Trust Wallet Discord short link hijacked; ZachXBT urgently warns: do not click

MarketWhisper
ETH-4,77%
BNB-4,79%
OP-4,07%
ARB-4,66%

Trust Wallet短連結遭劫持

On April 2, on-chain detective ZachXBT issued an urgent warning: the official Trust Wallet Discord short link discord[.]gg/trustwallet has been hijacked by an attacker and is currently pointing to a malicious phishing server. ZachXBT specifically advises users to avoid joining the Discord community via any links provided through official channels until the issue is resolved.

Discord Hijacking Alert: Emergency Protection Measures Users Need to Take Immediately

Trust Wallet Discord (Source: ZachXBT)

The official Trust Wallet Discord short link has been hijacked, meaning that all users who bookmarked this link or obtained it through any official or unofficial channel may, after clicking, end up on a phishing server disguised as the Trust Wallet community.

Common attack patterns of phishing servers include: impersonating official administrators to要求 users to submit a seed phrase or private key; sending “official security announcements” containing malicious links; and simulating Trust Wallet emergency upgrade prompts to诱导 users to take action. At present, users should immediately take the following steps:

Stop clicking on every existing link: No matter whether the source is the Trust Wallet official website, Telegram, a blog, or any other third-party channel, only get the latest security announcements and the correct links through the app or a verified X account

Wait for official confirmation: Do not re-join until Trust Wallet officially announces that the Discord link has been restored to safety

If you have entered any sensitive information: Immediately transfer your assets to a new wallet and regenerate your seed phrase

Address Poisoning Protection Going Live: Full Coverage of 32 EVM Chains

On the same day that the Discord hijacking incident broke out, Trust Wallet announced the launch of an address poisoning attack real-time protection feature, adding an in-app interface element with a proactive screening mechanism: the system will automatically compare target addresses against a database, and once it matches known scam addresses or look-alike spoof addresses, it will immediately alert the user to block potentially malicious transactions.

The initial supported scope covers 32 EVM-compatible blockchains, including major networks such as Ethereum, BNB Smart Chain, Polygon, Optimism, Arbitrum, Avalanche, and Base.

According to Trust Wallet data, address poisoning attacks have already occurred more than 225 million times, with confirmed losses totaling $500 million. In the past two major cases, one investor lost $50 million in USDT in December 2025; and two other investors together lost $62 million. These losses prompted Binance former CEO Changpeng Zhao (CZ) to publicly criticize, saying: “All wallets should simply check whether the receiving address is a malicious address and ban users—this is only a blockchain query.”

A String of Security Challenges for Trust Wallet Since 2025

This Discord hijacking incident is not isolated. On December 24, 2025, Trust Wallet’s Chrome browser extension was attacked, causing users to lose roughly $7 million; Trust Wallet urgently released a patched version and promised compensation to affected users. Currently, competing products such as Rabby Wallet, Zengo Wallet, and Phantom Wallet have already provided similar malicious transaction pre-filtering functions. Trust Wallet’s introduction of address poisoning protection is a direct response to industry pressure.

Frequently Asked Questions

After the Trust Wallet Discord is hijacked, how can I safely get the correct community invite link?

Before Trust Wallet officially confirms that the Discord link is safe again, it is recommended to obtain the latest Discord invite link through Trust Wallet’s official pages within the app, or through the verified official Trust Wallet X (Twitter) account. Avoid using any saved old links or links from third-party channels.

How does the address poisoning attack work specifically, and how can users protect themselves?

The attacker first sends a small transaction to the victim, causing the phishing address to appear in the victim’s transaction history; when the victim transfers funds next time, they may copy this look-alike malicious address from the history, leading to funds being sent to the attacker’s account. Protection methods: always manually enter the address or copy it only from trusted addresses; never copy an address from transaction history; and ensure you use a wallet version that already includes address screening functionality.

Has the 2025 security incident involving the Trust Wallet Chrome extension been fully resolved?

After the extension attack on December 24, 2025, Trust Wallet released a new version that removes the malicious code and promised compensation to affected users. It is recommended that all users confirm the Trust Wallet extension has been updated to the latest version, and verify the legitimacy of the source through the official page in the Chrome Web Store.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.
Comment
0/400
No comments