Post
Topic
Board Hardware wallets
Merits 1 from 1 user
Re: wallet.fail - 35C3 talk on hardware wallet vulnerabilities (Ledger, Trezor)
by
Lucius
on 28/12/2018, 14:47:19 UTC
⭐ Merited by bones261 (1)
Interesting video, I have to admit I looked at the part which show Flashing the Ledger Nano S with custom firmware just because I use that HW. In this part of video we can see that is possible to flash Nano S with custom firmware, and in case they presented we see that instead HW you can turn on this device in miniature game console and play game snake.

Yet this is no threat that can affect current users since requires physical access to the device, but it show that Ledger still have no solution to prevent that device is flash with custom firmware. So if hackers find way to trick users with false firmware update, it is possible that this could be one of the vectors of the attack.

The worst possible scenario : Hackers hack official Ledger site, add fake firmware and try to get as many users as possible. Maybe it's not a true comparison, but who could have imagined a few days ago that hackers will use original Electrum wallet to steal hundreds, and probably thousands of BTC?

Hardware wallets are safe, more then any desktop/online wallet, but we should never ignore the potential danger which is lurking from some dark corner. I would not want to play snake on my Nano S in time hackers play with my BTC.