• Dapps:16.23K
  • Blockchains:78
  • Active users:66.47M
  • 30d volume:$303.26B
  • 30d transactions:$879.24M

Vulnerabilities in Trezor Safe 3 and Safe 5 Expose Funds to Risk

user avatar

by Giorgi Kostiuk

3 hours ago


Trezor's latest hardware wallets, Safe 3 and Safe 5, face serious security challenges. Ledger Donjon's research team identified vulnerabilities in the devices' microcontrollers that could enable remote hacker access to user funds.

Cryptographic Security Issues in New Devices

Despite upgrades to EAL6+ level security features, all cryptographic operations are still executed on the microcontroller, susceptible to voltage glitching attacks, allowing attackers to extract secrets and modify firmware.

Trezor's Authentication System Fails to Protect Microcontroller

Ledger's findings reveal that Trezor's cryptographic authentication does not verify microcontroller firmware. The Secure Element is linked with the microcontroller by a pre-shared secret, which is vulnerable to voltage glitching.

Firmware Validation Flaws Leave Users Exposed

Firmware integrity checks can be bypassed if attackers manipulate computation, allowing modified firmware to appear genuine and risking private keys and transaction data security.

Security issues related to the microcontroller pose a serious threat to Trezor Safe 3 and Safe 5 users. Although patches and improvements have been made, exploitation risks remain high until microcontroller protection is enhanced.

0

Share

Other news

Sui and WLFI: A New Chapter in Decentralized Finance

Sui Network partners with World Liberty Financial to support Web3 projects.

user avatarGiorgi Kostiuk

a few seconds ago

Pi Network's Evolution: The Importance of Pi Day 2025 in Crypto

Pi Day 2025 symbolizes Pi Network's achievements and future. New announcements and network growth, including Open Mainnet achievements, are expected.

user avatarGiorgi Kostiuk

a minute ago

How Blockchain and Cryptocurrency are Changing Real Estate

Asset tokenization: blockchain enhances real estate investment liquidity and accessibility.

user avatarGiorgi Kostiuk

2 minutes ago

The Absence of a Roadmap Raises Questions for Pi Network

The absence of an updated Pi Network roadmap raises concerns in the user community. What actions will the project's team take?

user avatarGiorgi Kostiuk

2 minutes ago

Core DAO Ignition Season 3: What to Expect

Season 3 of Core DAO Ignition starts March 12, 2025, offering new opportunities in the BTCFi ecosystem.

user avatarGiorgi Kostiuk

5 minutes ago

U.S. Establishes Strategic Bitcoin Reserve: New Era in Crypto Policy

President Donald Trump establishes a strategic Bitcoin reserve and U.S. digital asset stockpile, marking a historic shift in crypto policy.

user avatarGiorgi Kostiuk

7 minutes ago

dapp expert logo
© 2020-2025. DappExpert. All rights reserved.
© 2020-2025. DappExpert. All rights reserved.

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.