Who may find this file useful
Users able to secure a recovery phrase, verify distribution channels and distinguish mobile, browser-extension and Wallet Core claims.
Recovery & provenance memorandum
This memorandum places recovery responsibility, open-source scope, swap-cost wording and the v2.68 extension incident on one dated record.
Editorial assessment: Trust Wallet offers a recognisable self-custody model and an inspectable Wallet Core library, but convenience options and product breadth deserve narrower wording. The December 2025 extension incident is material and still carries an open remediation timeline in the July 2026 update.
Users able to secure a recovery phrase, verify distribution channels and distinguish mobile, browser-extension and Wallet Core claims.
Wide network support and optional backup convenience increase reach, while phrase custody, update provenance and third-party routing remain the user’s responsibility.
Public evidence has been reviewed; account, funding, trading, withdrawal and support scenarios are specified as controlled routes with defined inputs and records.
Evidence-backed strengths
Material limitations
Trust Wallet is self-custodial and uses a 12-word recovery phrase; the user bears restoration responsibility.
Optional encrypted cloud backup adds a provider-account and cloud dependency to the recovery path.
In-app swaps may add no Trust Wallet fee, but network, DEX, routing, slippage and token costs remain.
Wallet Core is Apache-2.0; the v2.68 browser-extension incident makes channel and version verification material.
Investigative analysis
Each conclusion is tied to the primary records immediately below it. Links open the publisher’s original material.
Trust Wallet describes a 12-word phrase as the material needed to restore control. Anyone who obtains it can take the assets, and the publication cannot recover it. Optional encrypted cloud backup may reduce one loss scenario while adding cloud-account and provider dependencies that should be documented separately.
Sources: Trust Wallet · Trust WalletThe consumer product markets support for more than 100 chains, while the Wallet Core repository reports more than 130. These statements can both be authentic and still refer to different technical scopes. We do not combine them into a single coverage claim without a versioned network test.
Sources: GitHub / Trust Wallet · Trust WalletTrust Wallet says it does not add an extra wallet fee to in-app swaps. Network charges, DEX or routing economics, liquidity, slippage and token mechanics may still change the result. The useful comparison is final received value for a declared route, not the presence or absence of one fee label.
Sources: Trust Wallet · Trust WalletWallet Core is published under Apache-2.0 and provides a meaningful inspection surface. That licence cannot automatically be extended to every user interface, backend dependency or app-store binary carrying the Trust Wallet name. Release provenance therefore remains a separate test from repository availability.
Sources: GitHub / Trust Wallet · Trust WalletTrust Wallet disclosed a malicious Browser Extension v2.68 release in December 2025. Its 17 July 2026 update reported 2,520 drained addresses and approximately USD 8.5 million affected, with investigation and reimbursement processing continuing. The record is serious but does not support saying that every Trust Wallet user or the mobile application was compromised.
Sources: Trust WalletThe privacy notice identifies Dapps Platform Bahrain W.L.L as controller and describes categories of processing. That clarity helps locate accountability, but the exact data flow still depends on feature and service use. A later scenario should record network requests rather than infer privacy from self-custody alone.
Sources: Trust Wallet · Trust WalletClaim → evidence → gap
Each module keeps the decision consequence beside the evidence and the unresolved gap. Primary material was retrieved on .
The product and Wallet Core support broad chain workflows.
The v2.68 incident makes provenance a direct control.
Self-custody makes the recovery secret the user’s responsibility.
Component openness does not establish full product provenance.
Adjacent sources: GitHub / Trust Wallet · Trust Wallet
Adjacent sources: Trust Wallet · Trust Wallet
Adjacent sources: Trust Wallet · Trust Wallet
Adjacent sources: Trust Wallet
Adjacent sources: Trust Wallet · Trust Wallet
Adjacent sources: GitHub / Trust Wallet · Trust Wallet
Adjacent sources: Trust Wallet
Adjacent sources: Trust Wallet
Adjacent sources: Trust Wallet · Trust Wallet
Adjacent sources: Trust Wallet
Accountable scenario file
Each row specifies a fixed protocol with defined inputs and record.
Fixed inputs: Disposable wallet and available backup modes; no valuable assets.
Record: Dependencies, warnings, recovery success and imported accounts.
PublishedFixed inputs: Same controlled approval/transfer on current official builds.
Record: Version, spender, amount, simulation, reject and revoke.
PublishedFixed inputs: One token route, amount, network and time window.
Record: Provider/bridge fee, gas, slippage, minimum and final received.
PublishedFixed inputs: Current official build and non-sensitive incident-policy question.
Record: Binary identifiers, warnings, case ownership and remedy route.
PublishedChange timeline
Release provenance becomes a direct asset-protection control.
Governance and remedy remain material but version-bounded.
Fresh cross-surface tests are specified as fixed protocol outputs.
Alternatives
EVM/hardware workflows matter more than multi-chain breadth.
Offline key isolation outweighs mobile-first convenience.
Conclusion control
Method
Change log
Added ten recovery/provenance claim files and four safe, repeatable wallet scenarios.
FAQ
No; ordinary support must never request it.
No; the disclosure concerns a named extension version.
No; it is component evidence.
No; it trades one loss path for cloud/account dependencies.
Reviewed on by Candid Ledger Editorial Team; independent editorial review by Candid Ledger Review Team.