Trezor Safe 7 Wallet Vulnerability Disclosed, User Funds Deemed Secure
- An audit by the Ledger Donjon team uncovered a hardware vulnerability in Trezor’s TROPIC01 Secure Element chip.
- The vulnerability allows an attacker to reveal one of three “secrets” protecting a user’s PIN, reducing protection layers from three to two.
- Exploiting this flaw requires physical possession of the hardware wallet, disassembly, and specialized lab equipment.
- Trezor confirmed that user funds remain safe due to the complexity and impracticality of the attack.
- The vulnerability cannot be patched with a firmware update as it is hardware-based.
The security audit by Ledger Donjon revealed a potential risk in Trezor’s Safe 7 wallet but emphasized that exploiting the flaw is highly impractical due to its requirements for physical access and advanced equipment. Despite this issue, Trezor assures users their funds are secure because the attack only compromises one of three protection layers.
This disclosure highlights the importance of maintaining physical security over cold storage devices like Trezor’s Safe 7 wallets, as even sophisticated attacks require significant resources to succeed. (Source)