Trust Wallet is a mobile wallet owned by Binance. It is a horrible wallet and nobody should use it but it also happens to be one of the most used cryptocurrency and bitcoin wallets in the world.

They launched a browser extension version of the wallet in November. Ledger’s team discovered and reported a critical vulnerability in it within three days. Impressive work that appears to have saved millions in potential losses.

https://blog.ledger.com/Funds-of-every-wallet-created-with-the-Trust-Wallet-browser-extension-could-have-been-stolen/

Reply to this note

Please Login to reply.

Discussion

Which mobile wallet is good/okay in your opinion?

My bitcoin storage recommendations with guides:

Simple and easy self custody: werunbtc.com/muun

Easy lightning wallet on mobile: werunbtc.com/phoenix

Cold storage for long term savings: werunbtc.com/coldcard

Thanks a lot, @ODELL! Already using Phoenix. Will try Muun.

Here is a detailed guide about mobile wallets functionalities and a warning about Muun:

https://darthcoin.substack.com/p/lightning-wallets-comparison

When will LN go away from blue wallet

Installed Muun yesterday, was immediately surprised that user can restore the wallet using email and password. Started reading their blog. Multisig, double signature, the "inability" to steal bitcoin, some encrypted archive with two keys in case of emergency (what will happened if their app will be discontinued/banned from appstores, they don't tell). Pretty weird and doesn't look like non-custodial storage at all.

Which mobile wallet do you think is the best?

Oh, sorry, didn't noticed that it's your article on substack. "We too early, no need to focus on self custody, use wallet for your needs..." Okay, get it.

For long term storage, I was impressed with seedsigner. Is coldcard better?

I just set up Zeus on my mobile. Curious what your thoughts are in it & what your preferred Lightning wallet is

Odell still recommending Muun to noobs = we are still early

You don't make things better by calling people you don't know noobs)) Too early for arrogance.

If I could jump in,, Someone told me muun was KYC . is that correct?

Shouldn't #bitcoin only wallets be the standard?

Yes, but also do not think it is a coincidence that the most used mobile wallets support a ton of shitcoins.

Needless to say, nobody should use trust wallet. Even without this bug their bitcoin support is garbage, does not support lightning and does not even generate a new address for every receipt.

I use cold card, run my own node, and lightning node, bluewallet for mobile, and then alby for here. And btw, I have learned a lot from you over the past couple years. Thank you!

Cheers! Glad to hear it!

If you need to shitcoin, use #[4]

After checking that it’s open source, I immediately test a wallet for address reuse. That’s a big red flag on developer perspective and an immediate disqualifier for me.

FOSS is tough and some of us have bills to pay and families to feed, with donations or grants being few or far between.

But we can funnel the profits from the shitcoins into making better Bitcoin stuff. More or less what we do at Stack.

Wish they didn't report it, now no lessons were learned

Do you use Ledger? #plebquestion

Nope, but I have a lot of respect for their team.

I recommend coldcard.

Full guide here: https://werunbtc.com/coldcard

Thanks for the info. I’ve tried many hardware wallets so this one will be new to me

Been using ledger for 4 yrs. Much improvement in user experience in that time. Ledger Live at first was difficult to read... no dark mode/small font. Nano S was also finicky, and hard on my old Boomer eyes. Nano S+ much better. Being old, I have to keep it simple; so 24 words plus passphrase seems safe enough. Coldcard, much as I'd like to support a Canadian bitcoin-only company, is just too complicated. Been thinking about checking out Blockstream Jade.

👀👀👀👀👀 thanks for the heads up 🤙🏽

Agreed, I switched to BlueWallet.

But nostr:npub1qny3tkh0acurzla8x3zy4nhrjz5zd8l9sy9jys09umwng00manysew95gx, they called it "Trust Wallet" . Surely it's trust worthy.

But the word “trust” is in the name!

Good call

#[0]

Trust Wallet named by the same logic that brought us the Patriot Act

Bro it’s called trust wallet bro. Just trust it bro. Why r u bein so toxic bro?

Your funds are SNAFU.

This case is truly ridiculous. I remember doing "crack the (MT19937) Mersenne twister" as a cryptography 101 exercise 10 years ago - and it was a very old attack back then! Unforgivable, showing that whoever's in charge doesn't give a fuck about security (they didn't have to know it, they could have asked literally anyone with specialist knowledge). This is the problem with business types focused on marketing. Taking that attitude w.r.t. bearer instruments is a never ending category error, it seems.

Why would one ever connect a wallet to another application that connects to the internet?

there is no need to create panic

it is about the BROWSER wallet which could be attacked according to ledger

not the mobile wallet. what you are doing is libel. binance should sue you.