{"investigation":{"slug":"trinity-wallet","entity_name":"Trinity Wallet","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Trinity Wallet was the official desktop and mobile software wallet for the IOTA cryptocurrency, developed and maintained by the IOTA Foundation. In February 2020, a supply chain attack exploiting a compromised MoonPay SDK delivered via CDN resulted in the theft of approximately 8.55 Ti (teraIOTA) worth roughly $2 million from 50 user seeds, forcing the IOTA Foundation to shut down the entire IOTA network for 27 days. Trinity was subsequently deprecated in April 2021 following the Chrysalis protocol upgrade, with the Firefly wallet introduced as its replacement.","sections":[{"content":"On February 12, 2020, the IOTA Foundation halted the IOTA network Coordinator after detecting that funds were being stolen from Trinity Wallet users. Investigation confirmed a supply chain attack in which an attacker had compromised MoonPay's content delivery network (CDN) to distribute malicious versions of MoonPay's software development kit (SDK), which Trinity loaded automatically when users opened the wallet. Once a user's wallet was unlocked, the injected code decrypted the user's seed and transmitted both the seed and password to an attacker-controlled server. The IOTA Foundation's post-incident report named MoonPay 19 times and stated it found 'irrefutable proof' that affected Trinity caches had been loaded with illicit SDK versions served from MoonPay's CDN. The attack vector was possible because, at the time of integration, MoonPay was only available as CDN-bundled code. The IOTA Foundation acknowledged it had flagged the risk and requested a more secure NPM package from MoonPay, but that 'release pressure and human error' led to the Foundation launching Trinity with the CDN integration before the more secure package was available.","heading":"Supply Chain Attack — MoonPay SDK Compromise (February 2020)","sources":[{"url":"https://blog.iota.org/trinity-attack-incident-part-1-summary-and-next-steps-8c7ccc4d81e8/","name":"blog.iota.org","type":"other","credibility":3},{"url":"https://cryptopotato.com/iotas-recent-2-million-attack-leaves-open-questions-to-the-projects-payment-processor-moonpay/","name":"cryptopotato.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The attacker's activity preceded the public disclosure by several months. On November 27, 2019, the attacker executed a DNS-interception proof of concept by exploiting a Cloudflare API key associated with MoonPay's infrastructure, enabling interception of all data sent to api.moonpay.io. A longer-running proof of concept was evaluated on December 22, 2019. The active attack on Trinity users began January 25, 2020, when the attacker began delivering malicious code via the CDN. On February 11, 2020, the attacker executed transactions using hijacked seeds. The IOTA Foundation halted the Coordinator on February 12, 2020, interrupting the theft. The Foundation was not informed of the unauthorized Cloudflare API access until February 15, 2020, when Cloudflare logs provided by MoonPay revealed the unsanctioned activity. The attacker is alleged to have consolidated stolen funds in 28 Gi packages, a denomination chosen to remain below exchange KYC thresholds. No individual was publicly identified or arrested in connection with the attack. The IOTA Foundation reported the incident to the Berlin Police Cyber Division, the German Center for Cybercrime, Maltese authorities, and the U.S. Federal Bureau of Investigation.","heading":"Attack Timeline and Technical Mechanics","sources":[{"url":"https://blog.iota.org/trinity-attack-incident-part-1-summary-and-next-steps-8c7ccc4d81e8/","name":"blog.iota.org","type":"other","credibility":3},{"url":"https://news.sophos.com/en-us/2020/02/18/iota-shuts-down-network-temporarily-to-fight-wallet-hacker/","name":"news.sophos.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The IOTA Foundation confirmed that 50 independent user seeds were compromised, representing the total known victim population. The aggregate amount stolen was approximately 8.55 Ti (teraIOTA), valued at roughly $2 million at the time of the attack, though some contemporaneous reports cited figures between $1.4 million and $2.3 million depending on the MIOTA price used. Affected users who had opened Trinity Wallet between December 17, 2019 and February 17, 2020 were considered at risk. On March 6, 2020, IOTA co-founder David Sonstebo publicly announced via Discord that he would personally reimburse all theft victims from his own IOTA holdings rather than draw on IOTA Foundation reserves, citing the Foundation's need to preserve its operating runway. Sonstebo stated the decision was a 'preemptive step' to protect the project. No public confirmation was issued that all reimbursements were completed.","heading":"Losses and Victim Impact","sources":[{"url":"https://blog.iota.org/trinity-attack-incident-part-1-summary-and-next-steps-8c7ccc4d81e8/","name":"blog.iota.org","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2020/03/12/iota-founder-personally-refunding-hack-losses-to-safeguard-projects-remaining-reserves","name":"coindesk.com","type":"other","credibility":3},{"url":"https://decrypt.co/21683/iota-hack-compensation-founder-david-sonstebo-discord","name":"decrypt.co","type":"other","credibility":3}],"severity":"medium"},{"content":"In response to the ongoing theft, the IOTA Foundation halted the Coordinator on February 12, 2020. The Coordinator is a centralized safety mechanism embedded in the IOTA protocol architecture that, when stopped, halts all transaction confirmations on the Tangle network. The network remained fully halted for 27 days — one of the longest network shutdowns in the history of any major cryptocurrency project. A seed migration period ran from February 29 to March 7, 2020, allowing affected users to migrate their tokens to fresh seeds. The Coordinator was restarted on March 10, 2020. The incident attracted criticism focused on IOTA's reliance on a centralized Coordinator as a single point of control, which enabled the shutdown but also demonstrated a fundamental deviation from the decentralization principles underlying most cryptocurrency networks.","heading":"Network Shutdown — Centralization Concern","sources":[{"url":"https://coinfomania.com/iota-foundation-restarts-the-coordinator/","name":"coinfomania.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/iota-network-relaunched-following-trinity-wallet-theft","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/56637/iota-foundation-expects-to-reactivate-network-by-march-2-following-2m-user-wallet-attack","name":"theblock.co","type":"other","credibility":3}],"severity":"medium"},{"content":"Post-incident reporting by the IOTA Foundation acknowledged multiple security failures on the Foundation's part. The Foundation admitted it had identified CDN delivery as a security risk at the time of MoonPay integration but proceeded with the CDN approach anyway due to release pressure and human error. The Foundation's Part 3 post-mortem committed to a suite of remediation measures, including hiring a Chief Security Officer, mandatory external security audits for critical software releases, required manual sign-off from security personnel for all third-party integrations, stricter vulnerability policies for dependencies, and enhanced real-time Tangle monitoring. A separate analysis by security firm SlowMist identified the incident as a textbook supply chain attack and highlighted the risks inherent in wallet applications loading third-party SDKs from external CDNs without integrity verification (e.g., Subresource Integrity hashes).","heading":"Security Failures and IOTA Foundation Responsibility","sources":[{"url":"https://blog.iota.org/trinity-attack-incident-part-3-key-learnings-takeaways-c933de22fd0a/","name":"blog.iota.org","type":"other","credibility":3},{"url":"https://slowmist.medium.com/slowmist-iota-analysis-4acfb477a093","name":"slowmist.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Trinity Wallet was officially deprecated on April 28, 2021 in conjunction with the IOTA Chrysalis protocol upgrade. The IOTA Foundation introduced Firefly as Trinity's replacement, with users directed to migrate their tokens using the Firefly migration tooling. Trinity's GitHub repository (iotaledger/trinity-wallet) was subsequently archived and is no longer maintained. As of 2026, Trinity Wallet is non-functional for current IOTA network operations. The GitHub repository notes: 'Trinity is IOTA's old, deprecated wallet. Use Firefly instead.' Prior to its deprecation, Trinity had recorded over 160,000 downloads and processed more than $1.8 billion in IOTA transactions across its lifetime.","heading":"Deprecation and Current Status","sources":[{"url":"https://github.com/iotaledger/trinity-wallet/","name":"github.com","type":"other","credibility":3},{"url":"https://blog.iota.org/the-next-steps-for-trinity-f9af3fc64736/","name":"blog.iota.org","type":"other","credibility":3}],"severity":"medium"},{"content":"Trinity Wallet has been flagged by on-chain investigator ZachXBT as a notable incident in the history of crypto security failures. The flagging relates to the February 2020 supply chain attack and the broader systemic concerns it raised: the IOTA Foundation's acknowledged role in deploying insecure CDN-based third-party code in a custody-sensitive application, the 27-day total network shutdown demonstrating the risks of protocol centralization, and the absence of a publicly named or prosecuted perpetrator despite multi-jurisdiction law enforcement engagement. The incident is regularly cited in academic and industry analyses of supply chain attack vectors in the cryptocurrency wallet sector.","heading":"ZachXBT Flag and Broader Community Concern","sources":[{"url":"https://medium.com/cryptronics/what-recent-supply-chain-attacks-on-iota-and-monero-can-teach-us-about-blockchain-security-36f63876b539","name":"medium.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2019-07","event":"Trinity Wallet officially released by the IOTA Foundation as the project's primary desktop and mobile wallet.","source":"IOTA Foundation Blog","source_url":"https://blog.iota.org/iota-foundation-releases-the-trinity-wallet-5e3db189fbb5/","date_original":"2019-07-01"},{"date":"2019-11-27","event":"Attacker executes DNS-interception proof of concept by leveraging a Cloudflare API key linked to MoonPay's infrastructure, beginning reconnaissance against MoonPay's CDN endpoints.","source":"IOTA Foundation — Trinity Attack Incident Part 1","source_url":"https://blog.iota.org/trinity-attack-incident-part-1-summary-and-next-steps-8c7ccc4d81e8/"},{"date":"2019-12-17","event":"IOTA Foundation later determines this date as the start of the window during which Trinity users were at risk of seed theft.","source":"IOTA Foundation — Trinity Attack Incident Part 1","source_url":"https://blog.iota.org/trinity-attack-incident-part-1-summary-and-next-steps-8c7ccc4d81e8/"},{"date":"2019-12-22","event":"Attacker evaluates a longer-running proof of concept refining malicious code and exfiltration techniques via MoonPay CDN.","source":"IOTA Foundation — Trinity Attack Incident Part 1","source_url":"https://blog.iota.org/trinity-attack-incident-part-1-summary-and-next-steps-8c7ccc4d81e8/"},{"date":"2020-01-25","event":"Active attack on Trinity users commences; malicious MoonPay SDK begins being served to Trinity Wallet instances via CDN, capturing user seeds and passwords.","source":"IOTA Foundation — Trinity Attack Incident Part 1","source_url":"https://blog.iota.org/trinity-attack-incident-part-1-summary-and-next-steps-8c7ccc4d81e8/"},{"date":"2020-02-11","event":"Attacker executes transactions using hijacked seeds, draining approximately 8.55 Ti (roughly $2 million) from 50 user accounts.","source":"IOTA Foundation — Trinity Attack Incident Part 1","source_url":"https://blog.iota.org/trinity-attack-incident-part-1-summary-and-next-steps-8c7ccc4d81e8/"},{"date":"2020-02-12","event":"IOTA Foundation halts the Coordinator, suspending the entire IOTA network to stop further theft. All transaction confirmations cease.","source":"CoinDesk","source_url":"https://www.coindesk.com/tech/2020/02/13/iota-foundation-suspends-network-probes-fund-theft-in-trinity-wallet"},{"date":"2020-02-15","event":"IOTA Foundation receives Cloudflare logs from MoonPay confirming unsanctioned API access dating to November 2019.","source":"IOTA Foundation — Trinity Attack Incident Part 1","source_url":"https://blog.iota.org/trinity-attack-incident-part-1-summary-and-next-steps-8c7ccc4d81e8/"},{"date":"2020-02-17","event":"IOTA Foundation establishes end of the at-risk window for Trinity users.","source":"IOTA Foundation — Trinity Attack Incident Part 1","source_url":"https://blog.iota.org/trinity-attack-incident-part-1-summary-and-next-steps-8c7ccc4d81e8/"},{"date":"2020-02-29","event":"Seed migration period opens; IOTA Foundation releases dedicated migration tool for Trinity users to transfer funds to new seeds.","source":"IOTA Foundation — Trinity Attack Incident Part 2","source_url":"https://blog.iota.org/trinity-attack-incident-part-2-trinity-seed-migration-plan-4c52086699b6/"},{"date":"2020-03-06","event":"IOTA co-founder David Sonstebo announces via Discord he will personally reimburse all theft victims from his own IOTA holdings to protect Foundation reserves.","source":"Decrypt","source_url":"https://decrypt.co/21683/iota-hack-compensation-founder-david-sonstebo-discord"},{"date":"2020-03-07","event":"Seed migration period closes.","source":"IOTA Foundation — Trinity Attack Incident Part 2","source_url":"https://blog.iota.org/trinity-attack-incident-part-2-trinity-seed-migration-plan-4c52086699b6/"},{"date":"2020-03-10","event":"IOTA Foundation restarts the Coordinator after 27 days of network suspension; IOTA network returns to normal operation.","source":"CoinTelegraph","source_url":"https://cointelegraph.com/news/iota-network-relaunched-following-trinity-wallet-theft"},{"date":"2021-04-28","event":"Trinity Wallet officially deprecated with the Chrysalis protocol upgrade. Firefly wallet released as the replacement; users directed to migrate.","source":"GitHub — iotaledger/trinity-wallet","source_url":"https://github.com/iotaledger/trinity-wallet/"}],"sources_used":[{"url":"https://blog.iota.org/trinity-attack-incident-part-1-summary-and-next-steps-8c7ccc4d81e8/","name":"Trinity Attack Incident Part 1: Summary and next steps — IOTA Foundation","type":"official","archive_url":"http://web.archive.org/web/20260418005639/https://blog.iota.org/trinity-attack-incident-part-1-summary-and-next-steps-8c7ccc4d81e8/","credibility":1,"archive_timestamp":"2026-04-18T00:56:39+00:00"},{"url":"https://blog.iota.org/trinity-attack-incident-part-2-trinity-seed-migration-plan-4c52086699b6/","name":"Trinity Attack Incident Part 2: Trinity Seed Migration Plan — IOTA Foundation","type":"official","archive_url":"https://web.archive.org/web/20260725191042/https://blog.iota.org/trinity-attack-incident-part-2-trinity-seed-migration-plan-4c52086699b6/","credibility":1,"archive_timestamp":"2026-07-25T19:10:42+00:00"},{"url":"https://blog.iota.org/trinity-attack-incident-part-3-key-learnings-takeaways-c933de22fd0a/","name":"Trinity Attack Incident Part 3: Key Learnings and Takeaways — IOTA Foundation","type":"official","archive_url":"https://web.archive.org/web/20260725035117/https://blog.iota.org/trinity-attack-incident-part-3-key-learnings-takeaways-c933de22fd0a/","credibility":1,"archive_timestamp":"2026-07-25T03:51:17+00:00"},{"url":"https://www.coindesk.com/business/2020/03/12/iota-founder-personally-refunding-hack-losses-to-safeguard-projects-remaining-reserves","name":"IOTA Founder Personally Refunding Hack Losses — CoinDesk","type":"news_article","archive_url":"https://web.archive.org/web/20260724182352/https://www.coindesk.com/business/2020/03/12/iota-founder-personally-refunding-hack-losses-to-safeguard-projects-remaining-reserves","credibility":1,"archive_timestamp":"2026-07-24T18:23:52+00:00"},{"url":"https://www.coindesk.com/tech/2020/02/13/iota-foundation-suspends-network-probes-fund-theft-in-trinity-wallet","name":"IOTA Foundation Suspends Network, Probes Fund Theft in Trinity Wallet — CoinDesk","type":"news_article","archive_url":"https://web.archive.org/web/20260724183628/https://www.coindesk.com/tech/2020/02/13/iota-foundation-suspends-network-probes-fund-theft-in-trinity-wallet","credibility":1,"archive_timestamp":"2026-07-24T18:36:28+00:00"},{"url":"https://cointelegraph.com/news/iota-network-relaunched-following-trinity-wallet-theft","name":"IOTA Network Relaunched Following Trinity Wallet Theft — CoinTelegraph","type":"news_article","archive_url":"http://web.archive.org/web/20260314022114/https://cointelegraph.com/news/iota-network-relaunched-following-trinity-wallet-theft","credibility":1,"archive_timestamp":"2026-03-14T02:21:14+00:00"},{"url":"https://www.theblock.co/post/56637/iota-foundation-expects-to-reactivate-network-by-march-2-following-2m-user-wallet-attack","name":"IOTA Foundation Expects to Reactivate Network by March 2 — The Block","type":"news_article","archive_url":"https://web.archive.org/web/20260725041832/https://www.theblock.co/post/56637/iota-foundation-expects-to-reactivate-network-by-march-2-following-2m-user-wallet-attack","credibility":1,"archive_timestamp":"2026-07-25T04:18:32+00:00"},{"url":"https://www.theblock.co/linked/58337/iota-is-back-online-nearly-a-month-after-2-million-attack-on-wallet-software-users","name":"IOTA is Back Online Nearly a Month After $2 Million Attack — The Block","type":"news_article","archive_url":null,"credibility":1,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://decrypt.co/21683/iota-hack-compensation-founder-david-sonstebo-discord","name":"IOTA Hack Compensation — Founder David Sonstebo Discord Announcement — Decrypt","type":"news_article","archive_url":"http://web.archive.org/web/20260416045714/https://decrypt.co/21683/iota-hack-compensation-founder-david-sonstebo-discord","credibility":2,"archive_timestamp":"2026-04-16T04:57:14+00:00"},{"url":"https://cryptopotato.com/iotas-recent-2-million-attack-leaves-open-questions-to-the-projects-payment-processor-moonpay/","name":"IOTA's Recent $2 Million Attack Leaves Open Questions To MoonPay — CryptoPotato","type":"news_article","archive_url":"http://web.archive.org/web/20260112234426/https://cryptopotato.com/iotas-recent-2-million-attack-leaves-open-questions-to-the-projects-payment-processor-moonpay/","credibility":2,"archive_timestamp":"2026-01-12T23:44:26+00:00"},{"url":"https://news.sophos.com/en-us/2020/02/18/iota-shuts-down-network-temporarily-to-fight-wallet-hacker/","name":"IOTA Shuts Down Network Temporarily to Fight Wallet Hacker — Sophos News","type":"news_article","archive_url":"https://web.archive.org/web/20260724180434/https://www.sophos.com/en-us/blog/iota-shuts-down-network-temporarily-to-fight-wallet-hacker","credibility":2,"archive_timestamp":"2026-07-24T18:04:34+00:00"},{"url":"https://slowmist.medium.com/slowmist-iota-analysis-4acfb477a093","name":"SlowMist: Analysis and Security Suggestions for the IOTA Major Coin Stolen Incident","type":"research","archive_url":"http://web.archive.org/web/20250909130048/https://slowmist.medium.com/slowmist-iota-analysis-4acfb477a093","credibility":2,"archive_timestamp":"2025-09-09T13:00:48+00:00"},{"url":"https://medium.com/cryptronics/what-recent-supply-chain-attacks-on-iota-and-monero-can-teach-us-about-blockchain-security-36f63876b539","name":"What Recent Supply Chain Attacks on IOTA and Monero Can Teach Us — Cryptonics/Medium","type":"research","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://coinfomania.com/iota-foundation-restarts-the-coordinator/","name":"27 Days Later: IOTA Foundation Finally Restarts The Coordinator — CoinFomania","type":"news_article","archive_url":"https://web.archive.org/web/20260725035352/https://coinfomania.com/iota-chrysalis-update-ahead-of-coordicide/","credibility":2,"archive_timestamp":"2026-07-25T03:53:52+00:00"},{"url":"https://github.com/iotaledger/trinity-wallet/","name":"GitHub — iotaledger/trinity-wallet (archived repository)","type":"official","archive_url":null,"credibility":1,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:55:01.28657+00:00","updated_at":"2026-08-29T01:34:55.316+00:00"}}