Trezor Hardware Fixes the ‘Critical Flaw’ Found by Kraken Security Labs

2020-2-1 21:58

Kraken Security Labs had been able to extract seeds from both Trezor One and Trezor Model T Kraken discloses the vulnerability to Trezor in Oct. 2019 and as the hardware wallet team had found the fix, Kraken made the flaw public

In shocking news, cryptocurrency exchange Kraken’s Security Labs announced that they were able to find a “critical flaw” in Trezor hardware wallets.

Kraken Security Labs announced on Friday that they have devised a way to extract seeds from both crypto hardware wallets of Trezor One and Trezor Model T.

The attack relies on voltage glitching to extract an encrypted seed that required several hundred dollars of equipment but could be mass-produced at $75. This encrypted seed which is protected by a 1-9 digit PIN, was then cracked which is “trivia to brute force.”

The team reveals that the attack took advantage of inherent flaws within the microcontroller used in Trezor wallets, meaning it is difficult for the Trezor team to do anything about this vulnerability at least without a hardware redesign.

Fix released by the Trezor team

A couple of weeks back, Kraken co-founder and CEO Jesse Powell advised that people shouldn’t store their coins on any cryptocurrency exchange even on Kraken, rather they should use Ledger or Trezor.

And now the Kraken Security Labs has found a vulnerability that means even hardware wallets aren’t safe either.

But there is a solution. Do not allow anyone physical access to your Trezor wallet or you could permanently lose your crypto.

Well, Trezor has found the fix and released it because as Kraken states, they “disclosed the full details of this attack to the Trezor team on October 30, 2019.” It continued,

“We are going public with this vulnerability disclosure now so that the crypto community can protect themselves before a fix is released by the Trezor team.”

Do hardware wallets remain the best option?

The user must enable the BIP39 Passphrase with the Trezor Client because it is not stored on the device, this can prevent the attack.

Passphrase feature is an “exceptionally” secure layer of active protection against physical attacks, said Trezor in its response to the attack.

It is not stored anywhere on the device and is used only temporarily whenever you enter it. The passphrase is case sensitive and it belongs with recovery seed.

However, Crypto Twitter was aghast to hear the news but Trezor tried to calm everyone and clarified,

“Trezor is an open-source hardware wallet: we indeed don't use a secure element to let anyone verify our code, but that is also why the Passphrase feature exists – to fully mitigate the physical attacks, which are a case for 6-9% of people according to our research.”

While assuage any concerns of having such vulnerability itself, Trezor competitor Ledger stated, “Not to worry: we're not affected by this as we use a Secure Element.”

Ledger also emphasized that despite this, “Hardware wallets remain the best option for keeping your crypto safe.”

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

SIRIN LABS Token (SRN) на Currencies.ru

$ 0.001184 (-0.04%)
Объем 24H $1.512k
Изменеия 24h: 6.74 %, 7d: 1.42 %
Cегодня L: $0.001184 - H: $0.001184
Капитализация $0 Rank 5028
Цена в час новости $ 0.0107971 (-89.03%)

trezor kraken security labs hardware announced wallets

trezor kraken → Результатов: 6


Экспертам Kraken удалось за 15 минут извлечь seed-фразу из биткоин-кошелька Trezor

Специалисты Kraken Security Labs сообщили, что нашли критическую уязвимость в аппаратных кошельках Trezor, открывающую возможность извлечения seed-фразы в течение 15 минут. 🚨It took Kraken Security Labs just 15 minutes to hack both of @trezor’s crypto hardware wallets.

2020-2-1 11:13


Руководитель Kraken предупреждает об опасности

Руководитель Kraken отметил лучшие примеры для хранения криптовалюты, после взлома Cryptopia, среди которых хранение в холодных кошельках. По словам генерального директора Kraken, Джесси Пауэлла, пользователям не нужно держать больше криптовалюты на биржах, чем может понадобится для активной торговли.

2019-1-17 18:34


Гендиректор Kraken предложил трейдерам переместить монеты на автономные кошельки

Генеральный директор криптобиржи Kraken Джесси Пауэлл после недавней атаки на платформу Cryptopia призвал инвесторов перевести свои средства на аппаратные кошельки для их автономного хранения. Соответствующее предложение глава торговой площадки разместил на своей странице в Твиттере.

2019-1-16 16:43