hava 21° Çoğunlukla Bulutlu
DOLAR 20,3135 % % 1.09
EURO 21,8683 % % 1.21
GRAM ALTIN 1.269,40 % % 1,01
ÇEYREK A. 2.075,48 % % 1,01
BITCOIN 27.747,75 % -0.688
SON DAKİKA
Google News

Cryptosecurity firm finds a vector to hack a Trezor T wallet

Son Güncelleme :

25 Mayıs 2023 - 1:59

Cryptosecurity firm finds a vector to hack a Trezor T wallet

Key facts:
  • In a test, Unciphered demonstrated how to recover a startup phrase and PIN from a Trezor T.

  • Trezor speculates that they used a known and reported vulnerability from 2020.

Unciphered, a cryptosecurity firm that is dedicated to recovering lost or stolen cryptocurrency, claims to have discovered a way to access the Trezor T hardware wallet. This type of hack is only possible with physical access to the device and is disclosed in the midst of a controversy surrounding the security of Bitcoin hardware wallets.

According to the company, the method is based on taking advantage of a vulnerability in the STM32 chip, present in the One and T models, which allows obtaining the integrated flash and the data on a single write (OTP). Unciphered ensures that the vulnerability cannot be patched at the chip level, according to statements that the company offered to the Coindesk media outlet.

This would be the first time that information about a hack to a Trezor model T has been disclosed. However, it would not be the first hack of this type to a hardware wallet from the Trezor company, since in January a video was released where USD 2 was recovered million of a One model, as reported by CriptoNoticias. “That video shows a hack of a Trezor One with old firmware, our hack is for a Trezor T with the latest firmware”, indicates the cryptosecurity company in a tweet.

According to Coindesk’s account, Unciphered made a video about different faces of hacking run on a Trezor T that the media outlet provided for that purpose. There they demonstrated that they resurfaced the initial phrase and the PIN of the device. The cryptosecurity firm would have hacked EthereumWallet in the past and they state on their home page that they could hack any wallet on the market.

This video shows some steps that were followed to demonstrate the Trezor T vulnerability. Source: Unciphered / YouTube.

For his part, Trezor told the outlet that they do not have enough information from Unciphered to understand what method they used. However, they presume that it could be an “RDP downgrade attack”. As Trezor reported on its blog in 2020, a “read protection downgrade,” or RDP, attack requires the physical theft of a device to execute, extremely sophisticated technological knowledge, and advanced equipment.

Unciphered also ensures that they are not in a position to affirm or deny whether the Trezor T hack was done via an RDP downgrade attack, citing “current commitments and non-disclosure agreements” on how to exploit this vulnerability.

“In addition, any technical disclosure would put Satoshilabs customers at potential risk until mitigations such as a new chip other than the STM32 in current use are used,” according to statements by Unciphered.

Who are responsible

Unciphered criticized that Trezor has not done anything, beyond reporting the vulnerability of the STM32 chip in 2020. “The fact is that through this article they are trying to put the responsibility of protecting their device on the client instead of assuming the responsibility responsibility to admit that your device is fundamentally insecure,” Unciphered told CoinDesk.

“Contrary to Unciphered’s claims, Trezor has already taken significant steps to resolve this with the development of the world’s first transparent and auditable secure element through sister company Tropic Square,” Trezor said.

Controversies around hardware wallets

This fact coincides with the controversy sparked by a controversial Ledger update. As CriptoNoticias reported, the bitcoiner community criticized a new feature that allows Ledger users to save their recovery seed in the cloud. As a consequence, Ledger decided to delay the release of the feature called Recover.



#Cryptosecurity #firm #finds #vector #hack #Trezor #wallet

YORUM ALANI

YASAL UYARI! Suç teşkil edecek, yasadışı, tehditkar, rahatsız edici, hakaret ve küfür içeren, aşağılayıcı, küçük düşürücü, kaba, pornografik, ahlaka aykırı, kişilik haklarına zarar verici ya da benzeri niteliklerde içeriklerden doğan her türlü mali, hukuki, cezai, idari sorumluluk içeriği gönderen kişiye aittir.

DÖVİZ KURLARI

Dolar DOLAR

ALIŞ

20,3089

SATIŞ

20,3135

FARK

% 1.09
Dolar EURO

ALIŞ

21,7988

SATIŞ

21,8683

FARK

% 1.21
Dolar İNG. STERLİNİ

ALIŞ

25,1950

SATIŞ

25,2884

FARK

% 1.26
Dolar İSV. FRANGI

ALIŞ

22,4086

SATIŞ

22,4236

FARK

% 0.88
Dolar KAN. DOLARI

ALIŞ

14,9470

SATIŞ

14,9557

FARK

% 1.12
Dolar ÇEYREK ALTIN

ALIŞ

2.030,67

SATIŞ

2.075,48

FARK

% 1,01
Dolar GRAM ALTIN

ALIŞ

1.269,17

SATIŞ

1.269,40

FARK

% 1,01
Dolar BITCOIN

FİYAT

27.747,75

DEĞİŞİM

-0.688

ÇOK KAZANANLAR

  • KONKA33.04 9.99%
  • YESIL3.76 9.94%
  • GARAN27.46 9.23%
  • AKBNK16.22 8.93%
  • YKBNK10.17 8.89%

ÇOK KAYBEDENLER

  • MARKA16.00 -6.71%
  • SAMAT16.30 -4.73%
  • VANGD7.20 -4.38%
  • KLGYO2.28 -2.98%
  • SUWEN62.35 -2.58%

İŞLEM GÖRENLER

  • THYAO147.10 0.75%
  • ISCTR11.49 7.89%
  • KCHOL80.70 5.91%
  • AKBNK16.22 8.93%
  • GARAN27.46 9.23%