After years of crawling and fighting in the industry, I’ve seen many storms, but this time, a hacker incident involving a popular wallet browser extension still sends chills down my spine—an official version turned into an intrusion tool. This blow has awakened many to their reliance on the “security illusion.”



**Timeline: Carefully Crafted Christmas Hijacking**

The story begins on December 8. The hacker registered a spoofed domain api.metrics-trustwallet[.]com and lay in wait for two weeks without action. On December 22, a tampered version v2.68.0 was pushed out through official channels.

By Christmas Day, the fund transfers began. On-chain tracking expert ZachXBT’s monitoring data shows that within just a few days, at least $6 million to $7 million in crypto assets vanished, affecting hundreds of users.

**The Hacker’s True Cleverness**

This isn’t a brute-force server intrusion. The hacker inserted a seemingly harmless PostHog data analytics tool into the code—something wallet companies commonly use in their daily operations. But this tool left a backdoor: when users recharge and reopen the wallet, it quietly steals their mnemonic phrases.

This is a textbook case of supply chain attack. Instead of hacking the server, the attacker poisoned the official distribution channels—tricking users into handing over their private keys to thieves.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 4
  • Repost
  • Share
Comment
0/400
SchrodingersFOMOvip
· 7h ago
I'm not there, we can't trust anything, right? Even the official channels can be compromised, this is bad. The dog coefficient has risen again. Damn, this technique is perfect. The trap in PostHog is really deep. Next time, I won't click on anything. I'm really shocked this time. Over 6 million USD just disappeared, what else can we do? Official channels have been compromised, who can we trust now? This blow to the supply chain was too harsh, impossible to guard against. Christmas hijacking, this hacker's mind is really sharp. I've always said not to trust wallets too much, and now it's true. The theft of the mnemonic phrase, just thinking about it is terrifying. Now I have to mess around and change wallets again, so annoying.
View OriginalReply0
GrayscaleArbitrageurvip
· 7h ago
Wow, I can't believe even the official channels are not trusted anymore. What's the point of playing around? Wait, the PostHog backdoor move is indeed brilliant. I need to check my version number. Don't tell me I also got infected. I did update during those Christmas days... It's just ridiculous. Trust is like this now. In the future, I need to deploy across multiple chains. This hacker really put in effort, lying in wait for two weeks before striking. Their professionalism is on point.
View OriginalReply0
StakeOrRegretvip
· 7h ago
Damn, 6 to 7 million just disappeared like that, Christmas gift turned into Christmas hijacking. Once again, supply chain poisoning. I thought the official version was a fortress. That backdoor in PostHog is really something, too ruthless. This time I have to learn my lesson; cold wallets are the real boss.
View OriginalReply0
RadioShackKnightvip
· 7h ago
$6,000,000 to $7,000,000 just disappeared like that, still starting from the official version, damn this technique is really clever --- Official channels can't even hold on, what can we expect then --- PostHog backdoor move I need to remember, this hacker is too ruthless --- Christmas hijacking funds... even screenwriters wouldn't dare write this --- Waited two weeks before striking, this patience is stronger than my coin holding --- Hundreds of people were robbed, ZachXBT caught them, what else can be done --- Losing the mnemonic phrase like this, no matter how many layers of encryption, it's useless --- The official itself has become the biggest intrusion tool, ironic --- Supply chain is truly Web3's Achilles' heel, no matter how you defend, you can't prevent it --- By the way, is anyone still running version v2.68.0 now?
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)