Case study: fake hardware cryptowallet
kaspersky.com
Case study: fake hardware cryptowallet
1–10 of 160 posts
Re: Case study: fake hardware cryptowallet
#2Re: Case study: fake hardware cryptowallet
#3Would the firmware update fail? if the user had decided to update it? Wouldn't that raise a suspicion?
Re: Case study: fake hardware cryptowallet
#4Re: Case study: fake hardware cryptowallet
#5It would be trivial for any iOS-based software wallet to compromise your seed before your private key before is even created. You don't even need fancy spyware that calls home. If the seed is generated from a method that isn't random you'd never know. It will appear random to you, but the author of the software could simply increment on a known value and be able to recreate every private key ever created with that app. No one would ever know. The attacker could sit silent for years or even decades, and if they DID drain a wallet there would be no way to prove it and no one would believe the victim. It would just be a case of, "Well, you must have leaked your seed, it's your fault."
I can even see something like Coinbase Wallet being 100% compromised. The apology post is probably already written in a draft somewhere.
Re: Case study: fake hardware cryptowallet
#6Title seems misleading (and isn't the article title). It implies that Trezor is a fake wallet. The article is actually about a wallet that purports to be made by Trezor but is in fact not (hardware supply chain attack).
Re: Case study: fake hardware cryptowallet
#7Re: Case study: fake hardware cryptowallet
#8Other than having x-ray vision, one easy (but by no means perfect) verification to thwart these types of attacks is to weigh your devices.
Manufacturing should be consistent enough that resealing a device like this would be adding some grams that shouldn’t be there. And unlike something like a cisco router, nothing to cut out to make up for the added weight.
Re: Case study: fake hardware cryptowallet
#9I wonder if Trezor team communicated that in some maybe different way than that line in the CHANGELOG. Not blaming them of course, just wondering.
Re: Case study: fake hardware cryptowallet
#10If you want a hardware wallet, I recommend software in an air-gapped machine. Unless you can buy the hardware directly from the manufacturer, and ideally you walked into the factory and bought it at the source, the risk of compromise is too great.