Engineer hacks Trezor wallet, recovers $2M in 'lost' crypto

Engineer hacks Trezor wallet, recovers $2M in 'lost' crypto

A computer engineer and hardware hacker has revealed how he managed to crack a Trezor One hardware wallet containing more than $2 million in funds.

Joe Grand — who is based in Portland also known by his hacker alias “Kingpin" — uploaded a Youtube video explaining how he pulled off the ingenious hack.

Our top trading bots

After deciding to cash out an original investment of roughly $50,000 in Theta in 2018, Dan Reich, a NYC based entrepreneur, and his friend, realized that they had lost the security PIN to the Trezor One the tokens were stored on. After unsuccessfully trying to guess the security PIN 12 times, they decided to quit before the wallet automatically wiped itself after 16 incorrect guesses.

But with their investment growing to $2 million this year, they redoubled their efforts to access the funds. Without their wallet’s seed phrase or PIN the only way to retrieve the tokens was through hacking.

They reached out to Grand who spent 12 weeks of trial and error but eventually found a way to recover the lost PIN.

The key to this hack was that during a firmware update the Trezor One wallets temporarily move the PIN and key to RAM, only to later move them back to flash once the firmware is installed. Grand found that in the version of firmware installed on Reich’s wallet this information was not moved but copied to the RAM, which means that if the hack fails and RAM is erased the information about the PIN and key would still be stored in flash.

After using a fault injection attack — a technique that alters the voltage going to the chip — Grand was able to surpass the security the microcontrollers have to prevent hackers from reading RAM, and obtained the PIN needed to access the wallet and the funds. Grand explained:

“We are basically causing misbehavior on the silicon chip inside the device in order to defeat security. And what ended up happening is that I was sitting here watching the computer screen and saw that I was able to defeat the security, the private information, the recovery seed, and the pin that I was going after popped up on the screen."

According to a recent tweet from Trezor this vulnerability that allows it to read from the wallet’s RAM is an older one that has already been fixed for newer devices. But unless changes are made to the microcontroller fault injection attacks still can pose a risk.

Read on about Cointelegraph
Korean crypto exchanges are now in compliance with the Travel Rule
South Korean crypto exchanges have reached the government-mandated deadline to come into compliance with the so-called Travel Rule, but not all industry...
SBF opens Aussie Blockchain Week as govt says we’re “open for business”
FTX CEO Sam Bankman-Fried gave the opening keynote at this year's Blockchain Week, with the events of day one held at the headquarters of the Australian...
Russian crypto volume across major exchanges plunges by 50%
Data from blockchain-analysis firms show that Russian denominated crypto purchasing and trading on major exchanges have faltered, debunking theories that...
Fed senior officials will soon not be allowed to trade crypto, stocks and bonds
The Federal Open Market Committee, or FOMC, has approved rules that would ban senior officials at the Federal Reserve from purchasing and holding cryptocurrencies...
BIS-funded financial monitor wants more data to measure risks of Bitcoin
The Financial Stability Board (FSB), a global financial authority funded by the Bank for International Settlements, has released a new report on the financial...
Doctors Without Borders is now using blockchain tech for medical record storage
At a November 11 press conference, blockchain- based document security company Transcrypts announced a partnership with Doctors Without Borders, or DWB,...
Matt Damon partners with Crypto.com around clean water project
Digital currency exchange Crypto.com has donated $1 million to water.org, a clean-water initiative co-founded by Matt Damon and Gary White in 2009.The direct...
A third of Salvadorans ‘actively’ using Chivo wallet, President Bukele claims
Salvadoran President Nayib Bukele claims that 2.1 million of his fellow citizens are using the government-backed Chivo cryptocurrency wallet, offering a...
Crypto developer will lead Twitter's decentralized social media initiative
Jay Graber, a former software engineer for Zcash and blockchain firm Skuchain, will be leading the anticipated decentralized social media initiative first...
ASX sounds crypto exchange custody warning, calls for better regulations
The Australia Securities Exchange (ASX) has weighed in on the issue of crypto custody amid the ongoing discussions within the country’s Senate Select Committee...
China proves Bitcoin is an unstoppable machine: Bitcoin Center founder
China’s crackdown on Bitcoin (BTC) mining continues to face determined responses across the crypto ecosystem. One of the first BTC exchange operators and...
Iranian trade ministry issues 30 crypto mining licenses
Iran’s Ministry of Industries, Mining and Trade issued operating licenses for 30 crypto mining centers in the country, the country's Financial Tribue reported...
Bitcoin Climbs 20% As Investors Gain Confidence
Investing.com - Bitcoin was trading at $41,761.1 by 08:59 (12:59 GMT) on the Investing.com Index on Thursday, up 19.81% on the day. It was the largest one-day...
Next up, Bitcoin ETF by Fidelity: Crypto funds batting .000 against SEC
With more than 35 million customers, $21 billion in revenues and $3.8 trillion in discretionary managed assets, Fidelity Investments is one of the largest...
Despite Bear Market Bitcoin Will Survive, Says NYSE Chair
The past two weeks have been a challenge for the entire crypto-market with bitcoin leading the drop. The total crypto market cap dipped from relatively...