Live data from Hacker News

Case study: fake hardware cryptowallet

kaspersky.com

1–10 of 160 posts

Re: Case study: fake hardware cryptowallet

#3

Would the firmware update fail? if the user had decided to update it? Wouldn't that raise a suspicion?

Probably. It seems it was designed to run with the crypto after one month. Trezor's security on the physical realm is pretty good, but this is just a good attack.

Re: Case study: fake hardware cryptowallet

#5
Incredible. This is so sophisticated and takes so much effort it makes you wonder just how many other wallets are compromised from before you even use them. There are so many other low effort attacks you can run that the fact that people are doing THIS really makes me wonder just how many wallets out there are 100% compromised.

It would be trivial for any iOS-based software wallet to compromise your seed before your private key before is even created. You don't even need fancy spyware that calls home. If the seed is generated from a method that isn't random you'd never know. It will appear random to you, but the author of the software could simply increment on a known value and be able to recreate every private key ever created with that app. No one would ever know. The attacker could sit silent for years or even decades, and if they DID drain a wallet there would be no way to prove it and no one would believe the victim. It would just be a case of, "Well, you must have leaked your seed, it's your fault."

I can even see something like Coinbase Wallet being 100% compromised. The apology post is probably already written in a draft somewhere.

Re: Case study: fake hardware cryptowallet

#6
post #4

Title seems misleading (and isn't the article title). It implies that Trezor is a fake wallet. The article is actually about a wallet that purports to be made by Trezor but is in fact not (hardware supply chain attack).

Agreed -- the title should say (Trezor Impostor) to make it clear that Trezor is not the fake.

Re: Case study: fake hardware cryptowallet

#8
> The housing was difficult to open: its two halves were held together with liberal quantities of glue and double-sided adhesive tape instead of the ultrasonic bonding used on factory-made Trezors.

Other than having x-ray vision, one easy (but by no means perfect) verification to thwart these types of attacks is to weigh your devices.

Manufacturing should be consistent enough that resealing a device like this would be adding some grams that shouldn’t be there. And unlike something like a cisco router, nothing to cut out to make up for the added weight.

Re: Case study: fake hardware cryptowallet

#9
Does it mean that at the moment of releasing 2.0.4 the Trezor team already knew there is a fake firmware circling around?

I wonder if Trezor team communicated that in some maybe different way than that line in the CHANGELOG. Not blaming them of course, just wondering.

Re: Case study: fake hardware cryptowallet

#10

If you want a hardware wallet, I recommend software in an air-gapped machine. Unless you can buy the hardware directly from the manufacturer, and ideally you walked into the factory and bought it at the source, the risk of compromise is too great.

How do you feel about Yubikeys and HSM systems that corporations heavily rely on?
Post reply on HN