Trust Wallet review: safe after the extension breach?
We tested the mobile app and the browser extension behind Trust Wallet, checked its multi-chain self-custody model against the December 2025 Chrome extension incident that drained user seed phrases, and asked what actually changed.
7.5out of 107.5
Our verdict
Trust Wallet's mobile app remains what it has always been: a genuinely broad self-custody wallet across more than 100 chains, with private keys held on the device and a Security Scanner that checks transactions before you sign. The Chrome extension is a different story. A malicious update to version 2.68 in December 2025 transmitted seed phrases to an attacker's server and drained 2,520 wallets for roughly $8.5 million before Trust Wallet caught it, pushed a fix, and began reimbursing victims. Mobile-only users were never exposed. Anyone running the browser extension should treat it as the higher-risk half of this product and keep it current.
Best for: Multi-chain mobile users who skip the browser extension or keep it updated without exception
Trust Wallet is the wallet most people already have installed without thinking much about it: over 100 chains, a free download, and private keys that never leave the phone. We used it across several chains for weeks, then went back through exactly what happened when its Chrome extension got compromised in December 2025, because a wallet this widely installed is only as safe as its weakest surface.
What the app itself gets right
Moving assets between Bitcoin, Ethereum, Solana and BNB Smart Chain from one interface, without juggling separate wallets per network, is still Trust Wallet's core pitch, and it works the way it claims to. Swaps, staking, an NFT view and a built-in dApp browser all sit inside the same app, and none of it requires handing custody to Trust Wallet itself: the keys are generated and held on the device.
Trust Wallet's App Store page: a 4.7-star rating built on a very large, mostly mobile, install base
That mobile install base is large, reflected in a 4.7 out of 5 rating on the Apple App Store and 4.6 out of 5 on Google Play. A Security Scanner sits in front of transactions and dApp connections, checking a contract or destination against known risk signals before you sign, which the company says now covers over 200 million users across the app. We found it caught a flagged token contract during testing without slowing down an ordinary swap.
Onboarding is quick enough that a first-time user can be holding assets within minutes: install, generate or import a wallet, and the app defaults straight into its swap and staking screens rather than burying them behind a settings menu. Fiat on-ramps route through third-party providers rather than Trust Wallet itself processing card payments, which keeps the app's own custody surface small but means pricing and available payment methods vary by which partner handles a given country.
The Security Scanner's own page tells the story it wants told
Trust Wallet's marketing around security leans hard on the Scanner and on the phrase "your keys, your crypto," and on the page where the company makes that case, the framing is unmistakably defensive for a wallet that has had a real incident in its history.
Trust Wallet's security page: the Scanner feature framed as the centerpiece of the wallet's protection
None of the claims on that page are false. The Scanner is a real, useful feature, and the core mobile app has not been the source of a fund-draining incident. But the page frames security as a solved problem, and the extension breach below shows that framing needs a caveat the marketing page does not volunteer on its own.
What actually happened in December 2025
On December 24, 2025, Trust Wallet shipped Chrome extension version 2.68 with malicious code embedded in it, the result of a compromised update pipeline rather than a flaw in the extension's original design. The code transmitted users' seed phrases to an external server, and attackers used that access to drain 2,520 wallet addresses for roughly $8.5 million before the company caught it and pushed version 2.69 as a fix.
Trust Wallet's incident page: the company's own account of the compromised extension update and its response
The extension had roughly one million users on the Chrome Web Store at the time, meaning most installs were never touched, but the 2,520 that were lost real money to a supply-chain failure in the update process itself, not to a user mistake. Trust Wallet's response afterward is worth crediting on its own terms: the company published a public incident page, walked through what affected users should do, and committed to reimbursing victims rather than disputing the loss. Mobile app users, and anyone running a browser extension version other than 2.68, were confirmed unaffected throughout.
What we would actually do with it
For a mobile-only user, this incident does not touch the product you are using, and the core wallet remains a solid, broadly supported self-custody option with a real security feature in the Scanner rather than a marketing label. We would keep using it on that basis without hesitation.
For anyone running the browser extension, the lesson is narrower but sharper: a browser extension's attack surface includes its own update pipeline, not just the code you can audit once, and that risk does not disappear because the company caught this particular breach and paid people back. Keep the extension current, watch for Trust Wallet's own incident communications rather than assuming silence means safety, and treat a browser extension holding real value with more suspicion than you would a mobile-only setup. We would not avoid Trust Wallet over one caught and remediated incident, but we would not run the extension carelessly either.
What we liked
Self-custody across 100+ blockchains from a single app, keys never leave the device
Built-in Security Scanner flags risky contracts and transactions before you sign
4.7/5 on the Apple App Store and 4.6/5 on Google Play across a large user base
Trust Wallet reimbursed victims of the extension breach rather than disputing liability
What held it back
December 2025 Chrome extension v2.68 shipped malicious code that stole seed phrases
The breach drained 2,520 wallets for about $8.5 million before it was caught
The attack targeted the extension's own update pipeline, a supply-chain weakness
Self-custody means no recovery path if a device is lost without a backed-up seed phrase
Specs
Chains supported
100+ blockchains
Platforms
iOS, Android and a Chrome/browser extension
Custody model
Non-custodial; private keys stored on-device
Extension incident
v2.68, malicious code active December 24, 2025 to fix in v2.69