• Bitcoin(BTC)$63,602.00
  • Ethereum(ETH)$2,491.88
  • Tether(USDT)$1.00
  • BNB(BNB)$574.20
  • Solana(SOL)$149.95
  • USDC(USDC)$1.00
  • XRP(XRP)$0.54
  • Lido Staked Ether(STETH)$2,490.73
  • Dogecoin(DOGE)$0.113987
  • Toncoin(TON)$5.34

Crypto wallet Trust Wallet disclosed a security vulnerability that resulted in nearly 170,000 losses for some users. The vulnerability has been patched, according to the company.

Trust Wallet found out about the issue through its bug bounty program. A security researcher reported a WebAssembly (WASM) vulnerability in the open-source library Wallet Core in November 2022. New wallet addresses generated “between November 14 and 23, 2022 by Browser Extension contain this vulnerability,” said the company in a statement, adding that all addresses created before and after those dates are safe.

The breach resulted in two exploits that led to a total loss of nearly $170,000. Approximately 500 vulnerable addresses remain with an $88,000 balance, according to a postmortem report. Affected users will be offered a refund and gas fee assistance to cover the costs of fund transfers. According to Trust Wallet:

“We want to assure users that we will reimburse eligible losses from hacks due to the vulnerability and have created a reimbursement process for the affected users. And we urged affected users to move the remaining ~$88,000 USD balance on all the vulnerable addresses as soon as possible.”

Users who experienced abnormal fund movement in late December 2022 and late March 2023 may be among the victims affected by the two exploits.

The company urged affected customers to create a new wallet and transfer funds. Users with vulnerable addresses will be notified through the Trust Wallet browser extension, said the company. For developers who used Wallet Core library in 2022, the latest version should be implemented. Affected wallet addresses from Binance were previously notified through the crypto exchange.

Another recently unveiled exploit drained almost $11 million in nonfungible tokens (NFTs) and cryptocurrencies from various addresses across 11 blockchains since December last year, targeting veterans in the crypto community. The attack was initially attributed to an exploit in the MetaMask wallet, which was later denied by the company.

Magazine: ‘Account abstraction’ supercharges Ethereum wallets: Dummies guide


Source: Cointelegraph.com

Crypto Investing Risk Warning

Crypto assets are highly volatile. Your capital is at risk.
Don’t invest unless you’re prepared to lose all the money you invest.
This is a high-risk investment, and you should not expect to be protected if something goes wrong.

Read the full disclaimer

Newsletter

Sign up to receive the latest crypto breaking news in your inbox, every day.

I agree that my data is used according to the privacy policy

Check your inbox or spam folder to confirm your subscription.

Breaking crypto news about Bitcoin, Ethereum, Blockchain, NFTs, DeFi and Altcoins. Get instant notifications 24/7 as soon as a new article is published.

Exit mobile version