Trust Wallet 浏览器扩展
Search documents
吴说每日精选加密新闻 - Trust Wallet 浏览器扩展遭攻击,损失约 700 万美元
Xin Lang Cai Jing· 2025-12-27 15:37
Group 1 - Trust Wallet browser extension version 2.68 experienced a security breach, resulting in approximately $7 million in assets stolen from hundreds of user wallets, with some funds flowing into platforms like ChangeNOW, FixedFloat, and KuCoin. The vulnerability was exploited for several days before being publicly disclosed, and Trust Wallet has released version 2.69 to address the issue, promising full compensation to affected users [1] - Sberbank, Russia's largest bank, is considering launching a loan service backed by cryptocurrency, allowing digital assets to be used as collateral for ruble loans. The bank's vice chairman, Anatoly Popov, stated that they are prepared to collaborate with regulators to advance the necessary infrastructure and hope to discuss related transactions soon [1] - Russian President Putin mentioned that discussions are ongoing with the United States regarding the management of the Zaporizhzhia nuclear power plant, with the U.S. expressing interest in using the plant's electricity for Bitcoin mining. The Zaporizhzhia plant is the largest in Europe and the ninth largest globally, currently managed by Russia's state atomic energy corporation Rosatom [1] Group 2 - Japan's tax reform outline for fiscal year 2026 proposes to gradually classify cryptocurrencies as "financial products that contribute to national asset formation," exploring the introduction of separate taxation for gains from spot, derivatives, and ETF trading, along with a loss carryforward mechanism for up to three years. However, not all crypto transactions will fall under the new system, as staking, lending income, and NFT transactions may still be subject to comprehensive taxation, with specific applicability and execution details pending further legislation and regulation [2] - The Bank of Lithuania has warned that domestic cryptocurrency service providers must obtain licenses by December 31 or be considered illegal operators facing penalties. The transitional period for compliance for crypto exchanges and wallet platforms will end in 2025, and starting January 1, any unauthorized activities will be deemed illegal financial operations, potentially leading to fines, website bans, or up to four years of imprisonment. Currently, only about 30 institutions have submitted license applications, while over 370 local crypto service providers are registered, with around 120 still actively operating [2]
Trust Wallet 安全事件:钱包安全升级竟然可以变成风险开关?
Xin Lang Cai Jing· 2025-12-26 15:55
Core Insights - Trust Wallet's browser extension version 2.68 has encountered a security incident, leading to potential exposure of sensitive information such as mnemonic phrases during normal usage after an automatic update from version 2.67 [1][2] - The incident highlights a structural issue within the industry, where users are compelled to update software to maintain security, yet such updates can introduce new risks [2][3] Industry Challenges - Users face a dilemma: they must update to fix known vulnerabilities but risk introducing new threats through compromised updates [3] - The reliance on a single wallet provider's development and distribution process raises concerns about centralization risks, contradicting the principles of decentralization [4] User Defense Strategies - Users can mitigate risks by adjusting their asset management and operational habits, focusing on two core principles: reducing exposure and increasing verification thresholds [5][6] - Implementing a tiered wallet system can help isolate core assets from potential threats, allowing users to test new updates with minimal risk [10][11][12] Proposed Solutions - The "Test Mouse" strategy involves using a separate wallet for small amounts of funds to test new software updates before applying them to primary wallets [8][9] - A multi-signature wallet approach can enhance security by requiring multiple approvals for transactions, thus reducing the risk of single-point failures [15][16][18]