Security firm Unciphered hacked into popular hardware wallet OneKey

Quick Take

  • Unciphered successfully hacked a popular hardware crypto wallet manufactured by OneKey.
  • OneKey acknowledged the vulnerability, updated the security patch and paid Unciphered a bounty for the responsible disclosure.

Cybersecurity startup Unciphered demonstrated a hack of a notable hardware crypto wallet manufactured by OneKey, a Hong Kong-based firm that raised $20 million last year.

The firm demonstrated in a video that it exploited the lack of encryption between the hardware wallet's CPU and the secure element by using a field programmable gate array that was able to intercept communications between the processor and the secure element, which holds the device's seed phrase.

“The FPGA is a high speed processor also known as a field programmable gate array, allowing us to iterate through different algorithms, bypass the wallet’s security and extract the mnemonics,” Unciphered said.

OneKey acknowledged the vulnerability in a statement and said it had updated the security patch.

THE SCOOP

Keep up with the latest news, trends, charts and views on crypto and DeFi with a new biweekly newsletter from The Block's Frank Chaparro

By signing-up you agree to our Terms of Service and Privacy Policy
By signing-up you agree to our Terms of Service and Privacy Policy

"No one was affected," the company said, emphasizing that a potential attack, as demonstrated by Unciphered, cannot be exploited remotely and would require both the crypto wallet of a user and specialized FPGA equipment.

OneKey said it paid Unciphered a bounty for the disclosure.


© 2023 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

About Author

Vishal Chawla is The Block’s crypto ecosystems editor and has spent over six years covering tech protocols, cybersecurity, artificial intelligence and cloud computing. Vishal likes to delve deep into blockchain intricacies to ensure readers are well-informed about the continuously evolving crypto landscape. He is also a staunch advocate for rigorous security practices in the space. Before joining The Block, Vishal held positions at IDG ComputerWorld, CIO, and Crypto Briefing. He can be reached on Twitter at @vishal4c and via email at [email protected]

Editor

To contact the editors of this story:
Nathan Crooks at
[email protected]
Larry DiTore at
[email protected]