{"id":399247,"date":"2022-01-26T05:17:58","date_gmt":"2022-01-26T02:17:58","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/engineer-hacks-trezor-wallet-recovers-2m-in-lost-crypto\/"},"modified":"2022-01-26T05:17:58","modified_gmt":"2022-01-26T02:17:58","slug":"engineer-hacks-trezor-wallet-recovers-2m-in-lost-crypto","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/engineer-hacks-trezor-wallet-recovers-2m-in-lost-crypto\/","title":{"rendered":"# Engineer hacks Trezor wallet, recovers $2M in &#8216;lost&#8217; crypto"},"content":{"rendered":"<p>&#8220;<strong># Engineer hacks Trezor wallet, recovers $2M in &#8216;lost&#8217; crypto <\/strong>&#8221;<br \/>\n<img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/images\/840_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjItMDEvNmY1N2E4MWYtZTk0NC00YzY0LTk0NDktZmI4ZjJiYzNjZTIwLmpwZw==.jpg\" \/><\/p>\n<div class=\"post-content\" data-v-128018ef>A computer engineer and hardware hacker has revealed how he managed to crack a Trezor One hardware wallet containing more than $2 million in funds.<\/p>\n<p>Joe Grand \u2014 who is based in Portland also known by his hacker alias \u201cKingpin&#8221; \u2014 <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.youtube.com\/watch?v=dT9y-KQbqi4\">uploaded <\/a>a <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/social-mediaa\/\" data-internallinksmanager029f6b8e52c=\"1\" title=\"Social Media\" target=\"_blank\" rel=\"noopener\">Youtube<\/a> video explaining how he pulled off the ingenious hack.<\/p>\n<p>After deciding to cash out an original investment of roughly $50,000 in Theta in 2018, Dan Reich, a NYC based entrepreneur, and his friend, realized that they had lost the security PIN to the Trezor One the tokens were stored on. After unsuccessfully trying to guess the security PIN 12 times, they decided to quit before the wallet automatically wiped itself after 16 incorrect guesses.<\/p>\n<p>But with their investment growing to $2 million this year, they redoubled their efforts to access the funds. Without their wallet\u2019s seed phrase or PIN the only way to retrieve the tokens was through hacking.<\/p>\n<p>They reached out to Grand who spent 12 weeks of trial and error but eventually found a way to recover the lost PIN.<\/p>\n<p>The key to this hack was that during a firmware update the Trezor One wallets temporarily move the PIN and key to RAM, only to later move them back to flash once the firmware is installed. Grand found that in the version of firmware installed on Reich\u2019s wallet this information was not moved but copied to the RAM, which means that if the hack fails and RAM is erased the information about the PIN and key would still be stored in flash.<\/p>\n<p>After using a fault injection attack \u2014 a technique that alters the voltage going to the chip \u2014 Grand was able to surpass the security the microcontrollers have to prevent hackers from reading RAM, and obtained the PIN needed to access the wallet and the funds. Grand explained:<\/p>\n<blockquote><p>\u201cWe are basically causing misbehavior on the silicon chip inside the device in order to defeat security. And what ended up h<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a>ening is that I was sitting here watching the computer screen and saw that I was able to defeat the security, the private information, the recovery seed, and the pin that I was going after popped up on the screen.&#8221;<\/p><\/blockquote>\n<p>According to a recent <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/Trezor\/status\/1485736962262810626\">tweet<\/a> from Trezor this vulnerability that allows it to read from the wallet\u2019s RAM is an older one that has already been fixed for newer devices. But unless changes are made to the microcontroller fault injection attacks still can pose a risk.<\/p>\n<p><template data-name=\"subscription_form\" data-type=\"markets_outlook\"><\/template><\/div>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">News<\/a> articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/general\/\" target=\"_blank\" rel=\"noopener\">General category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/cointelegraph.com\/news\/engineer-hacks-trezor-wallet-recovers-2m-in-lost-crypto\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;# Engineer hacks Trezor wallet, recovers $2M in &#8216;lost&#8217; crypto &#8221; A computer engineer and hardware hacker has revealed how he managed to crack a Trezor One hardware wallet containing more than $2 million in funds. Joe Grand \u2014 who is based in Portland also known by his hacker alias \u201cKingpin&#8221; \u2014 uploaded a Youtube&#8230;<\/p>\n","protected":false},"author":1,"featured_media":399248,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/images.cointelegraph.com\/images\/1200_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjItMDEvNmY1N2E4MWYtZTk0NC00YzY0LTk0NDktZmI4ZjJiYzNjZTIwLmpwZw==.jpg","fifu_image_alt":"","footnotes":""},"categories":[1],"tags":[74894,75820,70944],"class_list":["post-399247","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general","tag-blockchain","tag-trezor","tag-hackers"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/399247","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=399247"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/399247\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/399248"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=399247"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=399247"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=399247"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}