A hacker group from China posing as a cybersecurity firm has allegedly stolen 7 million dollars via wallet supply‑chain attacks, targeting Trust Wallet and otherA hacker group from China posing as a cybersecurity firm has allegedly stolen 7 million dollars via wallet supply‑chain attacks, targeting Trust Wallet and other

China hacker group leaks $7M crypto theft operation targeting wallet supply chains​

2026/03/18 05:00
3 min read
For feedback or concerns regarding this content, please contact us at [email protected]

A hacker group from China posing as a cybersecurity firm has allegedly stolen 7 million dollars via wallet supply‑chain attacks, targeting Trust Wallet and other clients before an internal dispute triggered a whistleblower leak.

Summary
  • Operating under Wuhan Anshun Technology, the group presented itself as a security outfit while allegedly using Electron apps, browser plugins, and remote‑control tools to exfiltrate mnemonics and drain wallets across Ethereum, BNB Chain, Arbitrum and more.​
  • A disgruntled member claims the crew stole about 7 million dollars across 37 token types, then leaked internal details after a fight over profit splits and unpaid “severance,” saying they now plan to turn themselves in.​
  • Even as authorities stay quiet, the episode echoes recent supply‑chain and extension incidents involving Trust Wallet and others, underscoring that every update, plugin, and wrapper around self‑custody wallets is part of the real attack surface.

A Chinese hacker group posing as a cybersecurity firm has been exposed after an internal dispute led members to leak details of a multimillion‑dollar crypto theft operation. According to market reports, the group claims to have stolen around 7 million dollars in digital assets through supply chain attacks, with targets including popular wallet provider Trust Wallet.​

Operating under the corporate front Wuhan Anshun Technology, the group presented itself publicly as a security company focused on vulnerability research, network offense-and-defense exercises, and security services. Internally, however, members were allegedly conducting “gray market” activity, systematically stealing mnemonic phrases and raiding user wallets across multiple chains. The whistleblower says the team built automated tooling to bulk-scan mnemonic phrase assets and to identify high‑value portfolios across Ethereum, BNB Chain, Arbitrum and other networks.​

China fake cybersecurity firm accused of weaponizing wallet plugins and Electron supply chains

Per the leaked account, the group exploited supply chain vulnerabilities in Electron-based clients and browser plugins, combined with reverse engineering and remote-control programs, to exfiltrate wallet data and drain funds. The operation allegedly touched 37 different token types across several blockchains, with funds laundered via splitting and transfers to obscure the trail. The immediate trigger for the exposure was an internal fight over profit distribution and unpaid “severance” to one of the operators.

The whistleblower claims they clashed with the team leader over what they saw as unfair profit splits, then decided to publicly dump evidence after promised compensation was not delivered, stating they intend to turn themselves in to law enforcement. So far, the allegations have not been officially confirmed, and authorities have not publicly detailed any investigation progress. Industry commentators note that, confirmed or not, the episode again underscores the structural attack surface in wallet supply chains, plugin ecosystems, and desktop clients—especially for high‑value users who treat self‑custody software as “set and forget.”​

For retail and institutional users, the lesson is blunt: security risk is not just in private key handling, but in every update, extension, and client wrapper sitting between you and your keys. In a market where attackers are willing to build fake “security companies” as covers, rigorous supply‑chain auditing, minimal plugin use, and strict device‑level hygiene are no longer best practices—they are baseline survival requirements.

Market Opportunity
Intuition Logo
Intuition Price(TRUST)
$0.0716
$0.0716$0.0716
-1.44%
USD
Intuition (TRUST) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

TransFi Secures Pivotal $19.2M Funding to Revolutionize Global Stablecoin Payments

TransFi Secures Pivotal $19.2M Funding to Revolutionize Global Stablecoin Payments

BitcoinWorld TransFi Secures Pivotal $19.2M Funding to Revolutionize Global Stablecoin Payments In a significant move for the digital payments sector, stablecoin
Share
bitcoinworld2026/03/18 11:50
Wormhole launches reserve tying protocol revenue to token

Wormhole launches reserve tying protocol revenue to token

The post Wormhole launches reserve tying protocol revenue to token appeared on BitcoinEthereumNews.com. Wormhole is changing how its W token works by creating a new reserve designed to hold value for the long term. Announced on Wednesday, the Wormhole Reserve will collect onchain and offchain revenues and other value generated across the protocol and its applications (including Portal) and accumulate them into W, locking the tokens within the reserve. The reserve is part of a broader update called W 2.0. Other changes include a 4% targeted base yield for tokenholders who stake and take part in governance. While staking rewards will vary, Wormhole said active users of ecosystem apps can earn boosted yields through features like Portal Earn. The team stressed that no new tokens are being minted; rewards come from existing supply and protocol revenues, keeping the cap fixed at 10 billion. Wormhole is also overhauling its token release schedule. Instead of releasing large amounts of W at once under the old “cliff” model, the network will shift to steady, bi-weekly unlocks starting October 3, 2025. The aim is to avoid sharp periods of selling pressure and create a more predictable environment for investors. Lockups for some groups, including validators and investors, will extend an additional six months, until October 2028. Core contributor tokens remain under longer contractual time locks. Wormhole launched in 2020 as a cross-chain bridge and now connects more than 40 blockchains. The W token powers governance and staking, with a capped supply of 10 billion. By redirecting fees and revenues into the new reserve, Wormhole is betting that its token can maintain value as demand for moving assets and data between chains grows. This is a developing story. This article was generated with the assistance of AI and reviewed by editor Jeffrey Albus before publication. Get the news in your inbox. Explore Blockworks newsletters: Source: https://blockworks.co/news/wormhole-launches-reserve
Share
BitcoinEthereumNews2025/09/18 01:55
U.S SEC issues first-ever definitions for what crypto assets are securities

U.S SEC issues first-ever definitions for what crypto assets are securities

The post U.S SEC issues first-ever definitions for what crypto assets are securities appeared on BitcoinEthereumNews.com. For the first time, the U.S Securities
Share
BitcoinEthereumNews2026/03/18 12:24