3 ms·
To make sure I understand, these attacks only work if someone get hold of your hardware wallet (either before or after it's delivered)? So they are stil safe if
by owaty 8y ago
To make sure I understand, these attacks only work if someone get hold of your hardware wallet (either before or after it's delivered)? So they are stil safe if you buy it directly from the vendor (and trust your delivery service etc.)?
- DennisP 8y agoThe worst attack was against the Trezor; in that case, after your funds are on the device they could steal it, extract the seed, and steal your funds. Using a strong passphrase prevents this attack. The Ledger Blue was vulnerable to sniffing the PIN entry by radio, but Ledger claims it's not usable in practice. All attacks against the Ledger Nano required them to get access to the device then give it back to you.
- michaelt 8y agoAll attacks against the Ledger Nano required them to get access to the device then give it back to you. Presumably if you were planning to exploit these things, you'd blend in with the 90 third-party Ledger Nano S resellers on Amazon [1], offering a slightly lower price. Doctor the devices to use predictable private keys, sell at a loss to be the cheapest seller on Amazon, then grab all the bitcoins at a time of your choosing, because you know the private keys. [1] https://www.amazon.com/gp/offer-listing/B01J66NF46/ https://www.amazon.com/gp/offer-listing/B01J66NF46/
- DennisP 8y agoThat'd be devastating but so far none of the attacks have managed to make the Ledger create predictable private keys. You'd have to hack the secure chip to pull that off.