 27,000 GitHub Repos
The Shai-Hulud npm worm resurfaces, stealing 3,760 valid secrets from 27,000 GitHub repositories in a supply chain attack.