Post
Topic
Board Hardware wallets
Merits 1 from 1 user
Re: wallet.fail - 35C3 talk on hardware wallet vulnerabilities (Ledger, Trezor)
by
o_e_l_e_o
on 28/12/2018, 21:40:34 UTC
⭐ Merited by ETFbitcoin (1)
Regarding flashing custom firmware on Ledger Nano S, is hidden account also compromised?

They've not yet proven that any account is compromised.

Just saw this link posted in a thread on Bitcoin Discussion: https://www.ledger.fr/2018/12/28/chaos-communication-congress-in-response-to-wallet-fails-presentation/

It seems to confirm what I was saying. In short, they used a bug to install custom firmware in the bootloader, but did not access the secure element or manage to extract any PINs or seeds, and the bug will be patched in the next firmware version. I'm also pretty impressed by the response time from the Ledger team here.