Lookonchain APP

App Store

Plugin Wallet Security Incident Overview: Plagued by Counterfeit Software and Phishing Attacks, Direct Official Vulnerabilities Are Few

5 hours ago

December 26th — Trust Wallet issued a security alert this morning confirming a vulnerability in its browser extension (version 2.68). On-chain detective ZachXBT reports hundreds of users have already had funds stolen, with total losses hitting at least $6 million. Below are key security incidents involving major browser extension wallets: ### Trust Wallet (2022) Back in November 2022, Trust Wallet’s extension had a WebAssembly vulnerability affecting only new addresses created between Nov 14–23, 2022. The flaw led to ~$170k in stolen funds. Trust Wallet found the issue via its bug bounty program, patched it, and fully compensated affected users. ### MetaMask - **2022**: Faced a “Demonic” vulnerability (versions before 10.11.3) that exposed private keys in browser memory — no large-scale losses reported. - **2023–2025**: Official extension operated securely, but it’s often targeted by fake versions. A 2025 Chainalysis report noted a spike in abnormal thefts, driven mostly by counterfeit malware and phishing (not the wallet itself). - **Current**: MetaMask publishes monthly security reports on this, but as a top Ethereum plugin wallet, it remains a key counterfeit target. ### Phantom (Solana’s main wallet) - **2022**: Also had the “Demonic” vulnerability — no major losses reported. - **Early 2025**: A controversy arose after a user lost $500k when private keys were stored unencrypted in memory (leading to a hack). A class-action lawsuit was filed in the Southern District of New York. Phantom’s team denied all claims, calling the lawsuit “baseless” and noting Phantom is non-custodial (users bear fund security responsibility). ### Rabby Wallet (DeFi-focused) - **2022**: Hacked via a flaw in its Rabby Swap feature, leading to ~$200k in stolen crypto. The issue wasn’t with the extension itself, but the built-in swap tool. ### Key Takeaway The most common way extension wallets get compromised is via fake downloads. In 2025, multiple such incidents hit the Firefox store, targeting major wallets like MetaMask, Phantom, and Trust Wallet. Direct official vulnerabilities are far rarer. **Advice**: Only download extension wallets from the official Chrome Web Store to protect your funds.
Relevant content

Upbit will list zkPass (ZKP)

Per an official announcement on December 26, Upbit will list zkPass (ZKP).

3 minutes ago

The "BTC OG Insider Whale" has paid over $2.9 million in funding fees, with an unrealized loss of $41.8 million

December 26th, per monitoring from HyperInsight (via their Telegram channel @HyperInsight), the "BTC OG Insider Whale" still holds a combined $755.48 million in long positions across BTC, ETH, and SOL. The whale has an unrealized loss of $41.8 million total, plus $2.936 million in paid funding fees. Current positions break down as follows: - Long $603.7 million in ETH, entry price $3,147.39, unrealized loss $35.62 million; - Long $88.82 million in BTC, entry price $91,506.7, unrealized loss $2.61 million; - Long $62.96 million in SOL, entry price $130.19, unrealized loss $3.57 million.

3 minutes ago

Bithumb to List ZKP

On December 26, per an official announcement, Bithumb is set to list ZKP.

3 minutes ago

Current mainstream CEX and DEX funding rate displays market shifting back to full bearish mode

December 26 – Coinglass data shows funding rates across major centralized (CEX) and decentralized (DEX) exchanges have again shifted to a full bearish outlook, with specific rates for top coins detailed in the attached image. BlockBeats Note: Funding rates are fees set by crypto exchanges to align perpetual contract prices with underlying asset values. They function as a fund transfer mechanism between long and short traders—exchanges themselves do not collect this fee. The rate adjusts traders’ holding costs or profits to keep contract prices close to the underlying asset. A 0.01% rate is the baseline: rates above 0.01% signal a broadly bullish market, while rates below 0.005% indicate bearish sentiment.

3 minutes ago

Moody's Chief Economist: While Fed Rate Cut Next Year Is Possible, Patience Is Needed

December 26 – Moody’s Chief Economist Mark Zandi said the Federal Reserve may cut interest rates multiple times in 2026—not because of economic prosperity, but because he views the U.S. economy as in a delicate balance. Zandi noted this dynamic signals a gradual, cautious rate path ahead, rather than an aggressive rate-cut cycle. Inflation has also complicated the Fed’s rate-cut outlook. Zandi argues the consumer price index (CPI) is closer to 3% than the central bank’s 2% target, slowing policymakers’ ability to act. Official data supports his assessment: U.S. CPI rose 2.7% year-over-year in November 2025 (core CPI at 2.6%), still above the Fed’s goal. “Inflation remains well above the level the Fed wants to see,” Zandi said. “While upside surprises are still possible, risks are two-sided.” (Source: FX Street)

3 minutes ago

Solana's On-Chain Meme Coin WhiteWhale Market Cap Surpasses $18 Million, Reaching an All-Time High

Dec 26 — Solana-based meme coin WhiteWhale has hit a record market capitalization, surpassing $18 million, according to data from GMGN. As of the latest figures, its market cap stands at $18.44 million, with a 24-hour gain of 33.82%. BlockBeats reminds users that meme coin trading is highly volatile, often driven by market sentiment and hype, and lacks tangible value or real-world use cases. Investors should exercise caution and be aware of the associated risks.

3 minutes ago