• Latest
  • Trending
OneKey says it has fixed flaw that got its hardware wallet hacked in 1 second

OneKey says it has fixed flaw that got its hardware wallet hacked in 1 second

February 13, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

XRP, Shiba Inu, and More: Here are Top 6 Altcoins Priced Below $1 to Watch for Next Bull Run – The Crypto Basic

October 31, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Zodia Custody expands in Hong Kong, receives VASP in Ireland … – Tekedia

October 31, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Why Altcoins and Crypto Stocks Were Flying High Today – The Motley Fool

October 30, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Embracing the crypto evolution: Institutional adaptation and the … – Arabian Business

October 30, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Acala Spikes 5% on Binance's New Altcoin Pairs News — Can ACA … – CCN.com

October 30, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Bitcoin Spark, BNB, and Toncoin: Price Outlook in Upcoming Bull Run – CryptoPotato

October 30, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Crypto Price Today: Bitcoin holds $34,000; Ethereum slips below $1,800; most altcoins up – Business Today

October 30, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

The Next Bull Market Is Approaching: Sparking Opportunities For … – CryptoPotato

October 30, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Crypto Analyst Benjamin Cowen Says Fed Pivot and Altcoin Rallies Won’t Happen Until This Occurs – The Daily Hodl

October 29, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Litecoin Pronóstico del Precio: LTC insinúa una corrección del 15% si se cumplen estas condiciones clave – FXStreet

October 29, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Brazil's USDT adoption soars in 2023, makes up 80% of all crypto transactions – Cointelegraph

October 29, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Can Presales Like Scorpion Casino Token Match the Historic … – NewsWatch

October 29, 2023
Tuesday, June 3, 2025
EGROW ONLINE
  • Home
  • Cryptocurrency
  • Bitcoin
  • Ethereum
  • Blockchain
  • Altcoins
  • ADA
  • Litecoin
  • Dogecoin
  • ICO
  • Ripple
  • Market & Analysis
  • Videos
No Result
View All Result
EGROW ONLINE
No Result
View All Result

OneKey says it has fixed flaw that got its hardware wallet hacked in 1 second

by admin
February 13, 2023
in Blockchain
0



Crypto hardware wallet provider OneKey says it has already addressed a vulnerability in its firmware that allowed one of its hardware wallets to be hacked in one second flat.

A video on YouTube posted on Feb. 10 by cybersecurity startup Unciphered showed they had figured out a way to exploit a “Massive critical vulnerability” that allowed them to “crack open” a OneKey Mini.

According to Eric Michaud, a partner at Unciphered, by disassembling the device and inserting coding, it was possible to return the OneKey Mini to “factory mode” and bypass the security pin, allowing a potential attacker to remove the mnemonic phrase used to recover a wallet. 

“You have the CPU and the secure element. The secure element is where you keep your crypto keys. Now, normally, the communications are encrypted between the CPU, where the processing is done, and the secure element,” Michaud explained.

“Well it turns out it wasn’t engineered to do so in this case. So what you could do is put a tool in the middle that monitors the communications and intercepts them and then injects their own commands,” he said, adding:

“We did that where it then tells the secure element it’s in factory mode and we can take your mnemonics out, which is your money in crypto.”

However, in a Feb. 10 statement, OneKey said it had already addressed the security flaw identified by Unciphered, noting that its hardware team had updated the security patch “earlier this year” without “anyone being affected” and that “All disclosed vulnerabilities have been or are being fixed.”

Our Response to Recent Security Fix Reports https://t.co/Dp9nNp1D0U

— OneKey Open Source Wallet (@OneKeyHQ) February 10, 2023

“That said, with password phrases and basic security practices, even physical attacks disclosed by Unciphered will not affect OneKey users.” 

The company further highlighted that while the vulnerability was concerning, the attack vector identified by Unciphered can’t be used remotely and requires “disassembly of the device and physical access through a dedicated FPGA device in the lab to be possible to execute.”

According to OneKey, during correspondence with Unciphered, it was disclosed that other wallets have been found to have similar issues.

“We also paid Unciphered bounties to thank them for their contributions to OneKey’s security,” OneKey said.

Related: ‘Haunts me to this day’ — Crypto project hacked for $4M in a hotel lobby

In its blog post, OneKey has said it’s already gone to great pains to ensure the security of its users, including protecting them from supply chain attacks — when a hacker replaces a genuine wallet with one controlled by them. 

OneKey’s measures have included tamper-proof packaging for deliveries and the use of supply chain service providers from Apple to ensure stringent supply chain security management.

In the future, they hope to implement onboard authentication and upgrade newer hardware wallets with higher-level security components.

OneKey wrote that the main purpose of hardware wallets has always been to protect users’ money from malware attacks, computer viruses and other remote dangers, but unfortunately, nothing can be 100% secure. 

“When we look at the entire hardware wallet manufacturing process, from silicon crystals to chip code, from firmware to software, it’s safe to say that with enough money, time and resources, any hardware barrier can be breached, even if it’s a nuclear weapon control system.”



Source link

YOU MAY ALSO LIKE

What do the Long-Term Technicals Predict for Blockchain Cuties Universe Governance (BCUG) Sunday? – InvestorsObserver

SBF takes the stand, ‘buy Bitcoin’ searches soar and other news: Hodler’s Digest, Oct. 22-28

Tags: FixedflawhackedHardwareOneKeyWallet
ShareTweetPin

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result

Recent News

Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

XRP, Shiba Inu, and More: Here are Top 6 Altcoins Priced Below $1 to Watch for Next Bull Run – The Crypto Basic

October 31, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Zodia Custody expands in Hong Kong, receives VASP in Ireland … – Tekedia

October 31, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Why Altcoins and Crypto Stocks Were Flying High Today – The Motley Fool

October 30, 2023

Recent News

Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

XRP, Shiba Inu, and More: Here are Top 6 Altcoins Priced Below $1 to Watch for Next Bull Run – The Crypto Basic

October 31, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Zodia Custody expands in Hong Kong, receives VASP in Ireland … – Tekedia

October 31, 2023
Altcoins Lead Post-Fed Crypto Rally as Risk Appetite Increases – Yahoo Finance

Why Altcoins and Crypto Stocks Were Flying High Today – The Motley Fool

October 30, 2023

Categories

  • ADA
  • Altcoins
  • Bitcoin
  • Blockchain
  • Cryptocurrency
  • Dogecoin
  • Ethereum
  • ICO
  • Litecoin
  • Market & Analysis
  • Ripple
  • Videos

Follow Us

Find Via Tags

Ada Altcoin altcoins analysis Analyst Analytics Big Binance Bitcoin Blockchain BNB BTC Buy Cardano Coin Cointelegraph Crypto cryptocurrencies Cryptocurrency Digital DOGE Dogecoin ETH Ethereum finance Heres Insight Inu investors Litecoin LTC market Network news Prediction price Ripple SEC Shiba Solana Today Token Top week XRP
  • privacy And Policy
  • About Us

© 2020 Egrow Online

No Result
View All Result
  • Home
  • Cryptocurrency
  • Bitcoin
  • Ethereum
  • Blockchain
  • Altcoins
  • ADA
  • Litecoin
  • Dogecoin
  • ICO
  • Ripple
  • Market & Analysis
  • Videos

© 2020 Egrow Online