Post
Topic
Board Beginners & Help
Re: Hardware wallets, types, security and safety
by
Lucius
on 13/03/2020, 11:50:55 UTC
There has been no demonstrated successful physical attack against Ledger products, but that is not to say one doesn't exist.

Those who have been following the development of hardware wallets for a long time know about the case of Side channel attack which is released back in 2018. This attack demonstrated the possibility of a remote hack of user PIN, and it was successful (Ledger Blue). But PIN is of no use without physically accessing the device, so this vulnerability was declared "less dramatic" and I think it was fixed in next firmware.

Roth explained that they started by analysing the hardware architecture of the Blue. They noticed that there was a fairly long connection between the secure element and another processor. In other words, the wire that connected these two components was physically quite long, due to their physical distance apart on the circuit board (each on other side of the device’s relatively large battery).
So they built a small robotic device to press a button over and over while their antennae listened and logged data. This was used to build up training data for an artificial intelligence system to analyze.
They were able to get a very high likelihood of identifying each digit on a PIN on the tested device.