<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Crypton Nfts</title>
    <description>The latest articles on DEV Community by Crypton Nfts (@crypton_nfts).</description>
    <link>https://dev.to/crypton_nfts</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4173577%2Fcd13182c-a1e7-474f-853e-826708f57883.jpg</url>
      <title>DEV Community: Crypton Nfts</title>
      <link>https://dev.to/crypton_nfts</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/crypton_nfts"/>
    <language>en</language>
    <item>
      <title>What Researchers Actually Found When They Attacked Hardware Wallets</title>
      <dc:creator>Crypton Nfts</dc:creator>
      <pubDate>Fri, 09 Oct 2026 15:41:12 +0000</pubDate>
      <link>https://dev.to/crypton_nfts/what-researchers-actually-found-when-they-attacked-hardware-wallets-13m9</link>
      <guid>https://dev.to/crypton_nfts/what-researchers-actually-found-when-they-attacked-hardware-wallets-13m9</guid>
      <description>&lt;p&gt;Every few months there's a headline saying hardware wallets get hacked. I wanted to know what the published attacks actually needed, so I went through them.&lt;/p&gt;

&lt;h2&gt;
  
  
  The short version
&lt;/h2&gt;

&lt;p&gt;Researchers have extracted keys from hardware wallets. But every documented case required physical access to the device, often with the case opened, or a unit that had been tampered with before the owner unboxed it. Nobody has done it remotely to someone using their wallet normally.&lt;/p&gt;

&lt;h2&gt;
  
  
  Wallet.fail (2018)
&lt;/h2&gt;

&lt;p&gt;At the Chaos Communication Congress in December 2018, three researchers presented Wallet.fail after spending months taking apart Trezor, Ledger and KeepKey devices.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;On the Trezor One they pulled the private key out. It only worked because no passphrase was set. A passphrase (the optional "25th word") closes that exact path.&lt;/li&gt;
&lt;li&gt;On the Ledger Nano S they compromised the bootloader and ran their own firmware. They got it to play Snake. The secure element holding the key was not affected.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Both attacks needed the physical device, usually opened up with a screwdriver.&lt;/p&gt;

&lt;h2&gt;
  
  
  The supply chain angle
&lt;/h2&gt;

&lt;p&gt;In March 2018, Saleem Rashid, then 15, showed that the Ledger Nano S's non-secure microcontroller could be made to misreport the installed firmware to the secure element. The realistic risk is a device tampered with during manufacturing or shipping, not a wallet attacked while you use it. Ledger patched the flaw and now points buyers to its own store and verified resellers.&lt;/p&gt;

&lt;h2&gt;
  
  
  EUCLEAK (2024)
&lt;/h2&gt;

&lt;p&gt;NinjaLab's EUCLEAK attack hit a cryptographic library from Infineon. That library sits in security chips like those in YubiKeys and, more broadly, some hardware wallets. The flaw went unnoticed for roughly 14 years and passed around 80 Common Criteria evaluations. Getting the key out took electromagnetic side-channel measurements and specialized lab equipment. Certification lowers risk, but it doesn't remove it.&lt;/p&gt;

&lt;h2&gt;
  
  
  The 2020 Ledger "hack" that wasn't a wallet hack
&lt;/h2&gt;

&lt;p&gt;In June 2020, Ledger's e-commerce and marketing database was breached. About one million email addresses and roughly 270,000 physical addresses and phone numbers were exposed. Recovery phrases, private keys and funds were not touched. The leak did lead to targeted phishing, which is a real problem, but it is a different one from compromised hardware.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I'd do with this
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Set a passphrase. It directly defeated the Wallet.fail key extraction on the Trezor One.&lt;/li&gt;
&lt;li&gt;Buy from the vendor or an authorized reseller to avoid the supply chain risk.&lt;/li&gt;
&lt;li&gt;Keep the device somewhere a stranger can't casually reach it. Every attack above needed uninterrupted physical access.&lt;/li&gt;
&lt;li&gt;Update the firmware when the vendor tells you to.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;I wrote a longer version with more detail on my site: &lt;a href="https://www.cryptonnft.com/wallets-security/can-hardware-wallet-be-hacked/" rel="noopener noreferrer"&gt;https://www.cryptonnft.com/wallets-security/can-hardware-wallet-be-hacked/&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>web3</category>
      <category>cryptocurrency</category>
      <category>blockchain</category>
    </item>
  </channel>
</rss>
