Unciphered Claims to Physically Hack Trezor T Hardware Wallet, Revealing Vulnerability

Unciphered Claims to Physically Hack Trezor T Hardware Wallet, Revealing Vulnerability


Cybersecurity professionals Unciphered claim to have found an unpatchable hardware vulnerability allowing them to physically hack into the Trezor T hardware wallet, as demonstrated in a lab video, but manufacturer Trezor says it was previously aware of the vulnerability and the wallet is still protected by a strong passphrase.

Unciphered, a company of cybersecurity professionals who recover lost digitalย currency, reveals it found a way to physically hack into the Trezor T hardware wallet. Trezor reveals it acknowledged a similar-sounding attack vector severalย  years ago.

A company of cybersecurity professionals who specialize in recovering lost or stolen digitalย currency say they have found a way to hack into ourย  trending Trezor T hardware wallet once itโ€™s in their physical possession.

Unciphered informed CoinDesk in an extensive series of conversations and over email it made use of an โ€œunpatchable hardware vulnerability with the STM32 chip that allows us to dump the embedded flash and one-time programmable (OTP) data.โ€

Thatโ€™s all pretty technical, but the team did perform a laboratory demonstration โ€“ and documented it in a video โ€“ that it was able to hack into a Trezor T wallet supplied by CoinDesk and successfully retrieve our seed phrase and pin. Unciphered has previously hacked the EthereumWallet and recovered locked up cryptocurrency, though they claim on their website that they โ€œdo support every wallet in the market.โ€

READ NOW
Blockchain Defends Tornado Cash: Crypto Privacy Tool or Criminals Playground?

Trezor informed CoinDesk that its team didnโ€™t have enough details about the specific attack Unciphered performed to respond fully, but pointedย outย that it looked like an โ€œRDP downgrade attack,โ€ which was publicly flagged as a danger 3 years ago.

A press representative for the hardware wallet maker stated they were unaware of any attempts by Unciphered to reach out directly, despiteย theย factย that, โ€œas communicated on our blog in early 2020, RDP downgrade attacks require physical theft of a device and incredibly sophisticated technological knowledge and advanced equipment.โ€

Trezor alsoย mentionedย that โ€œeven with the over, Trezors can be protected by a strong passphrase, which adds another layer ofย safety that renders a RDP downgrade useless.โ€

Hardware wallets are suddenly in focus becauseย ofย  theย pastย few public backlash against the rival maker Ledger over its proposed optional โ€œ recovery option,โ€ which infuriated some users who had understood the device to be fully isolated. Numerous longtime cryptocurrency security specialists have recommended hardware wallets as a safer place to store assets than keeping them on exchanges โ€“ especially after last yearโ€™s collapse of Sam Bankman-Friedโ€™s FTXย Tradingย Ltd exchange โ€“ but the latest revelations show that the devices arenโ€™t foolproof either.

READ NOW
Secret Crypto Trading Strategy That OGs ARE USING NOW!

Unciphered stated it wouldnโ€™t confirm or deny whether its hack of the Trezor T would be considered an RDP downgrade, citing โ€œcurrent engagements and non-disclosure agreementsโ€ that restrict elaboration on โ€œhow this exploit chain works at this time.โ€

โ€œFurther, any technical disclosure would put Satoshilabs customers at potential danger till mitigations such as a new chip is utilized other than the STM32 in current use,โ€ reportsย by Unciphered.

Unciphered notedย that, despiteย theย factย that Trezor is aware that the Trezor T model has a vulnerability in its STM32 chip, the company has not done anything toย resolve that since theย preliminary attemptย to publicize the risk.

โ€œThe fact remains that through thisย post they are attemptingย to put the responsibility of securing their device on the customer rather than taking the responsibility of admitting that their device is fundamentally insecure,โ€ Unciphered wrote in an email to CoinDesk.

READ NOW
Elon Musks DOGE Insider Trading Scandal Sends Dogecoin Price Plummeting

Reportsย by Trezor: โ€œContrary to Uncipheredโ€™s states, Trezor has already taken wholeย lotย of steps toย fix this with the development of theย worldโ€™s 1st auditable and transparent secure elementย through sister company Tropic Square.โ€

Alternative options to hardware wallets

It bears emphasizing that Uncipheredโ€™s vector of attack only works with the device in the hackerโ€™s physical possession.

โ€œSecurity isย theย factย that the threat can often be coming from inside the house,โ€ stated Nick Federoff, head of marketing at Unciphered. โ€œWe can be our own worst enemy. So this is a huge part of it.โ€

Andย once a user sets up a hardware wallet, the wallet generates a random set of 12 or 24 words, known as a seed phrase, that allows access to the assets on the wallet.

READ NOW
Why This Crypto Traders Sudden Move is Sending Shockwaves Across the Market

As part of Uncipheredโ€™s attemptย to demonstrate its capability, company officials requested CoinDesk to acquire a new Trezor T wallet, set it up with our own seed phrase and write that down somewhere safe. We then sent it via a secure mailing option to Uncipheredโ€™s lab, where they then wentย ahead to hack into it (recording some of the steps on a video) and inย theย end were able to retrieve our seed phrase and pin. The extra step of involving CoinDesk was suggested by the Unciphered team as a way of supplying assurance that theย process wasnโ€™t faked or that the device wasnโ€™t compromised by a previous owner.

The device retails for $219 on the companyโ€™s website.

Unciphered acknowledged that it had not contacted Trezor to notify them about the vulnerability prior to tryingย to publicize it via an post on CoinDesk; often, such โ€œwhite hatโ€ attackers will work more cooperatively. โ€œUnciphered has not contacted Trezor whether through our responsible disclosure program or otherwise,โ€ stated a press representative at Trezor.

READ NOW
Bitcoins Bleak Future: Why the Worst is Yet to Come

Unciphered informed CoinDesk that they had not contacted Trezor because โ€œour obligations are to consumers instead of vendors, who have vested interests in selling more products, regardlessย of how vulnerable those products make the customers who use them.โ€

Bradley Keoun.

Source

Read Disclaimer
This page is simply meant to provide information. It does not constitute a direct offer to purchase or sell, a solicitation of an offer to buy or sell, or a suggestion or endorsement of any goods, services, or businesses. Lolacoin.org does not offer accounting, tax, or legal advice. When using or relying on any of the products, services, or content described in this article, neither the firm nor the author is liable, directly or indirectly, for any harm or loss that may result. Read more at Important Disclaimers and at Risk Disclaimers.




Follow us

Latest Crypto News

Share via
Share via
Send this to a friend