Post
Topic
Board Hardware wallets
Merits 6 from 4 users
Re: Critical vulnerability discovered in ESP32 chip
by
nc50lc
on 18/04/2025, 08:46:13 UTC
⭐ Merited by Pmalek (2) ,vapourminer (2) ,dkbit98 (1) ,satscraper (1)
The specifics are still fuzzy, but I read that some hackers showed they could actually drain a hardware wallet by taking advantage of this bug.
Hmm, I don't know but their reference "CVE-2025-27840" doesn't contain any information about a vulnerability in the chip's RNG.
If it's a problem caused by any those "hidden commands", the article didn't explained it clearly.

On a related topic, its maintainer mentioned that the undocumented features aren't an issue: github.com/orgs/espruino/discussions/7699#discussioncomment-12447043
They take that those articles are mostly "clickbait".
(but of course DYOR)