Cybersecurity Firm Hacks Trezor Hardware Wallet Using Three-Year-Old Exploit

Cybersecurity Firm Hacks Trezor Hardware Wallet Using Three-Year-Old Exploit
фото показано с : beincrypto.com

2023-5-25 10:30

Cybersecurity firm Unciphered has posted a video in which it claims to have hacked a Trezor hardware wallet.

Cybersecurity startup Unciphered claims to have infiltrated the security of the popular Trezor T model hardware crypto wallet.

On May 24, the team posted a video of them extracting the wallet’s mnemonic seed phrase or private key.

The cryptocurrency recovery firm took the Trezor apart to remove the internal circuit board. It was connected to its lab equipment which enabled the extraction of the device’s firmware.

Trezor Vulnerability Revealed

It then used powerful GPUs (graphics processing units) to work on the extraction.

Unciphered co-founder Eric Michaud said:

“We uploaded the firmware we extracted onto our high-performance computing cracking clusters. We have about 10 GPUs … and it took a little while but we extracted the PIN.”

He also stated that the retrieval was made possible by an “exploit that we developed in-house.” The team also had to write custom code to achieve the hack, which he explained was “extremely hard.”

Screenshot from Unciphered Trezor hack video – YouTube

Michaud stated that the exploit was not fixable with firmware updates. “In order to fix this, Satoshi Labs would have to recall all of their products,” he said before adding, “which they’re likely not going to do.”

Trezor responded to the experiment by stating that its team didn’t have enough details about this specific hack. It added that it appeared to be an “RDP [Read Protection] downgrade attack,” which was publicly flagged as a risk in early 2020.

“The RDP Downgrade attack is a precise attack that targets the hardware vulnerability of STM32 microchips used in the Trezor One and Trezor Model T hardware wallets,” it stated at the time.

Furthermore, the attack requires physical theft of the device, “extremely sophisticated technological knowledge and advanced equipment.”

Hardware Wallet Security Scrutinized

The revelation comes just a week after rival firm Ledger was involved in another PR imbroglio. Crypto Twitter was awash with comments calling for the dumping of Ledger in favor of Trezor, but that trend has now been quashed.

Ledger was lambasted last week for launching a recovery service that gave it control over the storage of seed phrases. The former CEO admitted the device was not trustless, and the current CEO, Pascal Gauthier, apologized for the firm’s latest foul-up.

It appears that no hardware wallet is 100% safe, despite what the manufacturers’ marketing departments claim.

The post Cybersecurity Firm Hacks Trezor Hardware Wallet Using Three-Year-Old Exploit appeared first on BeInCrypto.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Atomic Wallet Coin (AWC) на Currencies.ru

$ 0.0562034 (+2.30%)
Объем 24H $2.833k
Изменеия 24h: 0.22 %, 7d: 0.99 %
Cегодня L: $0.0549388 - H: $0.0562034
Капитализация $595.961k Rank 1868
Цена в час новости $ 0.7937 (-92.92%)

hardware wallet trezor cybersecurity firm three-year-old exploit

hardware wallet → Результатов: 126


Фото:

Sony Announces the Development of a Multi-Purpose Cryptocurrency Hardware Wallet

Sony’s research and development division, dubbed Sony Computer Science Laboratories Inc., announced on October 23, it has created a contactless IC card cryptocurrency hardware wallet. The Japanese tech giant utilizes its years of experience with contactless IC card technology, to develop a small and portable hardware wallet, which aims to improve usability and security compared to […] Sony Announces the Development of a Multi-Purpose Cryptocurrency Hardware Wallet was originally found on [blokt] - Blockchain, Bitcoin & Cryptocurrency News.

2018-10-26 15:29


Фото:

Unhackable? McAfee Hardware Wallet Uses Parts From ‘Cheap’ Smartphones

John McAfee and cryptocurrency hardware manufacturer Bitfi are facing heavy criticism after photos of the pair’s new wallet appeared online. ‘No Sign Of A Secure Element’ The Bitfi hardware wallet, which creators claim is “unhackable,” in fact runs off a standard motherboard common in “cheap” smartphones, social media users claim.

2018-7-30 18:00


Ledger Crypto Hardware Wallet Officially Adds Tron (TRX) & Zcoin (XZC)

Ledger Officially Adds Two Cryptocurrencies to Its list of Support Safely securing cryptocurrencies have always been an essential step, especially for investors who have large holdings. Of the many hardware wallets that have been making it to the market, that of the Ledger has been preferred by many. In particular, their operating system called BOLOS […]

2018-7-19 22:05


Sirin Labs Releasing $1000 Blockchain Phone

Sirin, a Swiss tech hardware company, has announced the release of a $1000 blockchain powered smart phone to be released later this year. The phone is called ‘Finney’ and will come with blockchain features such as a secure P2P resource-sharing utility, a built-in cold storage crypto wallet that will support all major cryptocurrencies and tokens,… The post Sirin Labs Releasing $1000 Blockchain Phone appeared first on UNHASHED.

2018-7-12 00:43


Crypto Wallet Ledger Introduces Ledger Live for Desktop

In a bid to appeal to more cryptocurrency investors, hardware wallet provider Ledger announced its new offering — Ledger Live. CEO Eric Larcheveque announced the new software in a blog post, stating that the company’s mission is to: “Ensure that everyone who owns crypto assets can keep them safe, using the most advanced security technology […] Crypto Wallet Ledger Introduces Ledger Live for Desktop was originally found on [blokt] - Blockchain, Bitcoin & Cryptocurrency News.

2018-7-11 16:14


Ledger Live: Crypto Hardware Wallet’s All in One Real Time Pricing App Launches

Cryptocurrency Wallet Manufacturer Ledger Launches New Software Known as ‘Ledger Live’ One of the most important hardware wallets manufacturers in the market, Ledger, has launched a new application for Ledger devices – including the Ledger Nano S and the Ledger Blue – that is known as ‘Ledger Live.’ The information has been released on July […]

2018-7-10 21:08