Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Dow, S&P 500, Nasdaq mixed as investors weigh tariff talks

    July 1, 2025

    AfCFTA SEcretary General Calls For Renewed Transformative Partnership With The US To Accelerate Production And Trade

    July 1, 2025

    XRP ETF buzz boosts XYZVerse presale momentum as investors eye a potential breakout

    July 1, 2025
    Facebook X (Twitter) Instagram
    Cryptify Now
    • Home
    • Features
      • Typography
      • Contact
      • View All On Demos
    • Typography
    • Buy Now
    X (Twitter) Instagram YouTube LinkedIn
    Cryptify Now
    You are at:Home » Crypto hardware wallets using ESP32 chip at risk of private key theft: report
    Crypto

    Crypto hardware wallets using ESP32 chip at risk of private key theft: report

    James WilsonBy James WilsonApril 16, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Researchers have warned of a new vulnerability affecting certain crypto hardware wallets that allows attackers to privately sign unauthorized Bitcoin transactions and steal private keys.

    Cryptocurrency wallets using the Chinese-made ESP32 chip, a widely used microcontroller designed for embedded systems and connected devices, are at risk, according to cybersecurity firm Crypto Deep Tech, which flagged a major vulnerability in a recent report. 

    Often deployed in security-critical environments and used in hardware wallets like Blockstream Jade and open-source projects such as Bowser and Colibri, these chips often act as gateways to sensitive networks or store cryptographic credentials, making the vulnerability especially severe.

    According to researchers, attackers can exploit the chip’s Bluetooth and Wi-Fi connectivity to inject malicious module updates, gain low-level access, and extract sensitive wallet data such as private keys.

    The chip suffers from multiple vulnerabilities, including a weak random number generator that makes Bitcoin private keys dangerously predictable, and broken validation checks that allow invalid or low-value keys to be used.

    Electrum-based wallets are especially vulnerable, as the chip’s flawed hashing logic allows attackers to exploit non-BIP-137 message formatting and generate forged ECDSA signatures that validate as real Bitcoin transactions. 

    What makes this vulnerability especially concerning for crypto users is its stealthy execution. In a real-world test case, Crypto Deep Tech researchers were able to exploit the vulnerability to bypass normal security checks, recover a private key, and gain access to a live Bitcoin wallet holding 10 BTC without alerting the user at any point.

    The risks aren’t limited to just cryptocurrency wallets. The vulnerability opens the door for large-scale supply chain attacks, state-level espionage, and coordinated theft campaigns targeting any network where ESP32-powered devices are in use.

    To mitigate the threat, researchers advised using trusted devices, keeping Bitcoin software up to date, and relying on secure cryptographic libraries to avoid risks like key theft and transaction forgery.

    Although considered a secure alternative to software wallets, which are often exploited, hardware wallet vulnerabilities remain a serious issue for cryptocurrency enthusiasts. 

    Last month, Ledger Donjon researchers found that wallet maker Trezor’s latest Safe models still rely on a general-purpose microcontroller that is vulnerable to physical attacks. 

    Despite having a certified secure element for PIN and secret storage, the STM32-based chip used in Trezor devices could reportedly be exploited through voltage glitching, an attack that can be carried out purely in software and is nearly impossible to detect.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleSouth Korean presidential candidate vows to deregulate crypto like Trump-era US
    Next Article Alchemy Pay secures Arizona MTL as ACH price jumps 47%, eyeing breakout above key resistance
    James Wilson

    Related Posts

    Dow, S&P 500, Nasdaq mixed as investors weigh tariff talks

    July 1, 2025

    XRP ETF buzz boosts XYZVerse presale momentum as investors eye a potential breakout

    July 1, 2025

    Wall Street’s Bitcoin proxy eyes $14b quarter, without selling a thing

    July 1, 2025
    Leave A Reply Cancel Reply

    Top Posts

    Remittix (RTX) hits $4m presale as XRP holders take notice

    February 4, 2025

    Here’s why OKB price spiked 20% today

    February 4, 2025

    iDEGEN price prediction: Is this the AI agent token to buy?

    February 4, 2025

    Gate.io to list CYBRO token on Dec 14 after $7M presale success

    February 4, 2025
    Don't Miss

    Dow, S&P 500, Nasdaq mixed as investors weigh tariff talks

    By James WilsonJuly 1, 2025

    The Dow Jones Industrial Average, S&P 500 and Nasdaq Composite opened mixed on Tuesday, July…

    AfCFTA SEcretary General Calls For Renewed Transformative Partnership With The US To Accelerate Production And Trade

    July 1, 2025

    XRP ETF buzz boosts XYZVerse presale momentum as investors eye a potential breakout

    July 1, 2025

    AfCFTA SEcretary General Calls For Renewed Transformative Partnership With The US To Accelerate Production And Trade

    July 1, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    About Us
    About Us

    CryptifyNow: Your daily source for the latest insights, news, and analysis in the ever-evolving world of cryptocurrency.

    X (Twitter) Instagram YouTube LinkedIn
    Our Picks

    Dow, S&P 500, Nasdaq mixed as investors weigh tariff talks

    July 1, 2025

    AfCFTA SEcretary General Calls For Renewed Transformative Partnership With The US To Accelerate Production And Trade

    July 1, 2025

    XRP ETF buzz boosts XYZVerse presale momentum as investors eye a potential breakout

    July 1, 2025
    Lithosphere News Releases

    Colle AI’s iOS App Launch Brings Multichain NFT Creation to Mobile

    February 4, 2025

    AGII Transforms Web3 Infrastructure with AI-Optimized Smart Contracts

    February 4, 2025

    Colle AI (COLLE) Allocates $250M for AI Tool Development and Liquidity Growth on Solana

    February 4, 2025
    Copyright © 2025

    Type above and press Enter to search. Press Esc to cancel.