Trezor, Others Affected By "Fault Injection" – May Leak Keys

A security flaw in Trezor hardware Bitcoin wallets can reveal users private keys, due to faulty STMicroelectronics chips used in the manufacture of the devices. While Trezor has released a fix for the hack detailed in this archived Medium post, the company – along with other hardware wallet manufacturers such as KeepKey – will continue to use chips from STMicroelectronics that may contain other fault injection vulnerabilities, and result in SFYL if Government agencies or other parties gain access to the device for even a short period of time. Trezor assured users that "everything is fine" and “coins are safe” provided devices are kept within reach of their owners since the glitch isn't a remote execution attack. A blog post on the trezor.io website promises that they will "publish a detailed report in the coming days".

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>