Leap Wallet: Sunset Notice
After careful consideration, we've made the decision to sunset Leap Wallet and its associated products.
The products will be sunset on 28th May, 2026, and all users should complete their migration before then.
We started Leap in 2022 to redefine what wallet experiences in crypto mean. Over time, that journey expanded across multiple ecosystems and 100+ chains. Through every phase, the team approached the work with conviction, care, and a deep sense of responsibility to the users and communities we served.
This decision was not made lightly. We continue to believe in the long-term future of crypto and the interchain ecosystem, and we remain supporters of the builders still in the arena.
What's being sunset
The following products will be sunset after 28th May, 2026:
• Leap Wallet (Extension, iOS, Android)
• Compass Wallet (Extension, iOS, Android)
• Leap WebApp
• Swapfast
• Leap Cosmos Hub Validator
• Leap Cosmos Snaps
Until that date, all wallet products listed above will retain their existing core functionality. You will still be able to view balances, send tokens, manage staking positions, and export your recovery phrase and private keys. All other products listed above will likewise retain their existing functionality until 28th May, 2026.
What users need to do
If you are using one of Leap’s wallet products, we recommend migrating your wallets to another wallet like Keplr, MetaMask, Phantom, or Rabby.
Because Leap is a non-custodial wallet, your assets live on the blockchain, not in our apps. As long as you have your recovery phrase, you can continue to access your assets through another compatible wallet by importing that recovery phrase. Your addresses and balances will carry over automatically.
If you have ATOM delegated to Leap’s Cosmos Hub validator, please redelegate to another validator to continue earning staking rewards. We encourage doing this as early as possible to account for network unbonding periods.
Detailed migration guide and FAQs can be found on the website - https://t.co/kVQa7HM32y
What to expect next
After 28th May, 2026, all Leap products will be sunset and will no longer function, including applications already installed in your browser or on your mobile device.
Even if you do not migrate from Leap to another wallet before that date, you can still recover access to your assets by importing your recovery phrase into another supported wallet
Migration support will be available through our official support channels until 28th May, 2026 at [email protected]
Thank You
Thank you to all our users, for letting us serve you through so many market cycles.
Thank you to our amazing partners, for helping us build experiences & worlds we never thought possible.
Thank you for Leaping with us.
🐸 💚
🚨 Blockaid detected an ongoing exploit targeting the SquidRouterModule on Ethereum and Base.
86 Gnosis Safes drained for ~$3M in ~2 hours.
All stolen tokens swapped to DAI via attacker-controlled Uniswap V3 pools.
More details in 🧵
AI 驱动的加密交易工具 Bankr 再次成为安全焦点。据官方确认,黑客通过社会工程学手段成功访问了 14 个用户钱包,这已经是一个月内的第二次了。
就在不久前,攻击者利用摩斯电码向 AI 注入恶意指令,绕过 Bankr 的安全过滤器,诱导其将 @grok 钱包中积累的约 $170,000 资产悉数转走。而 Grok 对此毫不知情,AI 自愿完成了整个转账过程。
接连不断的事故,不仅是 Bankr 一个项目的挑战,更是为整个"AI 钱包 / 交易机器人"赛道敲响了警钟。
1️⃣ AI 钱包的"阿喀琉斯之踵":私钥托管与服务器风险
目前市场上主流的 AI 钱包,为了实现自动化交易和智能决策,其核心逻辑往往建立在服务器端私钥生成的基础上。
这意味着,无论该项目的安全团队水平有多高、防火墙有多厚,用户的私钥在理论和事实上都处于联网状态。在黑客眼中,托管私钥的服务器就是一个巨大的"蜜罐"。一旦服务器权限被攻破,或内部管理出现疏忽,海量用户的资产将面临"一锅端"的风险。
2️⃣ 社会工程学与 Prompt Injection:新旧威胁的叠加
这次 Bankr 事件的切入点是社会工程学,但 AI 钱包真正危险的地方在于:攻击面比传统钱包多了一层。
黑客不仅可以通过钓鱼攻击、伪装官方身份来欺骗用户,还可以直接向 AI 系统注入恶意指令(Prompt Injection)。在 AI 钱包的交互场景中,用户往往因为信任"智能自动化"而降低警惕。一旦 AI 助理被投毒,用户可能根本不知道自己的钱包已经签署了一笔恶意交易。
3️⃣ 智能不代表安全,便捷不应以资产主权为代价
AI 钱包确实带来了前所未有的交易体验:自动抄底、智能策略、自然语言交互。但这不应成为牺牲资产安全主权的理由。
面向普通用户,我们建议:
🔹尝试新技术没问题,但请将 AI 钱包定位为"小额试验场",只存入即便丢失也不心痛的资金。
🔹真正的大额资产、核心仓位,必须回归去中心化的本质,用硬件钱包保护。
面对 AI 时代的复杂威胁,Keystone 始终坚持物理层面的绝对隔离:
🔹私钥离线生成: 你的私钥仅在硬件设备中生成,永不触网,从根本上杜绝"服务器端失窃"的可能。
🔹拒绝盲签: 所有交易细节都会在 Keystone 大屏幕上完整还原,只有经过你的物理确认,资产才会被允许流转。
QR 码通信: 彻底切断 USB 或蓝牙连接带来的潜在后门攻击
你的私钥,只应该存在于你手中的设备里。「Not your keys, not your coins」在 AI 时代,更值得认真对待。
We are continuing to investigate yesterday’s incident and are working through a full security review with internal and external teams. As a precautionary measure, certain Bankr functionality will remain temporarily disabled while we complete that process. Services will be re-enabled once we are confident the platform is secure. We appreciate everyone’s patience and will continue to share updates as appropriate.
We are also coordinating with law enforcement, including the FBI, as well as relevant third parties and counterparties in efforts to identify, freeze, and recover assets where possible and support potential enforcement actions against the responsible actors.
Wohooo, you can now use Ambire with @KeystoneWallet 🎊
Enjoy easy self-custody paired with air-gapped hardware security. Try it out and let us know how you like it!
🚨 Threat Intelligence | Analysis of a Fake TronLink Chrome Extension Phishing Campaign 🚨
SlowMist’s MistEye threat monitoring system recently detected a high-risk phishing campaign targeting #TRON wallet users. Attackers created a fake Chrome MV3 extension impersonating @TronLinkWallet, using Unicode bidirectional control characters and Cyrillic homoglyphs to spoof the brand name. Once installed, it loads a full phishing page via remote iframe — forming a “shell-core separation” credential theft chain.
🔍 Key Findings:
🔹 The extension name uses homoglyphs for disguise. Its Chrome Web Store page inherits the real extension’s high user count and positive reviews, significantly lowering review barriers.
🔹 Local code is extremely minimal — it only loads a remote page, making static analysis almost useless for detecting malice.
🔹 The remote phishing page perfectly replicates the official TronLink Web wallet UI, stealing mnemonic phrases, private keys, Keystore files, and passwords, then exfiltrating them in real time via Telegram Bot.
🔹 Built-in anti-analysis features (disables right-click, DevTools, drag-and-drop, printing) and geo/language-based redirection for Russian users to evade detection.
⚠️ This is not a simple fake extension — it employs advanced techniques like remote dynamic loading and anti-forensics, making it extremely difficult for traditional static scanners to catch.
🛡️ Immediate Actions :
• Uninstall any suspicious extension (Malicious ID: ekjidonhjmneoompmjbjofpjmhklpjdd)
• Official TronLink extension ID: ibnejdfjmmkpcnlpebklmnkoeoihofec
• Clear localStorage and check for abnormal traffic
• If credentials were entered, create a new wallet immediately and transfer assets
📖 Full technical analysis + IOCs + self-check guide here 👇
https://t.co/wWIeaKxX4z