HOME CATEGORIES WRITE AND EARN 🔍
CATEGORIES WRITE AND EARN MORE

CRYPTO NEWS

Your favorite crypto news blog

Kraken: Keepkey Crypto Hardware Wallet Has an Alarming Flaw

Crypto 2019/12/10 23:24 by davitbabayan
Keepkey crypto flaw

Crypto practitioners who depend on Keepkey hardware wallets to store their coins ought to take a pledge of not discussing it in public.


Kraken Warns Crypto Users

The warning appears on Kraken’s latest blog post wherein it discusses a serious flaw in all of the Keepkey hardware wallets. The US exchange’s security research wing claims that it has found a way to hack seeds from Keepkey wallets. In retrospective, a seed phrase is a string of random words that allows owners to recover their cryptocurrency wallets. That said, anybody with access to seeds could gain access to cryptocurrency funds stored on a wallet.

Kraken found that Keepkey devices have an issue related to their microcontrollers. The exchange noted that people with physical access to victims’ crypto wallets could use specialized hardware to read their encrypted seeds. For that, the attacker would also need to crack the wallets’ pin code through brute force.

The issue now resides in each one of the Keepkey wallets in circulation. The company cannot solve it until it decides to replace them all with patched devices.

“This,” wrote Kraken, “unfortunately means that it is difficult for the KeepKey team to do anything about this vulnerability without a hardware redesign.”

Not a New Problem

Keepkey rubbished Kraken’s findings based on its lack of relevance. The firm shared two articles discussing the same issue. One of them was penned by ShapeShift, which supports Keepkey as its premier wallet on its crypto-to-crypto exchange. The trading platform had written in June that Keepkey can protect clients’ funds from the most common attack vectors, such as viruses, malware, or remote hackers trying to steal private keys. Nevertheless, the firm is as helpless as any other wallet company when it comes to protecting clients’ devices from physical attacks.

“If somebody else has physical access to your device — as well as the time, skill, and tools necessary — they will always be able to command the device to do whatever they want, bypassing any digital lock that exists,” wrote ShapeShift. “Again, this is true of any hardware wallet.”

Keepkey rival, Ledger, had responded similarly to a malware issue affecting its Nano S wallets back in 2018. After DocDroid reported that attackers could game the Ledger software by replacing the copied receiver addresses with its own, the firm had responded by saying that the issue was universal. Excerpts:

Malware can always change what you see on your computer screen. The only solution is prevention and building a UX to make the user check on its device. The on-device verification feature has been added [six] month ago already.

Solution: Use Complex Passphrases

Charles Guillemet, the chief security officer at Ledger, demonstrated that hackers could guess Keepkey’s wallets’ passphrase in less than a minute by applying different combinations. Kraken reiterated the same evidence in its blog post, leading ShapeShift to write an eleven-step manual to fix the said problem.

Guillemet recommends using passphrases comprised of at least 32 digits made up of a unique combination of numbers, symbols, as well as upper and lower-case letters…With a sufficiently-long passphrase, if an attacker takes the data off your device, they’ll never be able to unlock it. Your PIN and your passphrase keep your funds — safe.

Overall, the issue reminded what doomsday economist Nouriel Roubini had complained about cryptocurrencies. He had noted that anybody with a gun can steal private keys of wallets holding multi-million dollars worth of bitcoin. More so, there was no way for the victim to get the stolen funds back since crypto transactions are irreversible.

By Q3 2019, the cryptocurrency industry lost about $4.4 billion to frauds and thefts, noted CipherTrace in its report. As of June, the amount was $1.1 billion.

What do you think of Kraken’s findings? Add your thoughts below!


Images via Shutterstock, Twitter @cryptokeepkey

The post Kraken: Keepkey Crypto Hardware Wallet Has an Alarming Flaw appeared first on Bitcoinist.com.

0 Like(s)



You should also read...

Crypto 10/12/19 16:23 by Joseph Young
Kraken Finds Way to Break Into Popular Hardware Crypto Wallet in 15 Minutes
A security research team at Kraken, a crypto exchange valued at $4 billion, has found a way to gain access to seeds from the widely-used KeepKey hardware wallet. To carry out the attack, the Kraken Se...
Read More
Bitcoin 11/06/20 19:09 by Guest Author
Bitcoin Wallets Come in All Sizes, Pick One That Fits the Best
As the global economy struggles to recover from the shock treatment delivered by the pandemic, cryptocurrencies seem to be strengthening their resolve to scale new heights. In the past few days, again...
Read More
Crypto 28/10/20 13:45 by Thomas Delahunty
The Most Secure Cryptocurrency Wallets for Different Users
Cryptocurrencies have the potential to disrupt traditional finance, by allowing people to retain full control over their assets at all times — without relying on centralized intermediaries like ...
Read More
Bitcoin 16/02/21 12:00 by Guest Author
The Best Bitcoin Wallets of 2021: A Comprehensive Review
The interest in Bitcoin is currently at an all-time high, thanks to the cryptocurrency breaking all its previous records by the end of 2020. With the crypto hovering close to the record $50000-mark, i...
Read More
Crypto 15/07/21 13:24 by NewsBTC
Bitop Exchange – Powerful Trading Platform for Cryptocurrency Traders
Cryptocurrency has been a disruptive tool revolutionizing gaming, banking, gambling, and our financial systems. There has been a tremendous interest in the cryptocurrency world in the past few years. ...
Read More