{"id":10540,"date":"2022-07-07T08:22:11","date_gmt":"2022-07-07T08:22:11","guid":{"rendered":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/?post_type=session&#038;p=10540"},"modified":"2023-06-09T00:37:06","modified_gmt":"2023-06-09T00:37:06","slug":"keybleed-attacking-the-onekey-mini","status":"publish","type":"session","link":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/keybleed-attacking-the-onekey-mini\/","title":{"rendered":"KeyBleed: Attacking the OneKey Mini"},"content":{"rendered":"<p style=\"text-align: justify;\">It&#8217;s hard to figure out which cryptocurrency wallets are more secure than others. Often good advice is to choose one that utilizes a Secure Element (like Ledger, ColdCard, OneKey, etc) as opposed to ones without that have been widely demonstrated to be easily dumped through fault injection (Trezor, KeepKey, etc).<\/p>\n<p style=\"text-align: justify;\">This talk will discuss how the devils are in the details and how transfer of keys and sensitive data from the SE to the main microprocessor can sometimes introduce exploitable conditions that allow an even easier and more reliable attack. This talk will review some other prior attacks on cryptocurrency wallets, issues with code reuse, and the specific issue with the OneKey Mini that allows our company to recover the seed with 100% reliability in under 1 second that we&#8217;ll demonstrate live on-stage an exploit of a OneKey Mini where we extract and crack it&#8217;s seed to recover any funds stored on it.<\/p>\n","protected":false},"template":"","class_list":["post-10540","session","type-session","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>KeyBleed: Attacking the OneKey Mini - HITBSecConf2023 - Phuket<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/keybleed-attacking-the-onekey-mini\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"KeyBleed: Attacking the OneKey Mini - HITBSecConf2023 - Phuket\" \/>\n<meta property=\"og:description\" content=\"It&#8217;s hard to figure out which cryptocurrency wallets are more secure than others. Often good advice is to choose one that utilizes a Secure Element (like Ledger, ColdCard, OneKey, etc) as opposed to ones without that have been widely demonstrated to be easily dumped through fault injection (Trezor, KeepKey, etc). This talk will discuss how [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/keybleed-attacking-the-onekey-mini\/\" \/>\n<meta property=\"og:site_name\" content=\"HITBSecConf2023 - Phuket\" \/>\n<meta property=\"article:modified_time\" content=\"2023-06-09T00:37:06+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/keybleed-attacking-the-onekey-mini\/\",\"url\":\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/keybleed-attacking-the-onekey-mini\/\",\"name\":\"KeyBleed: Attacking the OneKey Mini - HITBSecConf2023 - Phuket\",\"isPartOf\":{\"@id\":\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/#website\"},\"datePublished\":\"2022-07-07T08:22:11+00:00\",\"dateModified\":\"2023-06-09T00:37:06+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/keybleed-attacking-the-onekey-mini\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/keybleed-attacking-the-onekey-mini\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/keybleed-attacking-the-onekey-mini\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Session\",\"item\":\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"KeyBleed: Attacking the OneKey Mini\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/#website\",\"url\":\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/\",\"name\":\"HITBSecConf2023 - Phuket\",\"description\":\"August 22 - 26 @ InterContinental\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"KeyBleed: Attacking the OneKey Mini - HITBSecConf2023 - Phuket","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/keybleed-attacking-the-onekey-mini\/","og_locale":"en_US","og_type":"article","og_title":"KeyBleed: Attacking the OneKey Mini - HITBSecConf2023 - Phuket","og_description":"It&#8217;s hard to figure out which cryptocurrency wallets are more secure than others. Often good advice is to choose one that utilizes a Secure Element (like Ledger, ColdCard, OneKey, etc) as opposed to ones without that have been widely demonstrated to be easily dumped through fault injection (Trezor, KeepKey, etc). This talk will discuss how [&hellip;]","og_url":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/keybleed-attacking-the-onekey-mini\/","og_site_name":"HITBSecConf2023 - Phuket","article_modified_time":"2023-06-09T00:37:06+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/keybleed-attacking-the-onekey-mini\/","url":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/keybleed-attacking-the-onekey-mini\/","name":"KeyBleed: Attacking the OneKey Mini - HITBSecConf2023 - Phuket","isPartOf":{"@id":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/#website"},"datePublished":"2022-07-07T08:22:11+00:00","dateModified":"2023-06-09T00:37:06+00:00","breadcrumb":{"@id":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/keybleed-attacking-the-onekey-mini\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/keybleed-attacking-the-onekey-mini\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/keybleed-attacking-the-onekey-mini\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/"},{"@type":"ListItem","position":2,"name":"Session","item":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/"},{"@type":"ListItem","position":3,"name":"KeyBleed: Attacking the OneKey Mini"}]},{"@type":"WebSite","@id":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/#website","url":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/","name":"HITBSecConf2023 - Phuket","description":"August 22 - 26 @ InterContinental","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/wp-json\/wp\/v2\/session\/10540"}],"collection":[{"href":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/wp-json\/wp\/v2\/session"}],"about":[{"href":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/wp-json\/wp\/v2\/types\/session"}],"wp:attachment":[{"href":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/wp-json\/wp\/v2\/media?parent=10540"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}