{"id":43947,"date":"2023-02-13T05:15:19","date_gmt":"2023-02-13T05:15:19","guid":{"rendered":"http:\/\/egrowonline.com\/?p=43947"},"modified":"2023-02-13T05:15:19","modified_gmt":"2023-02-13T05:15:19","slug":"onekey-says-it-has-fixed-flaw-that-got-its-hardware-wallet-hacked-in-1-second","status":"publish","type":"post","link":"http:\/\/egrowonline.com\/?p=43947","title":{"rendered":"OneKey says it has fixed flaw that got its hardware wallet hacked in 1 second"},"content":{"rendered":"<p> <br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/images\/840_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjMtMDIvZGI3N2NjN2YtNmYyMy00MTZkLTg0NDYtNzllZTE1MGUxODliLmpwZw==.jpg\" \/><\/p>\n<div data-v-4bbf85c5=\"\">\n<p>Crypto hardware wallet provider OneKey says it has already addressed a vulnerability in its firmware that allowed one of its hardware wallets to be hacked in one second flat.<\/p>\n<p>A video on YouTube <a target=\"_blank\" href=\"https:\/\/www.youtube.com\/watch?v=b8OrakRJmHE\" rel=\"noopener nofollow\">posted<\/a>\u00a0on Feb. 10 by cybersecurity startup Unciphered showed they had figured out a way to exploit a \u201cMassive critical vulnerability\u201d that allowed them to \u201ccrack open\u201d a OneKey Mini.<\/p>\n<p>According to Eric Michaud, a partner at Unciphered, by disassembling the device and inserting coding, it was possible to return the OneKey Mini to \u201cfactory mode\u201d and bypass the security pin, allowing a potential attacker to remove the mnemonic phrase used to recover a wallet.\u00a0<\/p>\n<div class=\"jeg_video_container jeg_video_content\"><iframe loading=\"lazy\" title=\"How We Hacked a Hardware Crypto Wallet and Saved The World (of Cryptocurrency)\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/b8OrakRJmHE?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/div>\n<p>\u201cYou have the CPU and the secure element. The secure element is where you keep your crypto keys. Now, normally, the communications are encrypted between the CPU, where the processing is done, and the secure element,\u201d Michaud explained. <\/p>\n<p>\u201cWell it turns out it wasn\u2019t engineered to do so in this case. So what you could do is put a tool in the middle that monitors the communications and intercepts them and then injects their own commands,\u201d he said, adding:<\/p>\n<blockquote><p>\u201cWe did that where it then tells the secure element it\u2019s in factory mode and we can take your mnemonics out, which is your money in crypto.\u201d<\/p><\/blockquote>\n<p>However, in a Feb. 10 statement, OneKey said it had already\u00a0<a target=\"_blank\" href=\"https:\/\/blog.onekey.so\/our-response-to-recent-security-fix-reports-13914fea8afd\" rel=\"noopener nofollow\">addressed<\/a> the security flaw identified by Unciphered, noting that its hardware team had updated the security patch \u201cearlier this year\u201d without &#8220;anyone being affected\u201d and that \u201cAll disclosed vulnerabilities have been or are being fixed.\u201d<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Our Response to Recent Security Fix Reports <a target=\"_blank\" href=\"https:\/\/t.co\/Dp9nNp1D0U\" rel=\"noopener\">https:\/\/t.co\/Dp9nNp1D0U<\/a><\/p>\n<p>\u2014 OneKey Open Source Wallet (@OneKeyHQ) <a target=\"_blank\" href=\"https:\/\/twitter.com\/OneKeyHQ\/status\/1623944436488245248?ref_src=twsrc%5Etfw\" rel=\"noopener\">February 10, 2023<\/a><\/p><\/blockquote>\n<p>&#8220;That said, with password phrases and basic security practices, even physical attacks disclosed by Unciphered will not affect OneKey users.&#8221;\u00a0<\/p>\n<p>The company further highlighted that while the vulnerability was concerning, the attack vector identified by Unciphered can\u2019t be used remotely and requires &#8220;disassembly of the device and physical access through a dedicated FPGA device in the lab to be possible to execute.&#8221;<\/p>\n<p>According to OneKey, during correspondence with Unciphered, it was disclosed that other wallets have been <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/8-hacker-tactics-to-be-aware-of-when-protecting-your-crypto-assets\" rel=\"noopener\">found to have similar issues<\/a>.<\/p>\n<p>\u201cWe also paid Unciphered bounties to thank them for their contributions to OneKey\u2019s security,\u201d OneKey said.<\/p>\n<p><strong><em>Related: <\/em><\/strong><a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/haunts-me-to-this-day-crypto-project-hacked-for-4m-in-a-hotel-lobby\" rel=\"noopener\"><strong><em>\u2018Haunts me to this day\u2019 \u2014 Crypto project hacked for $4M in a hotel lobby<\/em><\/strong><\/a><\/p>\n<p>In its blog post, OneKey has said it\u2019s already gone to great pains to ensure the security of its users, including protecting them from\u00a0<a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/kraken-discovers-supply-chain-attacks-against-ledger-wallets\" rel=\"noopener\">supply chain attacks<\/a>\u00a0\u2014\u00a0when a hacker replaces a genuine wallet with one controlled by them.\u00a0<\/p>\n<p>OneKey\u2019s measures have included tamper-proof packaging for deliveries and the use of supply chain service providers from Apple to ensure stringent supply chain security management.<\/p>\n<p>In the future, they hope to implement onboard authentication and upgrade newer hardware wallets with higher-level security components.<\/p>\n<p>OneKey wrote that the main <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/how-do-crypto-hardware-wallet-firms-make-money\" rel=\"noopener\">purpose of hardware wallets<\/a> has always been to protect users\u2019 money from malware attacks, computer viruses and other remote dangers, but unfortunately, nothing can be 100% secure.\u00a0<\/p>\n<p>\u201cWhen we look at the entire hardware wallet manufacturing process, from silicon crystals to chip code, from firmware to software, it\u2019s safe to say that with enough money, time and resources, any hardware barrier can be breached, even if it&#8217;s a nuclear weapon control system.\u201d<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/cointelegraph.com\/news\/onekey-says-it-s-fixed-the-flaw-that-got-its-hardware-wallet-hacked-in-1-second\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Crypto hardware wallet provider OneKey says it has already addressed a vulnerability in its firmware that allowed one of its hardware wallets to be hacked in one second flat. A video on YouTube posted\u00a0on Feb. 10 by cybersecurity startup Unciphered showed they had figured out a way to exploit a \u201cMassive critical vulnerability\u201d that allowed [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":43948,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[38],"tags":[7993,12920,846,3331,13939,1130],"class_list":["post-43947","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blockchain","tag-fixed","tag-flaw","tag-hacked","tag-hardware","tag-onekey","tag-wallet"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"http:\/\/egrowonline.com\/wp-content\/uploads\/2023\/02\/db77cc7f-6f23-416d-8446-79ee150e189b.jpg","_links":{"self":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/43947","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=43947"}],"version-history":[{"count":1,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/43947\/revisions"}],"predecessor-version":[{"id":43949,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/43947\/revisions\/43949"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/media\/43948"}],"wp:attachment":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=43947"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=43947"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=43947"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}