Are Trezor wallets no longer secure? In just 15 minutes, hackers can steal private keys through physical access

According to Cointelegraph reported on February 1, Kraken Security Labs recently announced that Trezor hardware wallets and their derivatives can be used to steal private keys. Although the entire theft process is quite complicated, Kraken claims that hackers "simply perform physical access to the device in 15 minutes to succeed".

Studio shot.

(Image source: flickr )

This attack requires physical intervention in the Trezor wallet by extracting its chip and placing it on a special device, or soldering several key connectors.

The Trezor chip must then be connected to a "faulty device" that sends a signal to it at a specific moment. The device broke the Trezor chip's built-in protection that prevented external devices from reading its memory. This process allows an attacker to read key wallet parameters, including the private key seed. Although the private key seed was encrypted with a key generated by a PIN, the researchers cracked the password within two minutes.

The vulnerability was caused by Trezor's use of specific hardware, and the company may not be able to easily fix the hardware issue. It requires the company to completely redesign the wallet and recall all existing models.

At the same time, Kraken Labs urged users of Trezor and KeepKey not to let anyone easily get their own hardware wallet.

Trezor responded to the matter, and the team believes that the probability of this vulnerability being exploited by hackers is not high. The company argues that the attack will show clear signs of tampering as hackers need to turn on the device, while also pointing out that the attack requires extremely specialized hardware to perform.

The Kraken research team finally recommended that users activate the wallet's passphrase (a double private key set by the user) to avoid such attacks. The passphrase is not stored on the device, it is a dynamically generated private key. Although researchers consider passphrase "complicated in practice," Kraken notes that this is a viable option.

If users want to set a passphrase, they need to make it complicated enough to not be easily cracked by force. If the user forgets it, they will never be able to access the cryptocurrency in the wallet.

Cointelegraph contacted Kraken Labs for more details, but no response has been received as of press time.

We will continue to update Blocking; if you have any questions or suggestions, please contact us!

Share:

Was this article helpful?

93 out of 132 found this helpful

Discover more

Blockchain

Xiaoyan follow-up: CZ, Nathan Kaiser, ten "big coffee" in the same box, market, trading, technology, all the nets

The Asian Block Summit was held in Taipei on July 2nd and 3rd. The summit focused on “blockchain business ...

Blockchain

"New and old" exchanges compete on the same stage, how can you play in the future? | Interview with SheKnows

Exchanges are an important part of the blockchain ecosystem. They interact directly with users and therefore change a...

Blockchain

Featured | Messari Founder: Recent Frustrations and Hopes in the Industry; Innovations in the Bitcoin Technology Stack

Today's content includes: 1. Founder of Messari: the recent frustration and hope of the industry; 2.Innovation i...

News

Inventory of Seven Bills that Could Determine the Future of Cryptocurrency in the United States

Author | DL NEWS compilation | Garyma Wu said the original link of the blockchain https//www.dlnews.com/articles/defi...

Blockchain

Research Report | Blockchain Economics Panorama and Future: Exchange Compliance

Author: BlockVC industry research team Source: BlockVC Editor's Note: The original title is "Postal Chain E...

Blockchain

Interviewed 800 crypto traders in 75 countries around the world. What did they find?

"Traders look for simplicity, but the exchange can't meet it. 80% of participants have entered the market f...