Independent public-evidence reviewNo personal financial advice
Candid LedgerPut the evidence on the record.

Recovery & provenance memorandum

Trust Wallet

This memorandum places recovery responsibility, open-source scope, swap-cost wording and the v2.68 extension incident on one dated record.

Editorial assessment: Trust Wallet offers a recognisable self-custody model and an inspectable Wallet Core library, but convenience options and product breadth deserve narrower wording. The December 2025 extension incident is material and still carries an open remediation timeline in the July 2026 update.

Editorial statusPublished review
Evidence reviewPublic evidence reviewed
Scenario testingScenarios published
ComparisonCategory matrix eligible
Reviewed
Evidence confidencemedium
Suitable for

Who may find this file useful

Users able to secure a recovery phrase, verify distribution channels and distinguish mobile, browser-extension and Wallet Core claims.

Primary trade-off

The decision tension

Wide network support and optional backup convenience increase reach, while phrase custody, update provenance and third-party routing remain the user’s responsibility.

Research boundary

Documentary, not experiential

Public evidence has been reviewed; account, funding, trading, withdrawal and support scenarios are specified as controlled routes with defined inputs and records.

Evidence-backed strengths

What the record supports

  • Straightforward self-custody and seed-phrase documentation
  • Apache-2.0 Wallet Core codebase
  • Public incident updates with affected-address and reimbursement information

Material limitations

What must stay qualified

  • Cloud backup alters the pure offline-recovery model
  • No-extra-wallet-fee wording does not mean a cost-free swap
  • Wallet Core openness cannot be attributed to every interface or distributed binary
Control evidence file4 recorded fields
K1

Key control

Trust Wallet is self-custodial and uses a 12-word recovery phrase; the user bears restoration responsibility.

documented
K2

Recovery path

Optional encrypted cloud backup adds a provider-account and cloud dependency to the recovery path.

documented
K3

Signing and cost

In-app swaps may add no Trust Wallet fee, but network, DEX, routing, slippage and token costs remain.

documented
K4

Software provenance

Wallet Core is Apache-2.0; the v2.68 browser-extension incident makes channel and version verification material.

documented

Investigative analysis

Claims, records and the gaps between them.

Each conclusion is tied to the primary records immediately below it. Links open the publisher’s original material.

01

The recovery phrase is the control boundary

Trust Wallet describes a 12-word phrase as the material needed to restore control. Anyone who obtains it can take the assets, and the publication cannot recover it. Optional encrypted cloud backup may reduce one loss scenario while adding cloud-account and provider dependencies that should be documented separately.

Sources: Trust Wallet · Trust Wallet
02

Chain-count claims use different denominators

The consumer product markets support for more than 100 chains, while the Wallet Core repository reports more than 130. These statements can both be authentic and still refer to different technical scopes. We do not combine them into a single coverage claim without a versioned network test.

Sources: GitHub / Trust Wallet · Trust Wallet
03

No added wallet fee does not make swaps free

Trust Wallet says it does not add an extra wallet fee to in-app swaps. Network charges, DEX or routing economics, liquidity, slippage and token mechanics may still change the result. The useful comparison is final received value for a declared route, not the presence or absence of one fee label.

Sources: Trust Wallet · Trust Wallet
04

Open-source wording stops at Wallet Core

Wallet Core is published under Apache-2.0 and provides a meaningful inspection surface. That licence cannot automatically be extended to every user interface, backend dependency or app-store binary carrying the Trust Wallet name. Release provenance therefore remains a separate test from repository availability.

Sources: GitHub / Trust Wallet · Trust Wallet
05

The v2.68 incident is product- and version-specific

Trust Wallet disclosed a malicious Browser Extension v2.68 release in December 2025. Its 17 July 2026 update reported 2,520 drained addresses and approximately USD 8.5 million affected, with investigation and reimbursement processing continuing. The record is serious but does not support saying that every Trust Wallet user or the mobile application was compromised.

Sources: Trust Wallet
06

Privacy has a named controller

The privacy notice identifies Dapps Platform Bahrain W.L.L as controller and describes categories of processing. That clarity helps locate accountability, but the exact data flow still depends on feature and service use. A later scenario should record network requests rather than infer privacy from self-custody alone.

Sources: Trust Wallet · Trust Wallet

Claim → evidence → gap

Ten claims placed under an accountable burden of proof.

Each module keeps the decision consequence beside the evidence and the unresolved gap. Primary material was retrieved on .

Fit

Multi-chain access is valuable and seed responsibility is understood.

The product and Wallet Core support broad chain workflows.

Fit

The user will verify official channel and exact build.

The v2.68 incident makes provenance a direct control.

Not fit

Support must restore a lost phrase.

Self-custody makes the recovery secret the user’s responsibility.

Not fit

Open Wallet Core must prove every app/backend.

Component openness does not establish full product provenance.

01

01 / Product claim

Claim under review
Mobile, extension and Wallet Core share identical scope.
Evidence on record
The repository and product materials describe related but distinct surfaces.
Unresolved gap
Exact build capabilities remain unobserved.
Decision impact
Name surface and version before using chain/security claims.

Adjacent sources: GitHub / Trust Wallet · Trust Wallet

02

02 / Control claim

Claim under review
Self-custody removes dependency risk.
Evidence on record
The 12-word phrase controls recovery while services and releases remain dependencies.
Unresolved gap
Runtime service paths are not mapped.
Decision impact
Assess key control, distribution and integrations separately.

Adjacent sources: Trust Wallet · Trust Wallet

03

03 / Recovery claim

Claim under review
Cloud backup simply makes recovery safer.
Evidence on record
Optional encrypted backup adds cloud/account dependencies.
Unresolved gap
Compromise and loss behaviour is untested.
Decision impact
Choose backup against a stated threat model.

Adjacent sources: Trust Wallet · Trust Wallet

04

04 / Security claim

Claim under review
Official-store installation settles provenance forever.
Evidence on record
The v2.68 incident involved a malicious extension release.
Unresolved gap
Current release controls are not independently tested.
Decision impact
Verify publisher, version and incident guidance at every install/update.

Adjacent sources: Trust Wallet

05

05 / Cost claim

Claim under review
No extra wallet fee means a free swap.
Evidence on record
Provider FAQ/security material leaves network, DEX, routing and slippage costs.
Unresolved gap
Matched final amounts are absent.
Decision impact
Compare the destination value, not one fee label.

Adjacent sources: Trust Wallet · Trust Wallet

06

06 / Funding/exit claim

Claim under review
Broad chain support prevents wrong-network loss.
Evidence on record
Wallet Core and consumer claims use different coverage scopes.
Unresolved gap
Exact app/network/action support is untested.
Decision impact
Verify chain, contract and destination before transfer.

Adjacent sources: GitHub / Trust Wallet · Trust Wallet

07

07 / Permission claim

Claim under review
A familiar wallet prompt makes approvals understandable.
Evidence on record
The wallet signs user-authorised transactions.
Unresolved gap
Mobile/extension prompt parity and revocation remain unobserved.
Decision impact
Test spender, amount, chain and simulation on both surfaces.

Adjacent sources: Trust Wallet

08

08 / Privacy claim

Claim under review
Self-custody means no controller or telemetry.
Evidence on record
The privacy notice names a controller and describes processing.
Unresolved gap
Feature-level network flows remain unobserved.
Decision impact
Map RPC, analytics and integrated-service recipients.

Adjacent sources: Trust Wallet

09

09 / Support/remedy claim

Claim under review
Provider support can reverse chain loss.
Evidence on record
Self-custody and incident channels have different limits.
Unresolved gap
Current case ownership and reimbursement path are not tested.
Decision impact
Never share the phrase; preserve official case references.

Adjacent sources: Trust Wallet · Trust Wallet

10

10 / Incident-scope claim

Claim under review
The v2.68 event affected every Trust Wallet user.
Evidence on record
The provider bounded it to a named browser-extension version and later published affected-address/loss figures.
Unresolved gap
Final remediation remains ongoing in the cited update.
Decision impact
Keep product/version scope visible while treating release governance as material.

Adjacent sources: Trust Wallet

Accountable scenario file

What the next observation must record.

Each row specifies a fixed protocol with defined inputs and record.

P-1

Recovery-path comparison

Fixed inputs: Disposable wallet and available backup modes; no valuable assets.

Record: Dependencies, warnings, recovery success and imported accounts.

Published
P-2

Mobile versus extension signing

Fixed inputs: Same controlled approval/transfer on current official builds.

Record: Version, spender, amount, simulation, reject and revoke.

Published
P-3

Multi-chain cost route

Fixed inputs: One token route, amount, network and time window.

Record: Provider/bridge fee, gas, slippage, minimum and final received.

Published
P-4

Incident support/provenance

Fixed inputs: Current official build and non-sensitive incident-policy question.

Record: Binary identifiers, warnings, case ownership and remedy route.

Published

Change timeline

Events that change the reading.

  1. Malicious browser extension v2.68 disclosed.

    Release provenance becomes a direct asset-protection control.

  2. Provider reported 2,520 addresses and about USD 8.5m affected.

    Governance and remedy remain material but version-bounded.

  3. Privacy, recovery, code and incident sources re-retrieved.

    Fresh cross-surface tests are specified as fixed protocol outputs.

Alternatives

When another responsibility model fits better.

MetaMask

EVM/hardware workflows matter more than multi-chain breadth.

Hardware wallet

Offline key isolation outweighs mobile-first convenience.

Conclusion control

Medium evidence confidence.

Supported
Recovery, privacy, repository and incident records support the boundary analysis.
Gap
Current build provenance, signing, data flow, route cost and remedy are unobserved.
What changes the conclusion
Verified release-control improvements could raise confidence; another distribution failure would lower it.

Method

How the burden of proof is applied.

  1. Fix surface, version and distribution channel.
  2. Use disposable wallets for recovery/signing.
  3. Trace full fee and data paths.
  4. Bound incidents to product, version, affected set and update date.

Change log

Material file revisions.

Added ten recovery/provenance claim files and four safe, repeatable wallet scenarios.

FAQ

Questions that survive the headline.

Can support recover the phrase?

No; ordinary support must never request it.

Did v2.68 affect every user?

No; the disclosure concerns a named extension version.

Does Wallet Core prove the whole app?

No; it is component evidence.

Is cloud backup always safer?

No; it trades one loss path for cloud/account dependencies.

SR

Primary-source register

Reviewed on by Candid Ledger Editorial Team; independent editorial review by Candid Ledger Review Team.

  1. Trust Wallet privacy noticeTrust Wallet · retrieved 16 August 2026
  2. The lifecycle of a seed phrase in Trust WalletTrust Wallet · retrieved 16 August 2026
  3. Trust Wallet Wallet Core repositoryGitHub / Trust Wallet · retrieved 16 August 2026
  4. Trust Wallet FAQsTrust Wallet · retrieved 16 August 2026
  5. Complete overview of Trust Wallet securityTrust Wallet · retrieved 16 August 2026
  6. Browser Extension v2.68 incident community updateTrust Wallet · retrieved 16 August 2026