Trinity Wallet
Summary
Trinity Wallet was the official desktop and mobile software wallet for the IOTA cryptocurrency, developed and maintained by the IOTA Foundation. In February 2020, a supply chain attack exploiting a compromised MoonPay SDK delivered via CDN resulted in the theft of approximately 8.55 Ti (teraIOTA) worth roughly $2 million from 50 user seeds, forcing the IOTA Foundation to shut down the entire IOTA network for 27 days. Trinity was subsequently deprecated in April 2021 following the Chrysalis protocol upgrade, with the Firefly wallet introduced as its replacement.
Connected Entities
1 entities · 10 linked investigations- + 4 more
Timeline(14 events)
2019-07-01
Trinity Wallet officially released by the IOTA Foundation as the project's primary desktop and mobile wallet.
IOTA Foundation Blog2019-11-27
Attacker executes DNS-interception proof of concept by leveraging a Cloudflare API key linked to MoonPay's infrastructure, beginning reconnaissance against MoonPay's CDN endpoints.
IOTA Foundation — Trinity Attack Incident Part 12019-12-17
IOTA Foundation later determines this date as the start of the window during which Trinity users were at risk of seed theft.
IOTA Foundation — Trinity Attack Incident Part 12019-12-22
Attacker evaluates a longer-running proof of concept refining malicious code and exfiltration techniques via MoonPay CDN.
IOTA Foundation — Trinity Attack Incident Part 12020-01-25
Active attack on Trinity users commences; malicious MoonPay SDK begins being served to Trinity Wallet instances via CDN, capturing user seeds and passwords.
IOTA Foundation — Trinity Attack Incident Part 12020-02-11
Attacker executes transactions using hijacked seeds, draining approximately 8.55 Ti (roughly $2 million) from 50 user accounts.
IOTA Foundation — Trinity Attack Incident Part 12020-02-12
IOTA Foundation halts the Coordinator, suspending the entire IOTA network to stop further theft. All transaction confirmations cease.
CoinDesk2020-02-15
IOTA Foundation receives Cloudflare logs from MoonPay confirming unsanctioned API access dating to November 2019.
IOTA Foundation — Trinity Attack Incident Part 12020-02-17
IOTA Foundation establishes end of the at-risk window for Trinity users.
IOTA Foundation — Trinity Attack Incident Part 12020-02-29
Seed migration period opens; IOTA Foundation releases dedicated migration tool for Trinity users to transfer funds to new seeds.
IOTA Foundation — Trinity Attack Incident Part 22020-03-06
IOTA co-founder David Sonstebo announces via Discord he will personally reimburse all theft victims from his own IOTA holdings to protect Foundation reserves.
Decrypt2020-03-10
IOTA Foundation restarts the Coordinator after 27 days of network suspension; IOTA network returns to normal operation.
CoinTelegraph2021-04-28
Trinity Wallet officially deprecated with the Chrysalis protocol upgrade. Firefly wallet released as the replacement; users directed to migrate.
GitHub — iotaledger/trinity-walletDecision Log
- hash: 3NtR9BEacnv6KmzMbyGrS6KwMPUjwjbuKGNwkZDcbRaV
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:55:01 AM
last updated: 5/28/2026, 6:46:24 PM
avoid.net — verified advice for a post-truth world