The recent disclosure by Trust Wallet of a massive hack of its Chrome extension highlights the scale and growing sophistication of supply‑chain attacks. The company confirmed that the second wave of the Shai‑Hulud attack, which emerged at the end of 2025, is responsible for the theft of nearly $8.5 million in cryptocurrencies. The incident originated from the exposure of internal GitHub secrets, which gave attackers direct access to the extension’s source code as well as the Chrome Web Store API key. Thanks to this compromise, the cybercriminals were able to publish a modified version of the extension themselves, completely bypassing the usual internal validation processes.
A successful attack enabled by typosquatting
The attackers then registered the domain metrics‑trustwallet[.]com to distribute a trojanized version of the extension, embedding a backdoor capable of siphoning users’ mnemonic phrases. The malicious code triggered every time the wallet was unlocked, even when the user was not handling their seed phrase. According to Koi’s analysis, all wallets configured in the extension were compromised, and the secret phrases were quietly inserted into a field named errorMessage, hidden within what looked like simple analytics telemetry.
The domain used for the attack pointed to infrastructure hosted by Stark Industries Solutions, a hosting provider known for its tolerance of cybercriminal activity and already linked to operations supported by Russian state‑aligned actors. Researchers also noted a strange response when directly querying the server: “He who controls the spice controls the universe,” a Dune reference previously observed in other Shai‑Hulud variants. Server metadata shows that the infrastructure was ready as early as December 8, well before the malicious update was pushed on December 24, confirming a planned—not opportunistic—attack.
The impact was immediate: around one million users were prompted to update the extension to version 2.69, while the compromised version, 2.68, had already allowed attackers to drain 2,520 wallets into 17 addresses under their control. Trust Wallet has launched a reimbursement process, but each case must be reviewed individually to prevent fraud, which lengthens processing times.
The company emphasizes that Shai‑Hulud is not an isolated attack but a large‑scale supply‑chain incident affecting multiple sectors. The malware spreads through widely used development tools, allowing it to bypass traditional defenses by exploiting the trust placed in software dependencies. Version 3.0 of the malware, recently observed, shows stronger obfuscation and improved Windows compatibility—clear signs that the attackers aim to extend the lifespan of their campaigns.
Why monitoring is essential
In this case, one key point stands out: the importance of monitoring domains, associated infrastructure, and the weak signals that often precede an attack. The fraudulent domain used in the operation could have been detected much earlier if automated monitoring had been in place. A solution like Vigidomaine would have immediately spotted the suspicious registration, DNS changes, and abnormal activity around this domain, enabling alerts before the compromised extension was distributed. With continuous visibility over sensitive domains, the incident could have been anticipated—or even prevented.
Vigidomaine provides your monitoring
To prevent this type of scenario from happening again, it is essential to have a tool capable of detecting these signals in real time. Vigidomaine offers this capability, and you can test it for free right now to strengthen your security and anticipate threats before they turn into incidents.
Source: https://thehackernews.com/2025/12/trust-wallet-chrome-extension-hack.html

