Bitcoin Forum
April 25, 2024, 04:59:24 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: 1 2 [All]
  Print  
Author Topic: Has a BTC hardware wallet ever been hacked?  (Read 3380 times)
steppinup (OP)
Newbie
*
Offline Offline

Activity: 9
Merit: 0


View Profile
January 28, 2017, 04:58:31 PM
 #1

Maybe a better question is whether BTC in a hardware wallet has ever been stolen?
TalkImg was created especially for hosting images on bitcointalk.org: try it next time you want to post an image
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714064364
Hero Member
*
Offline Offline

Posts: 1714064364

View Profile Personal Message (Offline)

Ignore
1714064364
Reply with quote  #2

1714064364
Report to moderator
amacar2
Legendary
*
Offline Offline

Activity: 1120
Merit: 1007

CryptoTalk.Org - Get Paid for every Post!


View Profile
January 28, 2017, 05:08:15 PM
 #2

Maybe a better question is whether BTC in a hardware wallet has ever been stolen?
I haven't heard about such incident but this can happen, even if passphrase for hardware wallet get lost/stolen you will loss whatever bitcoin you have there if you haven't made backup of it.

But comparatively hardware wallet is the most secure wallet if it is not tampered by manufacturer.

 
                                . ██████████.
                              .████████████████.
                           .██████████████████████.
                        -█████████████████████████████
                     .██████████████████████████████████.
                  -█████████████████████████████████████████
               -███████████████████████████████████████████████
           .-█████████████████████████████████████████████████████.
        .████████████████████████████████████████████████████████████
       .██████████████████████████████████████████████████████████████.
       .██████████████████████████████████████████████████████████████.
       ..████████████████████████████████████████████████████████████..
       .   .██████████████████████████████████████████████████████.
       .      .████████████████████████████████████████████████.

       .       .██████████████████████████████████████████████
       .    ██████████████████████████████████████████████████████
       .█████████████████████████████████████████████████████████████.
        .███████████████████████████████████████████████████████████
           .█████████████████████████████████████████████████████
              .████████████████████████████████████████████████
                   ████████████████████████████████████████
                      ██████████████████████████████████
                          ██████████████████████████
                             ████████████████████
                               ████████████████
                                   █████████
.YoBit AirDrop $.|.Get 700 YoDollars for Free!.🏆
franky1
Legendary
*
Offline Offline

Activity: 4200
Merit: 4442



View Profile
January 28, 2017, 05:11:16 PM
 #3

put it this way, they are not 100% fool proof.

envision this.

a hacker makes a trojan with a tool the emulates the browser extension that trezor uses.

so it sits on a computer and waits for someone to plug in their trezor.
next some victim plugs in their trezor. and the trojan displays what looks like the usual trezor page. but this time. its actually the trojan. saying

"error on device, to restore please type in seed"
then the pin number.

and now the hacker has all your details to duplicate your keys on his own device.

hardware wallet are an extra layer of security above just having the private key on you computer.. but dont think they are fool proof. they still need to work on that

I DO NOT TRADE OR ACT AS ESCROW ON THIS FORUM EVER.
Please do your own research & respect what is written here as both opinion & information gleaned from experience. many people replying with insults but no on-topic content substance, automatically are 'facepalmed' and yawned at
BitcoinBarrel
Legendary
*
Offline Offline

Activity: 1961
Merit: 1020


Fill Your Barrel with Bitcoins!


View Profile WWW
January 28, 2017, 07:47:41 PM
 #4

There was a recent incident where the owner of KeepKey hardware wallet got hacked and customer information was compromised. The private keys of the user wallets were safe, but still a security risk nonetheless.



        ▄▄▄▄▄▄▄▄▄▄
     ▄██████████████▄
   ▄█████████████████▌
  ▐███████████████████▌
 ▄█████████████████████▄
 ███████████████████████
▐███████████████████████
▐███████████████████████
▐███████████████████████
▐███████████████████████
 ██████████████████████▀
 ▀████████████████████▀
  ▀██████████████████
    ▀▀████████████▀▀
.
.....
.....
.....
.....
.....
.....





calkob
Hero Member
*****
Offline Offline

Activity: 1092
Merit: 520


View Profile
January 28, 2017, 08:34:17 PM
 #5

The answer is NO, the keepkey incident wasnt in anyway a hack of the hardware i think it was the owner of the company got his email hacked or something like that.  Not great PR but still not a disaster for those using keepkey.  I know for certain that Ledger wallet cant be hacked, the tech in it has been used in European banking cards for years.
Coin-Keeper
Hero Member
*****
Offline Offline

Activity: 758
Merit: 606



View Profile
January 28, 2017, 08:35:20 PM
 #6

Quote
so it sits on a computer and waits for someone to plug in their trezor.
next some victim plugs in their trezor. and the trojan displays what looks like the usual trezor page. but this time. its actually the trojan. saying

"error on device, to restore please type in seed"
then the pin number.

and now the hacker has all your details to duplicate your keys on his own device.

Its difficult to imagine a user falling for that one!  I suppose anything is possible but wouldn't users know to only initialize their Trezor on a trusted system?

BTC: 1PYSBbuKM3kW19xe9TXJQfq64rPhd8XorF
Staked and Verified: https://bitcointalk.org/index.php?topic=996318.msg17102755#msg17102755
franky1
Legendary
*
Offline Offline

Activity: 4200
Merit: 4442



View Profile
January 28, 2017, 08:40:53 PM
 #7

Quote
so it sits on a computer and waits for someone to plug in their trezor.
next some victim plugs in their trezor. and the trojan displays what looks like the usual trezor page. but this time. its actually the trojan. saying

"error on device, to restore please type in seed"
then the pin number.

and now the hacker has all your details to duplicate your keys on his own device.

Its difficult to imagine a user falling for that one!  I suppose anything is possible but wouldn't users know to only initialize their Trezor on a trusted system?

the idea of a trusted system is what a hardware wallet meant to be.. not needing internet or a computer.
as soon as you introduce the internet and requirement of downloading a browser extension or bitcoin client. its less than 100% trusted

the next gen hardware wallets should be that the privkey is locked to a inaccessable data source. and just receives public keys via NFC and sends out signed tx's via NFC.

if you need to reset it. you do it from an offline system. not via a browser extension.

I DO NOT TRADE OR ACT AS ESCROW ON THIS FORUM EVER.
Please do your own research & respect what is written here as both opinion & information gleaned from experience. many people replying with insults but no on-topic content substance, automatically are 'facepalmed' and yawned at
Coin-Keeper
Hero Member
*****
Offline Offline

Activity: 758
Merit: 606



View Profile
January 28, 2017, 08:55:22 PM
 #8

I agree with your post.  I only do offline updates already!  With Linux, Electrum, and only onion connections, I just don't see how they could get to my Trezor.  I would have to say the better hardware wallets discussed in this forum are only weakened by a pretty serious user error.  Not a little one either, but a major mistake.  I realize that security is my thing in every single way.  I may be surprised but I can't even imagine the "best" out there getting to my Trezor keys.  Not challenging anyone here, just feeling really good about hardware wallet security.  I feel the same about Ledger stuff too.  I need many numerous password wallets from each Trezor I have so I have settled on a Trezor.  So I believe that NO major brand hardware wallet has ever been hacked to date.  I don't count a serious user error as a hack.

BTC: 1PYSBbuKM3kW19xe9TXJQfq64rPhd8XorF
Staked and Verified: https://bitcointalk.org/index.php?topic=996318.msg17102755#msg17102755
HaXX0R1337
Sr. Member
****
Offline Offline

Activity: 574
Merit: 252



View Profile
January 28, 2017, 10:11:20 PM
 #9

So I believe that NO major brand hardware wallet has ever been hacked to date.  I don't count a serious user error as a hack.
There is not a single reported incident of a hardware wallet being hacked till now,unless people do make silly mistakes with it it cannot be hacked because it is not always plugged online for the hacker to try something fishy and since everyone uses hardware wallets to store huge amount of coins it is infact a secure method.

▬▬▬▬▬▬

▬▬▬▬▬▬
       ▄▄█████████▄▄
    ▄█████████████████▄
  ▄█████▀▀       ▀▀█████▄
 ▄████▀             ▀████▄
▄████▀    ▄▄▄▄▄▄▄    ▀████▄
█████    █████████    █████
█████    ████████▀    █████
█████     ▄▄▄▄        █████
▀████▄   ██████      ▄████▀
 ▀████   █████▀     ▄████▀
   ▀▀     ▄▄▄    ▄▄█████▀
         █████   █████▀
         ▀███▀    ▀▀
COMPRO
FINANCE
▬▬▬▬▬▬

▬▬▬▬▬▬
▄▄█████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄████████████████▀▀█████▄
▄████████████▀▀▀    ██████▄
████████▀▀▀   ▄▀   ████████
█████▄     ▄█▀     ████████
████████▄ █▀      █████████
▀████████▌▐       ████████▀
▀████████ ▄██▄  ████████▀
▀█████████████▄███████▀
▀█████████████████▀
▀▀█████████▀▀
ranochigo
Legendary
*
Offline Offline

Activity: 2954
Merit: 4163


View Profile
January 29, 2017, 03:37:35 AM
 #10

None, as far as I know of.

Hardware wallets aren't the golden shield to avoid any attacks. They are still vulnerable in the sense that the manufacturer can hide a vulnerability in the source code for hackers to exploit. An example is intentionally weakening the RNG. Users still have to review the source code and audit it.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
romero121
Legendary
*
Offline Offline

Activity: 3164
Merit: 1213


View Profile
January 29, 2017, 04:22:33 AM
 #11

Haven't heard of such an issue, but people losing their hardware wallet have been found in several articles. Once lost is more than that of losing the private keys.
achow101
Staff
Legendary
*
Offline Offline

Activity: 3374
Merit: 6535


Just writing some code


View Profile WWW
January 29, 2017, 05:27:30 AM
 #12

This entirely depends on your definition of "hacked".

If by "hack" you mean that some vulnerability was found that allows Bitcoin to be stolen, then most certainly. Power analysis vulnerabilities have been found in at least one wallet, Trezor. This vulnerability works by examining the power drawn by the device to determine private keys. This vulnerability was fixed with a firmware update.

There are many attacks that can be done to extract the private keys from a hardware wallet such as Rubber Hose Cryptanalysis. Whether any such attacks have actually been used to steal Bitcoin is unknown.

So, if by "hack" you mean that Bitcoin were stolen from someone who stores their private keys on a hardware wallet, then, AFAIK, there have been no such (documented) "hacks". Even so, that does not mean that hardware wallets are foolproof, just that no one has found a viable way to steal the private keys.

noormcs5
Hero Member
*****
Online Online

Activity: 2618
Merit: 613


Leading Crypto Sports Betting & Casino Platform


View Profile
January 29, 2017, 06:53:02 AM
 #13

There was a recent incident where the owner of KeepKey hardware wallet got hacked and customer information was compromised. The private keys of the user wallets were safe, but still a security risk nonetheless.

No it was not a wallet hack. It was just related to keepkey email hack. I have not heard any incident where hardware wallet is hacked. Unless the person or company deliberately gives the private key, it is impossible to hack.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
lol3c
Hero Member
*****
Offline Offline

Activity: 518
Merit: 500



View Profile
January 29, 2017, 01:09:03 PM
 #14

If you know how to protect you wallet and your private key, I doubt that there is a possibility that your hardware wallet will be hacked. Try not to download junk file because they may harm your computer and contain Trojan horse. Trojan can easily access your computer and transfer all the Bitoin from your wallet to another.
Pettuh4
Sr. Member
****
Offline Offline

Activity: 812
Merit: 251


View Profile
January 29, 2017, 01:21:12 PM
 #15

Well it's not that I know or heard of but it should be possible since a lot of governments and financial institutions have cast doubt on Bitcoin security and are therefore running standard security tests to ascertain its strength before they adopt it full time do until its factually proven to be safe anything can happen.
deadsilent
Hero Member
*****
Offline Offline

Activity: 1148
Merit: 500



View Profile
January 29, 2017, 01:21:34 PM
 #16

That depends on the owner. All kinds of bitcoin wallet are safe. But if the owner is not responsible at keeping it. He might lose his bitcoin. We're humans. We can be fool. Hackers will find a way to steal your bitcoin. Maybe thru phishing or sending malicious software. Its not about the wallet. Its about the owner. Reponsible owner know how to keep their bitcoin safe.
BillyBobZorton
Legendary
*
Offline Offline

Activity: 1204
Merit: 1028


View Profile
January 29, 2017, 01:25:59 PM
 #17

The answer is NO, the keepkey incident wasnt in anyway a hack of the hardware i think it was the owner of the company got his email hacked or something like that.  Not great PR but still not a disaster for those using keepkey.  I know for certain that Ledger wallet cant be hacked, the tech in it has been used in European banking cards for years.

If something depends on the owner getting or not hacker then that product is already a failure.

I think the best way to cold storage keys is still a bip38 paperwallet created in an offline computer.

Other than that, just use Bitcoin Core with a strong password and you are helping activate segwit while you are at it.
densuj
Legendary
*
Offline Offline

Activity: 910
Merit: 1000


View Profile
February 01, 2017, 10:57:19 AM
 #18

Maybe a better question is whether BTC in a hardware wallet has ever been stolen?
If it be stolen as online not and something impossible but it will be different
if the bitcoin be stolen by the people who know the hardware wallet
and I never heard bitcoin be stolen from hardware wallet, it is the most safe wallet.
erickkyut
Hero Member
*****
Offline Offline

Activity: 1176
Merit: 509


View Profile
February 01, 2017, 11:29:56 AM
 #19

First, what do you mean by bitcoin hardware wallet? Do you mean a wallet that you install in your computer? If that is the thing, even though you install it in your computer, it still needs an online connection because it needs to be registered and updated on the server of your online wallet provider. Yes there are lots of wallets that had been hacked before!
CARrency
Sr. Member
****
Offline Offline

Activity: 546
Merit: 256



View Profile
February 01, 2017, 11:35:23 AM
 #20

I researched these before and i have read many articles that their bitcoin wallet is being hacked but not stolen.
Thats why i had some second thoughts of making one and earning bitcoin.
but the good thing is you must really trust this sites because it is their job and all you need to do is to trust them.

▄▄█████████▄▄
▄█████████████████▄
▄████████████ ▀███████▄
▄█████████████   ▀██████▄
▄█████████ ▀████▄   ▀█████▄
██████████  ██████▄   █████
█████ ▀████▄ ▀██████▄ █████
█████   ▀████▄ ▀ ██████████
▀█████▄   ▀████▄ █████████▀
▀██████▄   █████████████▀
▀███████▄ ████████████▀
▀█████████████████▀
▀▀█████████▀▀
Emporium.
Finance
.
Decentralized Peer-to-Peer
Marketplace and DeFi
Liquidity Mining Platform
.
▄▄█▀▀██▀██▀▄▄
▄███▀██▀▀▀▀▀ ▄▄   
 ▀          ▄█▀▄█▄     
▄▄▄▄▄        ▀   ▀██▄███▄
▄██████▄          ▄▄██████▄
███████▌       ▄███████████
█████████▄  ▀█▄████████████
███████████▄▄▄▀▀▀▀▀████████
▀█████████████▀     ▀▀████▀
▀████████████▄        ██▀
▀████████████▌    ▄▄██▀
▀██████████▌  ▄███▀
▀▀██████ ▄█▀▀
Available
in +125
Countries
▄███▄
█████
▀███▀
▄▄▄     ▄█████▄     ▄▄▄
█████    ███████    █████
█████    ███████    █████
▄███▄               ▄███▄
███████     ███     ███████
███████ ██▄█████▄██ ███████
▀▀▀▀▀▀▀  ███▀ ▀███  ▀▀▀▀▀▀▀
███▄ ▄███
██▀█████▀██
███
Community
Governance
System
▄▄██████▄▄ ▄▀▄
      ▀▀▀ ▄██▄
          ▀██ ▄██▄       ▄█
        ▄██   ▀▀███▄   ▄███
       ▄██        ▀█▄   ███
      ▄██           ▀  ▄███
     ▄██        ▄▄     ▀███
    ▄██        ██▀      ███
   ▄██                ▄████
  ▄██         ▄█████████▄ █
  ▀▀      ▄▄▄█████ █▀  ████
      ▄▄██▀▀██▀  ███▄  ▄███
    ▄██████████████████████
Liquidity
Mining
Platform
.
████████████████████████████████████████████████████████
.
JOIN NOW
.
████████████████████████████████████████████████████████
soros017
Full Member
***
Offline Offline

Activity: 238
Merit: 250



View Profile
February 01, 2017, 11:59:44 AM
 #21

I researched these before and i have read many articles that their bitcoin wallet is being hacked but not stolen.
Thats why i had some second thoughts of making one and earning bitcoin.
but the good thing is you must really trust this sites because it is their job and all you need to do is to trust them.
I have seen cases of common wallets that have gone through these problems, cases in which the owners had not taken all the security measures, of course. However, I have never seen articles reporting that hadware wallets have been hacked. If you refer to this, I would be grateful if you presented the sources. And you have no obligation to trust anyone. I really did not understand what you said.
steppinup (OP)
Newbie
*
Offline Offline

Activity: 9
Merit: 0


View Profile
February 08, 2017, 03:29:26 PM
 #22

This is a great community for helping new bitcoiners that are serious about getting involved the right way.  Thank you.

HarringtonStark
Sr. Member
****
Offline Offline

Activity: 294
Merit: 250


View Profile WWW
February 08, 2017, 03:34:12 PM
 #23

Anything can be hacked. Hackers can create a program that mimics the program you use when you sync your hardware wallet. They provide excellent security but they are not fool proof. Hackers usually say "There is always a way in!"

Kprawn
Legendary
*
Offline Offline

Activity: 1904
Merit: 1073


View Profile
February 08, 2017, 03:37:46 PM
 #24

The only instance I know of is where someone figured out how to extract the private key with special tools, but you have to have the device with

you to do that, and it requires a lot of specialized knowledge. So you have to steal the device and then you have to use special tools to extract the

private key. Hackers will not be able to extract it remotely over the internet.  Tongue

THE FIRST DECENTRALIZED & PLAYER-OWNED CASINO
.EARNBET..EARN BITCOIN: DIVIDENDS
FOR-LIFETIME & MUCH MORE.
. BET WITH: BTCETHEOSLTCBCHWAXXRPBNB
.JOIN US: GITLABTWITTERTELEGRAM
acyclovir
Newbie
*
Offline Offline

Activity: 45
Merit: 0


View Profile
August 22, 2017, 05:15:28 PM
 #25

Look at this:

https://medium.com/@Zero404Cool/trezor-security-glitches-reveal-your-private-keys-761eeab03ff8
https://medium.com/@Zero404Cool/frozen-trezor-data-remanence-attacks-de4d70c9ee8c
BitcoinNewsMagazine
Legendary
*
Offline Offline

Activity: 1806
Merit: 1164



View Profile WWW
August 22, 2017, 06:11:51 PM
 #26

If anyone had their Trezor or Nano S stolen and hacked it would be all over social media. If your hardware wallet is stolen and you use passphrases you have significant extra protection. Plenty of time to restore your seed to your spare and move your coins. As long as you follow recommended procedure from the manufacturer you may as well worry about getting struck by lightning.

wdnj
Hero Member
*****
Offline Offline

Activity: 762
Merit: 500



View Profile
August 22, 2017, 10:25:17 PM
 #27

As far as I know there are some chances to get hacked with hardware wallets but only if you buy the used ones.

Because the hacker can modify it and then re-sell for a cheaper price, that's why it is always recommended to buy from the official ones.
MostafaGamal
Sr. Member
****
Offline Offline

Activity: 1153
Merit: 252


View Profile
August 22, 2017, 10:29:19 PM
 #28

i didn't hear anything about it before .. but anything can be hacked so we should take care
Pages: 1 2 [All]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!