라이브 중
🚀 ZNS 토큰 사전 판매 라이브! 최대 50% 보너스 토큰 획득지금 구매
ZELF
Zelf

서비스

zWallet

셀프 커스터디, 복구 및 키

zKeys

비밀번호 관리자

zSignals

트레이딩 시그널 및 인사이트

탐색

$ZNS

토큰 구매

Zelf ID

아이덴티티 레이어 참여

리워드

받고 $ZNS 토큰 획득

NFT 마켓플레이스

NFT 발견 및 수집

회사

블로그

뉴스 및 기사

미션 및 토크노믹스

비전과 이코노미

마스터 플랜

로드맵과 미래

보안

HumanAuthn

생체 인식 신원 레이어

개발 문서

가이드 및 API 레퍼런스

Zelf ID 레지스트리

온체인 이름 등록

GitHub 웹 확장 프로그램

오픈 소스 코드

GitHub 온라인 버전

오픈 소스 코드

🇰🇷 ko
다운로드
블로그로 돌아가기
securitytrust-walletsupply-chainnpmbrowser-extension

Trust Wallet의 850만 달러 악몽: Shai-Hulud 공급망 공격의 내막

손상된 NPM 패키지로 인한 악성 Chrome 확장 프로그램이 2,500개 이상의 지갑에서 850만 달러를 빼냈습니다.

Miguel Treviño•1월 24, 2026
Trust Wallet의 850만 달러 악몽: Shai-Hulud 공급망 공격의 내막

TL;DR:

  • The Attack: A malicious NPM package ("Shai-Hulud 2.0") compromised Trust Wallet's Chrome extension, draining $8.5M from 2,500+ users.
  • The Vulnerability: Software supply chain attacks target developers' GitHub and App Store credentials, injecting malicious code directly into auto-updated software.
  • The Risk of Extensions: Browser-based wallets are uniquely vulnerable to exfiltration due to their broad permissions and seamless (but dangerous) auto-updates.
  • The Zelf Solution: Zelf’s mobile-first design and ZK Face Proof authentication eliminate seed-phrase storage entirely—preventing exfiltration even if a supply chain compromise occurs.
On Christmas Eve 2025, someone pushed a malicious update to Trust Wallet's Chrome extension.
Within days, over $8.5 million had been stolen from more than 2,500 wallets. The victims did nothing wrong—they simply had an auto-updated browser extension.

The Attack Vector

This wasn't a zero-day exploit or a smart contract hack. It was a supply chain attack targeting the software development pipeline.
The chain of events:
  1. Shai-Hulud 2.0: A massive supply chain attack compromised thousands of NPM packages
  2. Credential theft: Attackers obtained Trust Wallet's GitHub secrets and Chrome Web Store API keys
  3. Malicious release: Version 2.68 was pushed directly to the Chrome Web Store, bypassing review
  4. Seed phrase exfiltration: The malicious code silently sent wallet data to attacker-controlled servers

Why This Is Terrifying

This attack exposed a fundamental vulnerability in the crypto ecosystem: the software supply chain.
Every crypto wallet, exchange, and DeFi protocol depends on:
  • NPM packages (JavaScript libraries)
  • GitHub repositories (source code)
  • Browser extension stores (distribution)
  • CI/CD pipelines (automated builds)
Compromise any link in that chain, and you can inject malicious code into software used by millions.

What Was Stolen

The attackers made off with:
  • ~$3 million in Bitcoin
  • ~$3 million in Ethereum
  • $431 in Solana
  • Additional amounts in various altcoins
The funds were quickly moved through exchanges and cross-chain bridges. Most will never be recovered.

Trust Wallet's Response

To their credit, Trust Wallet acted quickly:
  • Revoked all compromised credentials
  • Released a clean version (2.69) within hours
  • Announced full reimbursement for affected users (backed by Binance)
  • Published detailed incident reports
CZ confirmed that Trust Wallet would cover all losses. But not every project has Binance's resources.

The Bigger Problem

This attack could have happened to any browser-based wallet:
  • MetaMask
  • Phantom
  • Rabby
  • Coinbase Wallet
All of them depend on the same vulnerable supply chain. All of them auto-update by default. All of them store sensitive data that malicious code could exfiltrate.

Why Browser Extensions Are Risky

Browser extensions operate in a uniquely dangerous environment:
  1. Broad permissions: They can read/modify web pages, access storage, intercept requests
  2. Auto-updates: New versions deploy automatically, often without user awareness
  3. Supply chain exposure: A single compromised dependency affects all users
  4. Limited sandboxing: Extensions share browser context with sensitive sites
Every time you install a browser extension wallet, you're trusting:
  • The development team
  • Every dependency they use
  • Every maintainer of those dependencies
  • The browser store review process
  • The security of their deployment infrastructure
That's a lot of trust.

The Zelf Difference

Zelf approaches security fundamentally differently:

1. Minimal Attack Surface

Our mobile-first architecture reduces supply chain exposure. Mobile apps have:
  • Stricter app store review processes
  • Better sandboxing between applications
  • No auto-update without user consent (for security-critical updates)

2. No Seed Phrase Storage

If there's no seed phrase to exfiltrate, malicious code can't steal it. ZK Face Proof authentication means:
  • Nothing sensitive stored on-device that could be extracted
  • Authentication happens through cryptographic proofs, not stored secrets

3. Biometric Non-Exportability

Your face can't be copied and sent to a remote server (in a usable form). Unlike text-based secrets, biometric authentication is inherently bound to you.

Lessons for Every Crypto User

  1. Minimize browser extensions: Every extension is an attack surface
  2. Disable auto-updates for security-critical software
  3. Use hardware separation: Keep serious holdings off browser-connected wallets
  4. Verify before trusting: Check extension versions against official announcements
  5. Consider alternatives: Mobile wallets with better security models

The Future of Wallet Security

The Trust Wallet incident proves that "non-custodial" doesn't mean "secure." Self-custody is only as safe as the software implementing it.
The next generation of wallets needs:
  • Zero-knowledge authentication that can't be exfiltrated
  • Hardware-backed security independent of software supply chains
  • Minimal trusted computing base to reduce attack surface
That's exactly what Zelf is building.
Experience Better Security | How ZK Face Proof Works
모든 게시물로 돌아가기

최신 소식을 받아보세요

암호화폐 보안, ZNS 업데이트, Web3 인사이트 최신 정보를 받아보세요.

제품

Zelf Wallet
  • Zelf vs Metamask
  • Zelf vs TrustWallet
  • Zelf vs Ledger
  • Zelf vs Ledger Recover
  • Zelf vs Trezor Keep Metal
  • Zelf vs 기타
  • BlockDAG용 지갑
  • Solana용 지갑
  • Stellar용 지갑
  • Sui용 지갑
ZelfKeys
  • 자체 보관 관리자
  • 비밀번호 없는 인증
  • Passkeys vs 자체 보관
  • 비밀번호 대안

리소스

회사

  • 블로그
  • 미션
  • 토큰노믹스
  • 마스터 플랜
  • 브랜드 에셋

보안

  • HumanAuthn
  • 개발자 문서
  • Zelf ID 레지스트리
  • Github Web Extension
  • Github Online version

법적 정보

  • 이용약관
  • 개인정보 처리방침

문의

  • 지원 미팅 예약
ZELF

© 2026 Zelf World, 모든 권리 보유.