Trust Wallet Vulnerability Leads to $170,000 Loss

0

[ad_1]

Trust Wallet reported a WebAssembly (WASM) vulnerability that led to the loss of $170,000.

In an April 22 statement, the crypto wallet provider revealed that the vulnerability affected wallets generated by its browser extension between Nov. 14 – 23, 2022. An unnamed security researcher reported the vulnerability in November 2022 through the Trust Wallet bug bounty program.

The company said it delayed this disclosure to prevent immediate attacks and reduce potential breaches. Despite the delay, the vulnerability was exploited twice and led to a loss of around $170,000.

However, this vulnerability does not affect Trust Wallet mobile app users or those who imported their wallets into the browser extension. It also does not affect those who created new wallet addresses via the extension before Nov. 14 or after Nov. 23, 2022. 

Meanwhile, Trust Wallet added that the vulnerability was unrelated to the one MyCrypto founder Taylor Monahan reported. Monahand had claimed that about 5000 ETH was stolen from numerous users’ wallets recently.

Trust Wallet to Reimburse Affected Users

The Binance-backed wallet assured that it would refund impacted users’ stolen funds. The firm said it created a reimbursement system that would notify these users via notifications through their browser extensions.

Trust Wallet further warned that there was still about $88,000 in some vulnerable addresses. The team urged users with these addresses to withdraw their funds immediately.

Following the incident, Trust Wallet said it increased its security audits and audit coverage over the last few months to five times more to prevent a recurrence.

Crypto-Related Exploits Are Rising

Following a quiet start to the year, crypto exploits have picked up steam in the past few weeks, starting with a Euler Finance hack in March.

DeFi protocols like Allbridge, Sentiment, Hundred Finance, and Yearn Finance were exploited during the first two weeks of April. According to DeFillama data, these attacks resulted in more than $20 million in losses.

Crypto exploits in April
Crypto Exploits in April (Source: DeFillama)

Wired recently reported that North Korea-backed hackers used a software supply-Chain attack to target and exploit some crypto companies. The report noted that these hackers were hiding malicious codes in the installer for a VoIP application known as 3CX. 

Disclaimer

In adherence to the Trust Project guidelines, BeInCrypto is committed to unbiased, transparent reporting. This news article aims to provide accurate, timely information. However, readers are advised to verify facts independently and consult with a professional before making any decisions based on this content.

[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 0.000000
ethereum
Ethereum (ETH) $ 0.000000
tether
Tether (USDT) $ 0.000000
bnb
BNB (BNB) $ 0.000000
xrp
XRP (XRP) $ 0.000000
usd-coin
USDC (USDC) $ 0.000000
solana
Wrapped SOL (SOL) $ 0.000000
staked-ether
Lido Staked Ether (STETH) $ 0.000000
tron
TRON (TRX) $ 0.000000
dogecoin
Dogecoin (DOGE) $ 0.000000
cardano
Cardano (ADA) $ 0.000000
figure-heloc
Figure Heloc (FIGR_HELOC) $ 0.000000
whitebit
WhiteBIT Coin (WBT) $ 0.000000
wrapped-steth
Wrapped stETH (WSTETH) $ 0.000000
bitcoin-cash
Bitcoin Cash (BCH) $ 0.000000
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 0.000000
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 0.000000
usds
USDS (USDS) $ 0.000000
chainlink
Chainlink (LINK) $ 0.000000
wrapped-eeth
Wrapped eETH (WEETH) $ 0.000000
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.000000
leo-token
LEO Token (LEO) $ 0.000000
weth
WETH (WETH) $ 0.000000
hyperliquid
Hyperliquid (HYPE) $ 0.000000
stellar
Stellar (XLM) $ 0.000000
monero
Monero (XMR) $ 0.000000
zcash
Zcash (ZEC) $ 0.000000
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 0.000000
ethena-usde
Ethena USDe (USDE) $ 0.000000
litecoin
Litecoin (LTC) $ 0.000000
sui
Sui (SUI) $ 0.000000
avalanche-2
Avalanche (AVAX) $ 0.000000
hedera-hashgraph
Hedera (HBAR) $ 0.000000
shiba-inu
Shiba Inu (SHIB) $ 0.000000
susds
sUSDS (SUSDS) $ 0.000000
usdt0
USDT0 (USDT0) $ 0.000000
dai
Dai (DAI) $ 0.000000
mantle
Mantle (MNT) $ 0.000000
the-open-network
Toncoin (TON) $ 0.000000
world-liberty-financial
World Liberty Financial (WLFI) $ 0.000000
paypal-usd
PayPal USD (PYUSD) $ 0.000000
crypto-com-chain
Cronos (CRO) $ 0.000000
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 0.000000
uniswap
Uniswap (UNI) $ 0.000000
polkadot
Polkadot (DOT) $ 0.000000
memecore
MemeCore (M) $ 0.000000
aave
Aave (AAVE) $ 0.000000
bittensor
Bittensor (TAO) $ 0.000000
usd1-wlfi
USD1 (USD1) $ 0.000000
canton-network
Canton (CC) $ 0.000000
Shares