Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Trust Wallet Chrome Extension Hack Drains $8.5M via Shai-Hulud Supply Chain Attack

Posted on December 31, 2025December 31, 2025 By CWS

Dec 31, 2026Ravie LakshmananSoftware Safety / Information Breach
Belief Pockets on Tuesday revealed that the second iteration of the Shai-Hulud (aka Sha1-Hulud) provide chain outbreak in November 2025 was possible accountable for the hack of its Google Chrome extension, in the end ensuing within the theft of roughly $8.5 million in belongings.
“Our Developer GitHub secrets and techniques have been uncovered within the assault, which gave the attacker entry to our browser extension supply code and the Chrome Internet Retailer (CWS) API key,” the corporate mentioned in a autopsy revealed Tuesday.
“The attacker obtained full CWS API entry through the leaked key, permitting builds to be uploaded immediately with out Belief Pockets’s commonplace launch course of, which requires inside approval/guide assessment.”

Subsequently, the attacker is claimed to have registered the area “metrics-trustwallet[.]com” and pushed a trojanized model of the extension with a backdoor that is able to harvesting customers’ pockets mnemonic phrases to the sub-domain “api.metrics-trustwallet[.]com.”
The disclosure comes days after Belief Pockets urged about a million customers of its Chrome extension to replace to model 2.69 after a malicious replace (model 2.68) was pushed by unknown menace actors on December 24, 2025, to the browser’s extension market.
The safety incident in the end led to $8.5 million in cryptocurrency belongings being drained from 2,520 pockets addresses to a minimum of 17 pockets addresses managed by the attacker. The primary wallet-draining exercise was publicly reported a day after the malicious replace.
Belief Pockets has since initiated a reimbursement declare course of for impacted victims. The corporate famous that critiques of submitted claims are ongoing and are being dealt with on a case-by-case foundation. It additionally confused that processing occasions might range with every case because of the want to differentiate between victims and dangerous actors, and additional shield towards fraud.
To stop such breaches from occurring once more, Belief Pockets mentioned it has carried out further monitoring capabilities and controls associated to its launch processes.

“Sha1-Hulud was an industry-wide software program provide chain assault that affected firms throughout a number of sectors, together with however not restricted to crypto,” the corporate mentioned. “It concerned malicious code being launched and distributed by means of commonly-used developer tooling. This allowed attackers to realize entry by means of trusted software program dependencies relatively than immediately concentrating on particular person organizations.”
Belief Pockets’s disclosure coincides with the emergence of Shai-Hulud 3.0 with elevated obfuscation and reliability enhancements, whereas nonetheless remaining laser-focused on stealing secrets and techniques from developer machines.
“The first distinction lies in string obfuscation, error dealing with, and Home windows compatibility, all geared toward growing marketing campaign longevity relatively than introducing novel exploitation strategies,” Upwind researchers Man Gilad and Moshe Hassan mentioned.

The Hacker News Tags:8.5M, Attack, Chain, Chrome, Drains, Extension, Hack, ShaiHulud, Supply, Trust, Wallet

Post navigation

Previous Post: DarkSpectre Browser Extension Campaigns Exposed After Impacting 8.8 Million Users Worldwide
Next Post: Self-Propagating GlassWorm Weaponizing VS Code Extensions to Attack macOS Users

Related Posts

Smishing Triad Linked to 194,000 Malicious Domains in Global Phishing Operation The Hacker News
Hazy Hawk Exploits DNS Records to Hijack CDC, Corporate Domains for Malware Delivery The Hacker News
Learn How to Build a Reasonable and Legally Defensible Cybersecurity Program The Hacker News
Qilin Ransomware Turns South Korean MSP Breach Into 28-Victim ‘Korean Leaks’ Data Heist The Hacker News
LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds The Hacker News
175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Expose All User Records from Popular Dark Web Forum
  • China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines
  • xRAT Malware Attacking Windows Users Disguised as Adult Game
  • Fog Ransomware Attacking US Organizations Leveraging Compromised VPN Credentials
  • In Other News: 8,000 Ransomware Attacks, China Hacked US Gov Emails, IDHS Breach Impacts 700k

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Expose All User Records from Popular Dark Web Forum
  • China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines
  • xRAT Malware Attacking Windows Users Disguised as Adult Game
  • Fog Ransomware Attacking US Organizations Leveraging Compromised VPN Credentials
  • In Other News: 8,000 Ransomware Attacks, China Hacked US Gov Emails, IDHS Breach Impacts 700k

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark