Ledger Labs
  • Tech
  • Security
    • Posts
    • Bug Bounty
    • Security Bulletins
    • Threat Model
  • Stories
manuel

Manuel San Pedro

3 posts •
Donjon

Follow-up on PIN verification against side-channel attack: KeepKey Hardware Wallet Under The Scope

18 May 2020

We mounted a 2-steps side-channel attack on the PIN verification function storage_isPinCorrect_impl of the KeepKey hardware wallet. If an attacker has a physical access to the device, the attack exposes the user PIN

Manuel San Pedro 15 min read
Donjon

OLED screen (minor) vulnerability

7 August 2019

On May 7, security researcher Christian Reitter contacted us through our Bounty program to inform us of a side-channel vulnerability which could potentially allow an attacker to spy on users of hardware wallets,

Manuel San Pedro 6 min read
Donjon

Breaking Trezor One with Side Channel Attacks

17 June 2019

A Side Channel Attack on PIN verification allows an attacker with a stolen Trezor One to retrieve the correct value of the PIN within a few minutes.

Charles Guillemet + 2 10 min read
Ledger Labs © 2022
Proudly published with Jekyll & GitHub Pages using Jasper2
About Twitter Donjon Twitter GitHub Donjon Github