Bitcoin Forum
November 13, 2024, 04:27:31 PM *
News: Check out the artwork 1Dq created to commemorate this forum's 15th anniversary
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [BUG] Don't update Wasabi if you are using Trezor hw  (Read 441 times)
dkbit98 (OP)
Legendary
*
Offline Offline

Activity: 2408
Merit: 7567



View Profile WWW
June 14, 2020, 09:44:44 PM
 #1

Recently found BIP-174 security vulnerability was fixed by Trezor, BUT it broke compatibility with third party software like Wasabi wallet is.

Quote
If you’re a Wasabi Wallet user with a Trezor device, please don’t update your current Wasabi Wallet installation and Trezor devices to version 2.3.1
(Trezor Model T) and version 1.9.1 (Trezor One) yet or you may get locked out of your bitcoins until we fix the issue.
Please update both when we’ve published a new version of Wasabi Wallet through our official channels.

Addendum:
We are advising users to not update Wasabi Wallet until the fixes are out due to the potential of bad actors distributing a malicious copy of Wasabi Wallet and exploiting the vulnerability.
source: https://medium.com/@jmacato/wasabi-wallets-advisory-for-trezor-users-7d942c727f92

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Husna QA
Legendary
*
Offline Offline

Activity: 2450
Merit: 3042


Buy on Amazon with Crypto


View Profile WWW
June 16, 2020, 01:18:44 AM
 #2

It seems that for Trezor users who have updated to the latest firmware (Trezor One v1.9.1 and Trezor Model T v2.3.1).
Recommended to temporarily not use third-party wallets such as Electrum and Wasabi until they are updated to work correctly and avoid problems, as mentioned in their blog:

The firmware updates for Trezor One (version 1.9.1) and Trezor Model T (version 2.3.1) change how Segwit transactions are handled and correct this.
Unfortunately, some third-party tools like Electrum or PSBT-based tools like BTCPay Server and Wasabi Wallet do not allow Trezor to obtain the previous transaction in case of Segwit inputs, which is why Trezor will not be able to sign transactions using these tools until they are updated to work correctly. We are cooperating with these parties to fix the problem as we speak.
Another option: don't update the Trezor firmware if you still want to use it with the previous version of wasabi or electrum wallet.


.....Zellix.com.....
.
▄████████████████████
███████████████▓█████████
████████████▓███████████
▀█████████▓████████████▀
░░░░░░░░░▄████████████▀
░░░░░░░▄████████████▀
░░░░░▄████████████▀
░░░▄████████████▀
▄████████████▓████████
████████████▓████████████
██████████▓██████████████
█████▓██████████████▀

.....Buy on Amazon with Crypto.....
▄▄▄▄▄
▀▀███
░░▀███
░░░██████████████████████
░░░██████████████████████
░░░█████████████████████
░░░░████████████████████
░░░░███████████████████
░░░░▀█████████████████▀
░░░░░░▄▄▄░░░░░░░░▄▄▄
░░░░░█████ ░░░░░█████
░░░░░▀███▀░░░░░░▀███▀

.....Sign Up Now.....
joniboini
Legendary
*
Offline Offline

Activity: 2366
Merit: 1806



View Profile WWW
June 16, 2020, 06:26:44 AM
 #3

Basically the latest patch has broken any third-party apps compatibility, not exclusive to Wasabi or Electrum. As discussed previously on a thread such as https://bitcointalk.org/index.php?topic=5253425.0. There's a high chance even if you use other third-party wallet apps, it won't work.

▄▄███████████████████▄▄
▄███████████████████████▄
████████▀░░░░░░░▀████████
███████░░░░░░░░░░░███████
███████░░░░░░░░░░░███████
██████▀░░░░░░░░░░░▀██████
██████▄░░░░░▄███▄░▄██████
██████████▀▀█████████████
████▀▄██▀░░░░▀▀▀░▀██▄▀███
███░░▀░░░░░░░░░░░░░▀░░███
████▄▄░░░░▄███▄░░░░▄▄████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 CHIPS.GG 
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
███▀░▄░▀▀▀▀▀░▄░▀███
▄███
░▄▀░░░░░░░░░▀▄░███▄
▄███░▄░░░▄█████▄░░░▄░███▄
███░▄▀░░░███████░░░▀▄░███
███░█░░░▀▀▀▀▀░░░▀░░░█░███
███░▀▄░▄▀░▄██▄▄░▀▄░▄▀░██
▀███
░▀░▀▄██▀░▀██▄▀░▀░██▀
▀███
░▀▄░░░░░░░░░▄▀░██▀
▀███▄
░▀░▄▄▄▄▄░▀░▄███▀
▀█
███▄▄▄▄▄▄▄████▀
█████████████████████████
▄▄███████▄▄
███
████████████▄
▄█▀▀▀▄
█████████▄▀▀▀█▄
▄██████▀▄▄▄▄▄▀██████▄
▄█████████████▄████████▄
████████▄███████▄████████
█████▄█████████▄██████
██▄▄▀▀▀▀█████▀▀▀▀▄▄██
▀█████████▀▀███████████▀
▀███████████████████▀
██████████████████
▀████▄███▄▄
████▀
████████████████████████
3000+
UNIQUE
GAMES
|
12+
CURRENCIES
ACCEPTED
|
VIP
REWARD
PROGRAM
 
 
  Play Now  
Coin-Keeper
Hero Member
*****
Offline Offline

Activity: 762
Merit: 606



View Profile
June 16, 2020, 03:31:44 PM
 #4

Trezors were updated to protect users employing SEGWIT transactions.  Trezor users on legacy BTC were never at risk because the network design protected against this vulnerability already.  SEGWIT made the decision, for speed, to do it differently.  I feel that now this vulnerability is out in the public maybe the process might be up for consideration of change.  Actually, I still hang on legacy because for me speed is not an issue.

BTC: 1PYSBbuKM3kW19xe9TXJQfq64rPhd8XorF
Staked and Verified: https://bitcointalk.org/index.php?topic=996318.msg17102755#msg17102755
hugeblack
Legendary
*
Offline Offline

Activity: 2688
Merit: 3983



View Profile WWW
June 17, 2020, 04:28:15 PM
Last edit: June 18, 2020, 08:04:43 AM by hugeblack
 #5

The last report of the vulnerability is not that dangerous, which could enable users to lose their money, so why did they force others to update the new version 2.3.1?
I think they should contact these wallets before they release the new Trezor firmware since they have had about 3 months.
It is also related to SEGWIT transactions, and does not necessarily mean that it will cause money loss, am I the only one who felt that correcting this vulnerability was not correct?


█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!