TW

TRANSACTION CONTROL FILE

Trust Wallet

A self-custody wallet with broad chain claims, optional cloud backup, Wallet Core source and a material 2025 browser-extension incident.

REVIEW DATE
EVIDENCE STATUS
partially verified
CONFIDENCE
medium

Written by Beacon Ratio Editorial TeamIndependently reviewed by Beacon Ratio Review TeamPublished by Beacon Ratio Team

EDITORIAL ASSESSMENT

Trust Wallet's recovery and swap model is understandable at document level, but breadth and no-extra-wallet-fee claims are not complete cost or security conclusions. The extension incident makes release provenance a first-class test.

SUITABLE FOR
Users seeking a multi-chain self-custody interface who can protect a 12-word recovery phrase and evaluate optional cloud backup separately.
PRIMARY TRADE-OFF
Wide network and in-app swap access simplify navigation, while seed custody, integrations and release-channel risk remain concentrated user responsibilities.
DOCUMENTED STRENGTHS
  • Recovery responsibility is explained plainly
  • Wallet Core is publicly inspectable under Apache-2.0
  • The provider published quantified updates on the v2.68 incident
LIMITS / OPEN TESTS
  • Cloud backup changes the recovery threat model
  • Wallet Core does not prove every interface or store build is open source
  • No added wallet fee does not equal a free swap
ANALYSIS / 5

From wallet claim to transaction-control test.

02

Swap economics

Trust Wallet says it adds no extra wallet fee to in-app swaps. Network fees, DEX or router charges, liquidity, slippage and token mechanics still determine total execution cost.

03

Breadth claims

Product marketing and Wallet Core describe different chain counts because they cover different scopes. Chain breadth should be tested as send, receive, sign, token-display and dapp support—not as one marketing number.

04

Release risk

Trust Wallet reported a malicious Browser Extension v2.68 release in December 2025. Its 17 July 2026 update reported 2,520 affected addresses and about USD 8.5 million affected while investigation and reimbursement processing continued.

05

Privacy and code boundary

The privacy notice names Dapps Platform Bahrain W.L.L as controller. Wallet Core is open source, but that licence cannot be extended to every UI component or distributed binary without separate evidence.

DECISION FILE / 04

Where this product fits—and where it does not.

BEST FIT

Users seeking a multi-chain self-custody interface who can protect a 12-word recovery phrase and evaluate optional cloud backup separately.

NOT A FIT

Users who cannot maintain an offline recovery plan, verify extension provenance and permissions, or assess third-party swap and dapp routes.

STRONGEST DOCUMENTED CASE

Recovery responsibility is explained plainly

CLOSEST ALTERNATIVE

MetaMask has more explicit MetaMetrics controls and a different Ethereum-centric extension ecosystem; a hardware wallet may narrow online key risk but does not eliminate dapp or approval risk.

REVIEW SCOPE
Trust Wallet mobile and browser-extension self-custody, seed lifecycle, privacy notice, Wallet Core and the disclosed browser-extension v2.68 incident. Embedded dapps and third-party on-ramps retain separate providers.
ENTITY / CONTROL BOUNDARY
Private keys are described as locally stored under user custody. Dapps Platform Bahrain W.L.L. is named as privacy controller, while network, swap, cloud and external service providers can receive separate data or instructions.
SCENARIOS / 4

Concrete routes, not generic personas.

01

Primary decision route

A multi-chain user sets up an empty wallet, documents seed and optional cloud choices, compares an in-app swap with a direct protocol, then verifies extension version and rehearses recovery.

02

In-app swap

Wallet quote → routed protocol → on-chain settlement. Open question: Pool fee, price impact, approval/revocation gas, failed transaction and provider spread.

03

Recovery route

New device → phrase or optional backup → account discovery. Open question: Operational time, backup dependency, missing-account discovery and security exposure during recovery.

04

Alternative route

MetaMask has more explicit MetaMetrics controls and a different Ethereum-centric extension ecosystem; a hardware wallet may narrow online key risk but does not eliminate dapp or approval risk.

EXPERT LEDGER / 8

Decision factors with evidence state and the next test attached.

Trust Wallet execution, control and evidence ledger
Decision factorCurrent finding and adjacent evidenceEvidence stateVerification protocol
Scope and product

Mobile, browser extension and Wallet Core are not interchangeable evidence objects. Each build and feature route must be named.

Documented

Record store version, platform and enabled features for the test wallet.

Keys and recovery

The recovery phrase anchors user control; optional backup or device services can add dependencies without turning the wallet into exchange custody.

Documented

Rehearse recovery with an empty wallet and separately test any optional backup path.

Release security

Wallet Core is inspectable, while the v2.68 incident shows that distribution provenance can fail even in a self-custody product.

Mixed

Verify extension source, signature and store release path for the current version.

Legal and provider boundary

The privacy notice names a controller; embedded financial services remain third parties with their own terms and eligibility.

Documented

Record provider and jurisdiction for each on-ramp, swap or bridge used.

Swap and total cost

No-extra-wallet-fee language does not remove gas, pool fee, spread, price impact, approval or failed-transaction cost.

Planned verification

Compare identical routes and report realised output after every on-chain cost.

Data flow

The notice describes local keys, transaction history, device/usage information and transient IP processing; third-party services can receive public addresses.

Documented

Observe endpoints by feature and distinguish controller statements from network behaviour.

Support and disputes

Support can address product issues but cannot reverse a valid on-chain signature or reconstruct undisclosed recovery material.

Mixed

Open a harmless release-provenance question and record the escalation path.

Incident and change control

The v2.68 disclosure is product-specific historical evidence. It should inform release testing without implying every mobile or current build is compromised.

Documented

Track remediation and current release controls; never generalise the incident beyond its stated scope.

TOTAL COST / 2

Fee schedules are inputs, not outcomes.

Scenario total-cost model; documented inputs applied
ScenarioRouteDocumented inputsOpen question
In-app swapWallet quote → routed protocol → on-chain settlement

Quoted output, network gas and any disclosed provider fee.

Pool fee, price impact, approval/revocation gas, failed transaction and provider spread.
Recovery routeNew device → phrase or optional backup → account discovery

Documented recovery method and device requirements.

Operational time, backup dependency, missing-account discovery and security exposure during recovery.
REPRODUCIBLE METHOD

How this file becomes a measured result

Fix mobile/extension version, chain and recovery mode. Capture permissions, network endpoints, quotes, gas, routing, approval scope, release provenance and clean-device recovery without using material funds.

EVIDENCE CONFIDENCE

What the documents can support

Medium for the documented local-key and privacy-controller model; medium for Wallet Core visibility; high for the provider's own incident disclosure as a historical record; insufficient for current shipped-build and live-route performance.

Conclusion-change gates

  • Privacy-controller, telemetry or cloud-backup disclosures change.
  • Release provenance controls materially change after the v2.68 incident.
  • Reproducible recovery and chain-matched route tests produce durable findings.
CHANGE LOG / 03

Evolution stays visible.

  1. Rechecked privacy notice, seed guidance, Wallet Core and v2.68 disclosure; added release and route scenarios.

  2. Opened the wallet public-evidence file.

  3. Privacy-controller, telemetry or cloud-backup disclosures change. Release provenance controls materially change after the v2.68 incident. Reproducible recovery and chain-matched route tests produce durable findings.

FAQ / 4

Questions that change the decision.

Does Trust Wallet charge no costs for swaps?

A no-extra-wallet-fee statement is not a zero-cost result; network, protocol, price impact and third-party costs remain.

Is Wallet Core the complete shipped app?

No. It is an important open-source component, not proof of every interface, service or store binary.

Does the v2.68 incident affect every Trust Wallet user?

The provider disclosure concerns a specific browser-extension release. Its scope must not be expanded without evidence.

What would change this conclusion?

Privacy-controller, telemetry or cloud-backup disclosures change.

PRIMARY SOURCE REGISTER

6 records reviewed

Provider pages establish provider statements. Terms, filings and regulator records retain their narrower legal or historical scope. Dynamic sources were retrieved on 16 August 2026.

  1. termsRetrieved 2026-08-16Trust Wallet Privacy Notice
  2. productRetrieved 2026-08-16The lifecycle of a seed phrase in Trust Wallet
  3. technicalRetrieved 2026-08-16Trust Wallet Wallet Core
  4. productRetrieved 2026-08-16Trust Wallet FAQs
  5. technicalRetrieved 2026-08-16Trust Wallet security overview
  6. productRetrieved 2026-08-16Trust Wallet Browser Extension v2.68 incident update