Wallet.Fail: What Does It Mean For Hardware Wallet Security?

2018-12-30 20:13

This week, a group of security researchers gave a presentation called Wallet.Fail at the #35C3 Security Conference. During the presentation, the team outlined vulnerabilities in three popular hardware wallets.

Since hardware wallets are widely considered the most secure form of crypto storage, these discoveries could present a serious issue. However, wallet manufacturers are assuring users that the attacks are impractical and that their wallets are safe.

So, who should you trust? If you are a hardware wallet owner, this is what you need to know.

The Attacks In Brief

The Wallet.fail team managed to attack three different wallet models using four different lines of attack. These attacks were performed in controlled circumstances and have not been proven to be effective against real users:

Ledger Nano S: The team was able to install a hardware implant in this device. Combined with spyware, this allowed the team to obtain the wallet’s PIN the next time the wallet was used. Ledger Nano S: In a second attack on the same device, the team installed custom firmware and gained partial access to the device. The Wallet.fail team claims that they were able to send malicious transactions and display false transactions via this method. Ledger Blue: The team was able to intercept radio signals used by the device in order to obtain the wallet’s PIN the next time the device was used. Trezor One: The team was able to flash the device with custom firmware and obtain private keys, allowing the team to access funds stored in the wallet. A Serious Threat?

All of these issues appear to be fairly serious, but Trezor and Ledger have called the viability of the attacks into question. Ledger has argued that Wallet.fail’s attacks are impractical due to the fact they require attackers to have direct access to—and/or prolonged proximity to—each device.

Furthermore, some of these attacks hinge on discovering a PIN, and as Ledger notes, there are far simpler ways to go about stealing a PIN. Assuming that an attacker knows where a hardware wallet is being used, it would be much easier for that attacker to install a camera and then watch the owner enter their PIN.

Suggested Reading : Take a look at our picks for the best IOTA wallets.

Fixes On the Way

Although Trezor and Ledger have reassured users that their wallets are safe, the manufacturers do intend to implement a few security improvements as part of future updates:

Ledger Nano S: There is no direct way of preventing hardware implants, but Ledger is reminding users that they can easily open their device and check for modifications. Ledger Nano S: A minor bug is being addressed in the firmware upgrade process. However, Ledger claims this bug allows far less access to the device than the Wallet.fail team claims. Ledger Blue: To prevent attackers from observing PIN entry over radio waves, the device’s touchscreen will use a randomized keyboard in future updates. Trezor One: Trezor has announced that a firmware update is planned for the end of January, but has not specified any details. It also notes that the device’s passphrase feature can prevent the attack.

In short, it seems that hardware wallets remain much more secure than software and web wallets, which are susceptible to remote attacks. Furthermore, it seems that upcoming fixes will eliminate the Wallet.fail vulnerabilities entirely.

Even at the moment, most of the Wallet.fail attacks require that attackers have prolonged and direct access to a hardware wallet – meaning that those who use hardware wallets in public settings are slightly at risk. Those who use hardware wallets privately face virtually no risk at all.

The post Wallet.Fail: What Does It Mean For Hardware Wallet Security? appeared first on UNHASHED.

Similar to Notcoin - Blum - Airdrops In 2024

origin »

TokenStars (TEAM) на Currencies.ru

$ 0 (-0.07%)
Объем 24H $0
Изменеия 24h: 2.23 %, 7d: 15.07 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Цена в час новости $ 0.0042796 (-100%)

wallet hardware security fail wallets mean does

wallet hardware → Результатов: 126


How To Make a Hardware Wallet – Can You Create Your Own Hardware Wallet?

It is quite feasible to create your own hardware wallet. However, an identical replica of a Trezor or Ledger would be impossible to produce. Let’s have a look at the gist of what you can expect from a commercial hardware wallet: it has a separate chip in the device, which creates and saves private keys, […] The post How To Make a Hardware Wallet – Can You Create Your Own Hardware Wallet? appeared first on CaptainAltcoin.

2022-9-15 14:23


D’Cent Crypto Hardware Wallet: Bitcoin Smart Contract Ready Storage?

What Is D'Cent Crypto Hardware Wallet? D’Cent is an advanced cryptocurrency hardware wallet and is the world’s first hardware wallet in the market that implements Bitcoin smart contracts. D’Cent also runs on the RSK network, which provides it with the ability to support DApp platforms using RSK and RRC-20 tokens like RIF and TEMCO. The hardware wallet […]

2019-2-20 11:18


Lisk [LSK], Bitcoin Private [BTCP] and 6 others gather support from Trezor

Today, Lisk [LSK] announced on Twitter that they have got support from Trezor, a hardware wallet providing security without sacrificing convenience. Earlier, Trezor had also announced that they have expanded coin and token support for Decred [DCR], Bitcoin Private [BTCP], Fujicoin [FJC], Groestlcoin [GRS], Vertcoin [VTC], Viacoin [VIA], and Zcoin [BUZZ]. Lisk’s post on Twitter | Source: Twitter […]

2018-6-29 02:06


John Mcafee’s “UN-HACKABLE” Hardware Wallet Sold Out In Just Twenty Two Minutes

Early last month, John McAfee announced on twitter that he was launching his own cryptocurrency, regarded as the McAfee coin which will come in fiat currencies (collectible) backed by crypto. While Crypto Fans were anticipating its release, the computer programmer now widely recognized for his strong presence as an active influencer in the cryptocurrency space […] The post John Mcafee’s “UN-HACKABLE” Hardware Wallet Sold Out In Just Twenty Two Minutes appeared first on ZyCrypto.

2018-6-29 01:40


Фото:

Just How ‘Cool’ is the CoolWallet S? (Review)

The CoolWallet S by CoolBitX is a credit-card-like hardware wallet for storing Bitcoin (BTC), Ethereum (ETH), Litecoin (LTC), Ripple (XRP), Bitcoin Cash (BCH), and select ERC20 tokens — but just how “cool” is it? Let’s find out!  Design First and foremost, let’s get one thing straight — you’re not going to find a ‘cooler’ looking hardware wallet anywhere on the market today.

2018-6-24 17:00


Фото:

Crypto Hardware Wallet Maker, Ledger, собрал $ 75 миллионов

Согласно заявлению на их официальном сайте, Леджер, компания, стоящая за популярным аппаратным кошельком, сумела собрать впечатляющие 75 миллионов долларов в раунде серии B. Поскольку за последние трейдеры и пользователи подвергались все большему уровню кибератак.

2018-6-22 15:10


Bitfi launching open source crypto wallet and 1st hardware wallet for Monero

Bitfi, a global payments technology company working to enable businesses and consumers to participate in the digital currency economy, today announced Bitfi Knox Wallet – the first unhackable, open source hardware wallet with an accompanying dashboard that features wireless setup and support for many popular cryptocurrencies and crypto assets, including Monero, a fully decentralized private cryptocurrency that has previously never had a hardware wallet solution.

2018-6-14 13:42