If you want a hardware wallet, I recommend software in an air-gapped machine. Unless you can buy the hardware directly from the manufacturer, and ideally you walked into the factory and bought it at the source, the risk of compromise is too great.
How do you feel about Yubikeys and HSM systems that corporations heavily rely on?
Case study: fake hardware cryptowallet
11–20 of 160 posts
Re: Case study: fake hardware cryptowallet
#12Incredible. This is so sophisticated and takes so much effort it makes you wonder just how many other wallets are compromised from before you even use them. There are so many other low effort attacks you can run that the fact that people are doing THIS really makes me wonder just how many wallets out there are 100% compromised. It would be trivial for any iOS-based software wallet to compromise your seed before your…
Re: Case study: fake hardware cryptowallet
#13Re: Case study: fake hardware cryptowallet
#14Re: Case study: fake hardware cryptowallet
#15Title seems misleading (and isn't the article title). It implies that Trezor is a fake wallet. The article is actually about a wallet that purports to be made by Trezor but is in fact not (hardware supply chain attack).
Agreed -- the title should say (Trezor Impostor) to make it clear that Trezor is not the fake.
Re: Case study: fake hardware cryptowallet
#16https://www.youtube.com/watch?v=dT9y-KQbqi4&pp=ygULdHJlem9yI...
> I was contacted to hack a Trezor One hardware wallet and recover $2 million worth of cryptocurrency (in the form of THETA).
Re: Case study: fake hardware cryptowallet
#17Does it mean that at the moment of releasing 2.0.4 the Trezor team already knew there is a fake firmware circling around? I wonder if Trezor team communicated that in some maybe different way than that line in the CHANGELOG. Not blaming them of course, just wondering.
* Offer rewards to anyone able to send me the fake devices or clues who is making them.
* Tell my clients to upgrade the firmware on devices before use. Make sure every new firmware is distinctive in some way - for example the boot screen, and tell the users to check for that to ensure they are actually running the firmware they thought they just flashed.
Re: Case study: fake hardware cryptowallet
#18Nice article, but are we sure we want to elevate the status of FSB founded and funded Kapersky labs on the front page of HN?
Re: Case study: fake hardware cryptowallet
#19Does it mean that at the moment of releasing 2.0.4 the Trezor team already knew there is a fake firmware circling around? I wonder if Trezor team communicated that in some maybe different way than that line in the CHANGELOG. Not blaming them of course, just wondering.
If I were Trezor and became aware of a fake firmware, I would: * Offer rewards to anyone able to send me the fake devices or clues who is making them. * Tell my clients to upgrade the firmware on devices before use. Make sure every new firmware is distinctive in some way - for example the boot screen, and tell the users to check for that to ensure they are actually running the firmware they thought they just flashed.
Re: Case study: fake hardware cryptowallet
#20> The housing was difficult to open: its two halves were held together with liberal quantities of glue and double-sided adhesive tape instead of the ultrasonic bonding used on factory-made Trezors. Other than having x-ray vision, one easy (but by no means perfect) verification to thwart these types of attacks is to weigh your devices. Manufacturing should be consistent enough that resealing a device like this would b…