Crypto Security Firm Unciphered Claims Ability to Physically Hack Trezor T Wallet (2024)

Technology

Unciphered, a company of cybersecurity professionals who recover lost cryptocurrency, says it found a way to physically hack into the Trezor T hardware wallet. Trezor says it acknowledged a similar-sounding attack vector a few years ago.

By Margaux Nijkerk

Crypto Security Firm Unciphered Claims Ability to Physically Hack Trezor T Wallet (1)May 24, 2023 at 3:35 p.m. UTC

Updated May 25, 2023 at 2:21 a.m. UTC

Crypto Security Firm Unciphered Claims Ability to Physically Hack Trezor T Wallet (2)

A company of cybersecurity professionals who specialize in recovering lost or stolen cryptocurrency say they have found a way to hack into the popular Trezor T hardware wallet once it’s in their physical possession.

Unciphered told CoinDesk in an extensive series of conversations and over email it made use of an “unpatchable hardware vulnerability with the STM32 chip that allows us to dump the embedded flash and one-time programmable (OTP) data.”

That’s all pretty technical, but the team did perform a laboratory demonstration – and documented it in a video – that it was able to hack into a Trezor T wallet supplied by CoinDesk and successfully retrieve our seed phrase and pin. Unciphered has previously hacked the EthereumWallet and recovered locked up crypto, though they claim on their website that they “do support every wallet in the market.”

Trezor told CoinDesk that its team didn’t have enough details about the specific attack Unciphered performed to respond fully, but noted that it looked like an “RDP downgrade attack,” which was publicly flagged as a risk three years ago.

A press representative for the hardware wallet maker said they were unaware of any attempts by Unciphered to reach out directly, even though, "as communicated on our blog in early 2020, RDP downgrade attacks require physical theft of a device and extremely sophisticated technological knowledge and advanced equipment.”

Trezor added that “even with the above, Trezors can be protected by a strong passphrase, which adds another layer of security that renders a RDP downgrade useless.”

Hardware wallets are suddenly in focus as a result of the recent public backlash against the rival maker Ledger over its proposed optional “recovery option,” which infuriated some users who had understood the device to be fully isolated. Many longtime crypto security experts have recommended hardware wallets as a safer place to store assets than keeping them on exchanges – especially after last year’s collapse of Sam Bankman-Fried's FTX exchange – but the latest revelations show that the devices aren’t foolproof either.

Read more: Crypto Wallet Provider Ledger Delays Key-Recovery Service After Uproar

Unciphered said it wouldn’t confirm or deny whether its hack of the Trezor T would be considered an RDP downgrade, citing “current engagements and non-disclosure agreements” that restrict elaboration on “how this exploit chain works at this time.”

“Further, any technical disclosure would put Satoshilabs customers at potential risk till mitigations such as a new chip is utilized other than the STM32 in current use,” according to Unciphered.

Unciphered pointed out that, even though Trezor is aware that the Trezor T model has a vulnerability in its STM32 chip, the company has not done anything to fix that since the initial effort to publicize the risk.

“The fact remains that through this article they are trying to put the responsibility of securing their device on the customer rather than taking the responsibility of admitting that their device is fundamentally insecure,” Unciphered wrote in an email to CoinDesk.

According to Trezor: “Contrary to Unciphered’s claims, Trezor has already taken significant steps to resolve this with the development of the world’s first auditable and transparent secure element through sister company Tropic Square.”

Alternative options to hardware wallets

It bears emphasizing that Unciphered’s vector of attack only works with the device in the hacker’s physical possession.

“Security is that the threat can often be coming from inside the house,” said Nick Federoff, head of marketing at Unciphered. “We can be our own worst enemy. So this is a huge part of it.”

When a user sets up a hardware wallet, the wallet generates a random set of 12 or 24 words, known as a seed phrase, that allows access to the assets on the wallet.

As part of Unciphered’s effort to demonstrate its capability, company officials asked CoinDesk to acquire a new Trezor T wallet, set it up with our own seed phrase and write that down somewhere safe. We then sent it via a secure mailing option to Unciphered’s lab, where they then proceeded to hack into it (recording some of the steps on a video) and ultimately were able to retrieve our seed phrase and pin. The extra step of involving CoinDesk was suggested by the Unciphered team as a way of providing assurance that the procedure wasn’t faked or that the device wasn’t compromised by a previous owner.

The device retails for $219 on the company's website.

Unciphered acknowledged that it had not contacted Trezor to notify them about the vulnerability prior to attempting to publicize it via an article on CoinDesk; often, such “white hat” hackers will work more cooperatively. “Unciphered has not contacted Trezor whether through our responsible disclosure program or otherwise,” said a press representative at Trezor.

Unciphered told CoinDesk that they had not contacted Trezor because “our obligations are to consumers instead of vendors, who have vested interests in selling more products, regardless of how vulnerable those products make the customers who use them.”

Read more: Hot vs. Cold Crypto Wallets: What Are the Differences?

Edited by Bradley Keoun.

Disclosure

Please note that our

privacy policy,

terms of use,

cookies,

and

do not sell my personal information

has been updated

.

CoinDesk is an

award-winning

media outlet that covers the cryptocurrency industry. Its journalists abide by a

strict set of editorial policies.

In November 2023

, CoinDesk was acquired

by the Bullish group, owner of

Bullish,

a regulated, digital assets exchange. The Bullish group is majority-owned by

Block.one; both companies have

interests

in a variety of blockchain and digital asset businesses and significant holdings of digital assets, including bitcoin.

CoinDesk operates as an independent subsidiary with an editorial committee to protect journalistic independence. CoinDesk employees, including journalists, may receive options in the Bullish group as part of their compensation.

Margaux Nijkerk

Margaux Nijkerk reports on the Ethereum protocol and L2s. A graduate of Johns Hopkins and Emory universities, she has a masters in International Affairs & Economics. She holds a small amount of ETH and other altcoins.

Read more about

Hackhardware walletTrezorCrypto

Crypto Security Firm Unciphered Claims Ability to Physically Hack Trezor T Wallet (2024)
Top Articles
What are the disadvantages of using RFID?
Cruise Embarkation tips: general information
Calvert Er Wait Time
Www.paystubportal.com/7-11 Login
Sprinter Tyrone's Unblocked Games
Food King El Paso Ads
Snarky Tea Net Worth 2022
Top Golf 3000 Clubs
Mndot Road Closures
Housing Intranet Unt
World Cup Soccer Wiki
Jasmine Put A Ring On It Age
Local Dog Boarding Kennels Near Me
Vcuapi
Billionaire Ken Griffin Doesn’t Like His Portrayal In GameStop Movie ‘Dumb Money,’ So He’s Throwing A Tantrum: Report
Voy Boards Miss America
Zack Fairhurst Snapchat
Msu 247 Football
Sprinkler Lv2
Dallas Craigslist Org Dallas
Toyota Camry Hybrid Long Term Review: A Big Luxury Sedan With Hatchback Efficiency
Japanese Mushrooms: 10 Popular Varieties and Simple Recipes - Japan Travel Guide MATCHA
Integer Division Matlab
Makemv Splunk
Phoenixdabarbie
Bfsfcu Truecar
San Jac Email Log In
Paradise Point Animal Hospital With Veterinarians On-The-Go
Wells Fargo Bank Florida Locations
Alima Becker
Mg Char Grill
Capital Hall 6 Base Layout
Clark County Ky Busted Newspaper
Ny Post Front Page Cover Today
Craigslist Ludington Michigan
Froedtert Billing Phone Number
Henry Ford’s Greatest Achievements and Inventions - World History Edu
Download Diablo 2 From Blizzard
The Conners Season 5 Wiki
If You're Getting Your Nails Done, You Absolutely Need to Tip—Here's How Much
Pekin Soccer Tournament
Alpha Labs Male Enhancement – Complete Reviews And Guide
Ghareeb Nawaz Texas Menu
Brother Bear Tattoo Ideas
Mother Cabrini, the First American Saint of the Catholic Church
Sea Guini Dress Code
Conan Exiles Colored Crystal
Bridgeport Police Blotter Today
Craigslist Chautauqua Ny
Gelato 47 Allbud
Sleep Outfitters Springhurst
Competitive Comparison
Latest Posts
Article information

Author: Laurine Ryan

Last Updated:

Views: 5848

Rating: 4.7 / 5 (57 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Laurine Ryan

Birthday: 1994-12-23

Address: Suite 751 871 Lissette Throughway, West Kittie, NH 41603

Phone: +2366831109631

Job: Sales Producer

Hobby: Creative writing, Motor sports, Do it yourself, Skateboarding, Coffee roasting, Calligraphy, Stand-up comedy

Introduction: My name is Laurine Ryan, I am a adorable, fair, graceful, spotless, gorgeous, homely, cooperative person who loves writing and wants to share my knowledge and understanding with you.