Trust Wallet confirms second Shai-Hulud supply-chain attack, $8.5M in crypto stolen

Trust Wallet confirms second Shai-Hulud supply-chain attack, $8.5M in crypto stolen

Pierluigi Paganini
January 01, 2026

Trust Wallet says a second Shai-Hulud supply-chain attack likely compromised its Chrome extension, leading to the theft of about $8.5M in crypto.

Trust Wallet linked a second Shai-Hulud supply-chain attack to its Chrome extension hack, which resulted in the theft of about $8.5 million in crypto assets.

The investigation reveals that the attacker independently developed and published a malicious Trust Wallet extension (v2.68) using a leaked Chrome Web Store API key, likely tied to the November SHA-1 Hulud supply-chain incident, which enabled the…

Source link