#数字资产市场动态 Another major incident—A leading browser wallet plugin has revealed a serious vulnerability



A few days ago, I saw a news report that a top wallet Chrome extension, backed by major institutions, version 2.68, experienced a crash. After the December 24 update, users began to report funds being transferred out gradually. Mainstream coins like BTC, ETH, and SOL were all affected, with total losses exceeding $7 million, impacting hundreds of wallets.

What's the most outrageous part? As long as you import your seed phrase in version 2.68, transfers are executed automatically without any prompt. You can't even react in time. Even more bizarre, the mobile app remains safe and unaffected; only the browser plugin has issues. The wallet team urgently advised users to disable version 2.68 immediately and upgrade to 2.69. The management also issued a statement promising full compensation to affected users.

My take on this: A wallet endorsed by top institutions should not have such a severe security flaw. There are two possible reasons—either there are overlooked blind spots in the code audit, or the supply chain has been compromised (for example, third-party dependencies being tainted). While the compensation promise sounds good, this incident has already caused substantial damage to the brand. Paying out $7 million is easy, but regaining user trust will be much harder.

My advice: If you're using this wallet's browser plugin, whether you've been affected or not, move your assets to a hardware wallet or another trusted hot wallet now. Wait for the official investigation to determine the true cause. When it comes to security, it's better to be overly cautious than to gamble with luck.
BTC-0.83%
ETH-1.04%
SOL-1.23%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 6
  • Repost
  • Share
Comment
0/400
GateUser-00be86fcvip
· 4h ago
Big institutional endorsements can't save this wave either; how could the code audit still be so flawed? --- 7 million is gone, and compensation can't restore trust either. --- I always said browser plugins are the least secure; it was about time to switch entirely to hardware wallets. --- V2.68 auto-transfers as soon as it’s released? That's not a bug, that's giving away tokens. --- How can I not be nervous when upgrading to 2.69? Who dares to trust again? --- Supply chain contamination is really hard to prevent; you have to stay vigilant yourself. --- Another crash site—when will this circle finally be able to rest assured? --- Just compensate? What about the trust of those hundreds of users lost? --- Would you still dare to use browser plugin wallets in the future? That's the lesson learned. --- Investing with top-tier institutions doesn't work either; no one can truly guarantee security.
View OriginalReply0
BitcoinDaddyvip
· 4h ago
Damn, 7 million USD just gone like that? Even big institutions backing it can't stop such a ridiculous vulnerability, it's hilarious. --- This is outrageous, automatic transfers? No reaction time at all? --- Honestly, losing money is easy, but once trust is broken, it's very hard to put back together. --- I think, for sure, there was a failure in the audit. How could such a big wallet make this kind of mistake? --- Hurry up and move the coins to a hardware wallet. Being cautious never hurts, anyway, I'm just idling. --- The app on the phone is fine, but the browser plugin had issues? That's pretty interesting, the supply chain might really be compromised. --- Wallets and vulnerabilities again, too many scams in the past two years, gotta learn a lesson. --- Full compensation sounds good, but the confidence level has already dropped too low to look at. --- I just want to know if this is a code problem or someone sabotaged it; both options aren't optimistic. --- Anyway, I don't trust this version anymore. Wait for the official investigation before making any moves.
View OriginalReply0
ShadowStakervip
· 4h ago
ngl, supply chain compromise on browser extensions is genuinely my nightmare scenario. audit theater doesn't catch this stuff.
Reply0
PanicSeller69vip
· 4h ago
I am a scared bird in the crypto circle, always thinking everyone is about to run away. No matter how much compensation is offered, trust cannot be regained. --- 7 million USD? Uh... this is the real "flash loan," right? The direction is all wrong. --- Damn, again supply chain contamination? Feels like there are more vulnerabilities now than new coins. --- Has the hardware wallet price increased? Hurry up and stock one to ease the nerves. --- If even the wallets of top institutional investors can be compromised, who can I trust? Self-management is the way to go. --- Entering the mnemonic phrase automatically triggers a transfer? That design is really brilliant. What happened to user experience? --- The compensation promise sounds great, but I just want to know when the money will arrive. Don’t make me wait another half a year. --- Being endorsed for security capabilities like this? Are they hinting that I should sell off? --- The mobile app crashes while browsing on the browser—can you understand this logic? Feels like there are too many black-box operations. --- I stopped trusting top projects a long time ago; the most valuable thing in this circle is people's hearts.
View OriginalReply0
SocialAnxietyStakervip
· 4h ago
Coming again? I told you not to put your coins in the browser, and now look at this. Don't expect any compensation or anything; trust is not that easy to repair.
View OriginalReply0
ForkMastervip
· 4h ago
Endorsements from leading institutions can't prevent the pitfalls of code audits, and 7 million is gone just like that. I've said before that supply chain contamination is hard to prevent; it requires a team with white-hat backgrounds. Hardware wallets are the way to go. It's better to be a bit more trouble than to gamble on this.
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)