Hacker in the US hacked into Trezor wallet to help user
A hacker recovered $2 million in cryptocurrency to a wallet’s owner who forgot the password

27.01.2022 - 09:15
139
1 min
0
What’s new? Joe Grand, known under the pseudonym Kingpin, has posted a video on YouTube in which he explained how he hacked into the Trezor One crypto wallet. The hacker broke into the wallet at the request of investors who had forgotten the password from him back in 2018. The accumulated investments amounted to about $2 million in cryptocurrency.
How did the hacker manage to hack the wallet? It took Grand 12 weeks to recover the lost PIN. During a firmware update, the Trezor One wallets temporarily move the code and key to RAM and then back to flash memory. Grand found that in the version of the firmware installed on the investors’ wallet, this information was not moved, but copied to RAM. This meant that if the hack failed and the RAM was erased, the PIN and key information would still be stored in the flash memory.
After using a fault injection attack, Grand still got the cherished numbers. After the hacker’s video of the hack was released, Trezor reported it was working on a fix for this vulnerability.
Useful material?
Incidents
The attacker conducted a flash loan attack by exploiting vulnerabilities in the protocol.
Jul 21, 2023
Market
The former CEO of the exchange discussed building a bunker and conducting genetic experiments with his younger brother
Jul 21, 2023
Incidents
Hayden Adams restored the account nine hours later
Jul 21, 2023
Market
Chainlink CEO Sergey Nazarov predicted the growth of the blockchain industry by trillions of dollars
Jul 20, 2023
Market
The company stopped accepting bitcoin payments in May 2021
Jul 20, 2023
Politics
The bill is designed “to fight the rise in crypto-facilitated crime”
Jul 20, 2023