Post
Topic
Board Hardware wallets
Merits 2 from 1 user
Re: Hardware Wallet Hacked?
by
magdaniewczas
on 23/10/2019, 17:40:50 UTC
⭐ Merited by malevolent (2)
Yes, you can hack a trezor and extract all 24 words
Do you care to elaborate on that maybe? Where did you read or hear about Trezor wallets getting hacked and seed words being extracted?

I did read an article a while ago published by Kaspersky it is possible to gain access to the seed using a hacking technique called voltage glitching. More about that here:
Source: https://www.kaspersky.com/blog/hardware-wallets-hacked/25315/

Quote
Using a hacking technique called voltage glitching (applying lowered voltage to a microcontroller, which causes funny effects in the chip) they switched Trezor One’s chip state from “no access” to “partial access,” which allowed them to read the chip’s RAM, but not the flash storage. After that they found out that when the firmware upgrade process is started, the chip places the cryptographic seed into RAM to retain it while the flash is being overwritten. In this manner, they managed to get all memory contents. Finding the cryptographic seed in this dump turned out to be no problem; it was stored in RAM unencrypted, in the form of a mnemonic phrase (meaning actual words instead of random number) that was easy to spot.

https://media.kasperskydaily.com/wp-content/uploads/sites/92/2019/01/10073034/hardware-wallets-hacked-trezor-pwned.jpg

You can hack a Trezor using side channel attack, there are various tools for this, one is Chipwhisperer manufactured in Canada. Their CEO even demonstrated the hack in a video in Las Vegas in August this year.