Tuesday, November 18, 2025
DIGESTWIRE
Contribute
CONTACT US
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
DIGESTWIRE
No Result
View All Result
Home Blockchain

How malicious hardware wallet firmware can leak your Bitcoin seed phrase

by DigestWire member
August 6, 2024
in Blockchain, Crypto Market, Cryptocurrency
0
How malicious hardware wallet firmware can leak your Bitcoin seed phrase
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Dark Skippy, a recently discovered attack vector, poses a significant threat to the security of Bitcoin hardware wallets. The method allows a compromised signer to exfiltrate its master seed phrase by embedding portions into transaction signatures, requiring only two transactions to complete. Unlike previous assumptions that multiple transactions were necessary, this streamlined approach means that a single use of a compromised device can lead to a complete security breach.

The attack hinges on using malicious firmware that alters the standard signing process. Typically, signing operations use a randomly generated nonce as part of the Schnorr signature process. However, in a device compromised by Dark Skippy, the firmware instead uses deterministic, low-entropy nonces derived from the master seed. Specifically, the first half of the seed is used for one transaction and the second half for another, allowing an attacker to piece together the entire seed if they can observe both transactions.

This attack requires that the signing device be corrupted, which can occur through various means: malicious firmware could be installed by an attacker or inadvertently by a user; alternatively, attackers might distribute pre-compromised devices through supply chains. Once in place, the compromised firmware embeds secret data within public transaction signatures, effectively using the blockchain as a covert channel to leak sensitive information.

The attacker monitors the blockchain for transactions with a specific watermark that reveals the presence of the embedded data. Utilizing algorithms such as Pollard’s Kangaroo, the attacker can retrieve the low-entropy nonces from the public signature data, subsequently reconstructing the seed and gaining control over the victim’s wallet.

Although this attack vector does not represent a new fundamental vulnerability—nonce covert channels have been known and mitigated to some extent—Dark Skippy refines and exploits these vulnerabilities more efficiently than previous methods. The subtlety and efficiency of this technique make it particularly dangerous, as it can be executed without the user’s knowledge and is challenging to detect after the fact.

Robin Linus is credited with Discovering the attack and bringing attention to its potential during a Twitter discussion last year. Further investigation during a security workshop confirmed the feasibility of extracting an entire 12-word seed using minimal computational resources, demonstrating the attack’s effectiveness and the ease with which it could be executed using even a modestly equipped system.

Mitigations for such attacks include implementing ‘anti-exfil’ protocols in signing devices, which can help prevent the unauthorized leaking of secret data. However, these defenses require rigorous implementation and continuous development to stay ahead of evolving threats.

The cryptographic community and device manufacturers are urged to address these vulnerabilities promptly to safeguard users against potential exploits facilitated by Dark Skippy and similar methods. Users should remain vigilant, ensuring their devices run genuine firmware and are sourced from reputable vendors to minimize the risk of compromise. Further, multi-sig setups can create additional defenses against the attack vector.

The post How malicious hardware wallet firmware can leak your Bitcoin seed phrase appeared first on CryptoSlate.

Read Entire Article
Tags: BlockchainCoin SurgesCryptoslate
Share30Tweet19
Next Post
Coinshares Sees $528 Million Outflow From Crypto Products Due to Recession Fears

Coinshares Sees $528 Million Outflow From Crypto Products Due to Recession Fears

Cardano Defies Market Downturn: On-Chain Activity Surges in July, Stats Show

Gold hopes for Team GB – but there’s an early blow in individual jumping | Olympics latest on Sky Sports

Gold hopes for Team GB - but there's an early blow in individual jumping | Olympics latest on Sky Sports

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

No Result
View All Result
Coins MarketCap Live Updates Coins MarketCap Live Updates Coins MarketCap Live Updates
ADVERTISEMENT

Highlights

‘Absolutely rapid’ Wood pushes for first Test selection after injury scare

Doha Film Institute CEO Fatma Hassan Alremaihi on Spirit of New Doha Film Festival: ‘Film, Gaming, Animation and Cosplay Are All Forms of Expression That Inspire and Unite People’

Why Is Bitcoin Price Crashing? Arthur Hayes Isn’t Surprised

Crypto Market Update: Hyperliquid (HYPE), ASTER and Monero (XMR) Rise Despite BTC Correction

NEM Price Prediction 2025, 2026 – 2030: Will The XEM Price Go Up?

AMINA HK Gains SFC Type 1 License For Professional Crypto Services

Trending

Scotland v Denmark: Line-ups, stats and preview
Football

Scotland v Denmark: Line-ups, stats and preview

by DigestWire member
November 18, 2025
0

Scotland host Denmark tomorrow. Read our in-depth preview here...

Voges to step down as Western Australia coach for franchise roles

Voges to step down as Western Australia coach for franchise roles

November 18, 2025
Bangladesh women’s tour of India in December postponed

Bangladesh women’s tour of India in December postponed

November 18, 2025
‘Absolutely rapid’ Wood pushes for first Test selection after injury scare

‘Absolutely rapid’ Wood pushes for first Test selection after injury scare

November 18, 2025
Doha Film Institute CEO Fatma Hassan Alremaihi on Spirit of New Doha Film Festival: ‘Film, Gaming, Animation and Cosplay Are All Forms of Expression That Inspire and Unite People’

Doha Film Institute CEO Fatma Hassan Alremaihi on Spirit of New Doha Film Festival: ‘Film, Gaming, Animation and Cosplay Are All Forms of Expression That Inspire and Unite People’

November 18, 2025
DIGEST WIRE

DigestWire is an automated news feed that utilizes AI technology to gather information from sources with varying perspectives. This allows users to gain a comprehensive understanding of different arguments and make informed decisions. DigestWire is dedicated to serving the public interest and upholding democratic values.

Privacy Policy     Terms and Conditions

Recent News

  • Scotland v Denmark: Line-ups, stats and preview November 18, 2025
  • Voges to step down as Western Australia coach for franchise roles November 18, 2025
  • Bangladesh women’s tour of India in December postponed November 18, 2025

Categories

  • Blockchain
  • Blog
  • Breaking News
  • Business
  • Cricket
  • Crypto Market
  • Cryptocurrency
  • Defense
  • Entertainment
  • Football
  • Founders
  • Health Care
  • Opinion
  • Politics
  • Sports
  • Strange
  • Technology
  • UK News
  • Uncategorized
  • US News
  • World

© 2020-23 Digest Wire. All rights belong to their respective owners.

No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Blockchain
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Strange
  • Blog
  • Founders
  • Contribute!

© 2024 Digest Wire - All right reserved.

Privacy Policy   Terms and Conditions

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.