• About us
  • Advertise With Us
  • Become a Contributor
  • Guest Posting Service
  • Privacy Policy
  • Submit Press Release
  • Terms & Conditions
  • Contact
Cryptowall Street News
  • Home
  • Trending Coins
    • Cardano
    • Ethereum
    • Coinbase
    • Polkadot
    • Metaverse
    • BNB Chain
    • DeFi
    • Polkadot
    • Solana
  • Market
    • Bitcoin
    • Blockchain
    • Analysis
    • Guide
  • Top List
    • Top 10 cryptocurrencies
    • Top 50 Cryptocurrency
    • Top 100 Cryptocurrencies
    • Top 200 Cryptocurrency
    • Top 250 Cryptocurrencies
  • Binance
  • Coinbase
  • Crypto
    • Crypto Exchange
  • Finance
  • Litecoin
  • Ripple
  • Tether
No Result
View All Result
  • Home
  • Trending Coins
    • Cardano
    • Ethereum
    • Coinbase
    • Polkadot
    • Metaverse
    • BNB Chain
    • DeFi
    • Polkadot
    • Solana
  • Market
    • Bitcoin
    • Blockchain
    • Analysis
    • Guide
  • Top List
    • Top 10 cryptocurrencies
    • Top 50 Cryptocurrency
    • Top 100 Cryptocurrencies
    • Top 200 Cryptocurrency
    • Top 250 Cryptocurrencies
  • Binance
  • Coinbase
  • Crypto
    • Crypto Exchange
  • Finance
  • Litecoin
  • Ripple
  • Tether
No Result
View All Result
Latest News and Updates on Cryptocurrency
No Result
View All Result

How a Trezor Wallet Passphrase Taking a Lifetime to Brute Force Was Cracked by KeychainX Experts in 24 Hours

by
August 16, 2022
in Uncategorized
0 0
0
How a Trezor Wallet Passphrase Taking a Lifetime to Brute Force Was Cracked by KeychainX Experts in 24 Hours
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

Recovering a Trezor Wallet Passphrase

A TREZOR hardware wallet is a security device that protects the user from key loggers and phishing e-mail, keeping the user’s Bitcoin and crypto safe. Various hacking groups could open the device by mitigating side-channel attacks; however, the method was only possible because ‘a passphrase was not used’. When making a transaction, the user only enters a PIN and therefore protects the private key of the Bitcoin. The only backup is a 12/24-word mnemonic that determines which addresses are stored on the device.

The KeyChainX team split the job into two phrases (or three). But before the team could start, the client wanted to meet face-to-face. As travelling to South America was out of the question as we had a security presentation scheduled in Europe, the client agreed to a Skype “interview”. After 2 hours, the team convinced him that the team would not run away with his funds.

How Did the Team Crack It Open and Brute Force It?

The first part is data sourcing. First, the team gathered information about the possible hints to the passphrase, as a six characters passphrase would take forever to brute force with conventional tools. For example, a GITHUB repo by the user gurnec has a tool called Btcrecover that brute forces a couple of hundred passwords per second on average. For example, to break a 5-character password would take two days; if you add capital letters and numbers six months.

The client’s password consisted of more than 5-characters with both upper- and lower-case characters, possibly numbers and a unique character, which could approximately take 2+ years to brute force with the tool; that is, if the main wallet was the first created on the TREZOR. This was not the case. Instead, the “fake” wallet was created; first, there were transactions, and the genuine wallet was created later. Then, the team was forced to search for multiple wallet addresses and change addresses, which multiplied the time required to break the encryption.

Since this was not the first time the team had received a request to open a TREZOR, the team decided to build a custom-made tool that uses GPUs about a year ago. The custom tool speed is 240,000 passwords per second, an increase by 1000x compared to the gurnec GitHub source.

Customizing Mask Attack

The client gave the KeyChainX team 5 wallet addresses he had used in the past, a list of hints, and the 24-word mnemonic. First, the team had to determine if the 24 words were valid and if the mnemonic was valid.

Next, they had to choose which derivation path to search for; a TREZOR can use both LEGACY and SEGWIT addresses, and their specifications can easily be distinguished by looking at the first character of the address. LEGACY starts with one and SEGWIT with 3. They also use different derivation paths depending on the BIP version, so the team had to specify which wallet type and derivation path to use. Finally, SEGWIT uses m/49’/0’/0’/0 and LEGACY has several options. Finally, TREZOR fired up the custom tool with 8 x 1080Ti Founders Edition GPU cards (they cost up to 1000USD each depending on specification and model).

At first, the team searched an ample space of characters and words, but the mask and algorithm took approximately two months too long. The team had to change tactics and look at the TREZOR owner’s hints and find a pattern. The pattern used small/capital characters as the first password character. Then several lower-case characters, and then limited combinations of numbers (birth dates, months, pin codes to safe etc.). Two unique characters were also used, so the team had to add that into account. The mask was modified again, and BOOM, the team found the password within 24 hours after the “interview”.

A quick message on WeChat, asking the client for their BTC wallet (the team advised him not to use the same TREZOR again). The team transferred the client’s funds to them within the hour.

Crypto Wallets Recovery Experts

KeychainX has relocated in 2021 from its birthplace in the U.S., to Zug, Switzerland – a part of the world known in the blockchain community as Crypto Valley due to its concentration of relevant companies. Robert Rhodin, the CEO of the company, is naturally one of the leading experts in the field of crypto wallet recovery.

source

  • Trending
  • Comments
  • Latest
Beldex and Geometry Labs enter privacy-enhancing partnership

Beldex and Geometry Labs enter privacy-enhancing partnership

September 13, 2022
Here's When the Ethereum Proof-of-Work Fork Will Take Place

Here’s When the Ethereum Proof-of-Work Fork Will Take Place

September 13, 2022
Horizen Labs' ApeCoin staking hype sets $APE on a bullish trajectory

Horizen Labs’ ApeCoin staking hype sets $APE on a bullish trajectory

September 13, 2022
Bitcoin breaks to $20K as bulls target higher mothly close

Bitcoin breaks to $20K as bulls target higher mothly close

October 9, 2022
Only1 review: redefining social media experience using NFTs

Only1 review: redefining social media experience using NFTs

0
Et voici EIP-1559 !

Et voici EIP-1559 !

0
Crypto.com is now registered as a virtual asset service provider in the Cayman Islands

Crypto.com is now registered as a virtual asset service provider in the Cayman Islands

0
Crypto has provided Ukraine a way to ‘fight back’, digital transformation minister says

Crypto has provided Ukraine a way to ‘fight back’, digital transformation minister says

0
Metaverse Tokens Outperform Top Crypto Assets in 2023 With Decentraland's MANA Leading the Pack – Metaverse Bitcoin News

Metaverse Tokens Outperform Top Crypto Assets in 2023 With Decentraland’s MANA Leading the Pack – Metaverse Bitcoin News

February 2, 2023
82% of Millionaires Ask About Putting Crypto in Their Portfolios, Survey Shows – Featured Bitcoin News

82% of Millionaires Ask About Putting Crypto in Their Portfolios, Survey Shows – Featured Bitcoin News

February 1, 2023
JPMorgan CEO Jamie Dimon Calls Bitcoin 'Hyped-up Fraud' — Expects Satoshi Nakamoto to Increase BTC Supply Cap – Featured Bitcoin News

JPMorgan CEO Jamie Dimon Calls Bitcoin ‘Hyped-up Fraud’ — Expects Satoshi Nakamoto to Increase BTC Supply Cap – Featured Bitcoin News

January 31, 2023
Nothing Outlaws Crypto in India if Legal Procedures Are Followed, Says Government Official – Regulation Bitcoin News

Nothing Outlaws Crypto in India if Legal Procedures Are Followed, Says Government Official – Regulation Bitcoin News

January 30, 2023

POPULAR NEWS

    Recommended

    Metaverse Tokens Outperform Top Crypto Assets in 2023 With Decentraland's MANA Leading the Pack – Metaverse Bitcoin News

    Metaverse Tokens Outperform Top Crypto Assets in 2023 With Decentraland’s MANA Leading the Pack – Metaverse Bitcoin News

    February 2, 2023
    82% of Millionaires Ask About Putting Crypto in Their Portfolios, Survey Shows – Featured Bitcoin News

    82% of Millionaires Ask About Putting Crypto in Their Portfolios, Survey Shows – Featured Bitcoin News

    February 1, 2023
    JPMorgan CEO Jamie Dimon Calls Bitcoin 'Hyped-up Fraud' — Expects Satoshi Nakamoto to Increase BTC Supply Cap – Featured Bitcoin News

    JPMorgan CEO Jamie Dimon Calls Bitcoin ‘Hyped-up Fraud’ — Expects Satoshi Nakamoto to Increase BTC Supply Cap – Featured Bitcoin News

    January 31, 2023
    Nothing Outlaws Crypto in India if Legal Procedures Are Followed, Says Government Official – Regulation Bitcoin News

    Nothing Outlaws Crypto in India if Legal Procedures Are Followed, Says Government Official – Regulation Bitcoin News

    January 30, 2023

    About Us

    Get the latest news on Cryptocurrency and stay up-to-date ... Cryptocurrency prices today

    Categories

    • Analysis
    • Binance
    • Bitcoin
    • Blockchain
    • BNB Chain
    • Cardano
    • Coinbase
    • Crypto
    • DeFi
    • Ethereum
    • Finance
    • Guide
    • Market
    • Metaverse
    • Polkadot
    • Solana
    • Tether

    Tags

    BNB Chain Business Wire Pricing Cardano Cardano Crypto Crypto Cryptocurrency News Crypto Guest Posting Crypto News Crypto news distribution network Crypto news platform Crypto news site Crypto World DeFi Crypto Ethereum Ethereum Crypto Ethereum Digital Marketing agency Ethereum Marketing Agency Ethereum Marketing Experts Ethereum Online Marketing Agency Latest Crypto News Marketwired Pricing Metaverse Polkadot Polkadot Digital Marketing firm Polkadot Marketing Experts PRNewswire Cost PRNewswire Pricing PRWeb Pricing Solana Solana Crypto Solana Digital Marketing Specialists Solana Marketing Experts3 Solana Online Marketing Agency Today Crypto Update Top Cryptocurrency News video news release video press release video press release service
    • About us
    • Advertise With Us
    • Become a Contributor
    • Contact
    • Guest Posting Service
    • Home 4
    • List Of Top All Cryptocurrencies In The World (2022 Updated)
    • Privacy Policy
    • Submit Press Release
    • Terms & Conditions
    • Top 10 cryptocurrencies in the world | Crypto Prices Today LIVE
    • Top 100 Cryptocurrencies (Real-Time Prices) Market Cap
    • Top 200 Cryptocurrency List Price – Charts
    • Top 50 Cryptocurrency Prices – Coin Market Cap and Price Charts

    © 2022 cryptowallstreetnews.

    No Result
    View All Result
    • Home
    • Trending Coins
      • Cardano
      • Ethereum
      • Coinbase
      • Polkadot
      • Metaverse
      • BNB Chain
      • DeFi
      • Polkadot
      • Solana
    • Market
      • Bitcoin
      • Blockchain
      • Analysis
      • Guide
    • Top List
      • Top 10 cryptocurrencies
      • Top 50 Cryptocurrency
      • Top 100 Cryptocurrencies
      • Top 200 Cryptocurrency
      • Top 250 Cryptocurrencies
    • Binance
    • Coinbase
    • Crypto
      • Crypto Exchange
    • Finance
    • Litecoin
    • Ripple
    • Tether

    © 2022 cryptowallstreetnews.

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In
    • bitcoinBitcoin(BTC)$23,796.003.44%
    • ethereumEthereum(ETH)$1,669.226.03%
    • USDEXUSDEX(USDEX)$1.08-0.31%
    • tetherTether(USDT)$1.000.10%
    • binancecoinBNB(BNB)$330.377.55%
    • usd-coinUSD Coin(USDC)$1.000.12%
    • rippleXRP(XRP)$0.4156383.30%
    • Binance USDBinance USD(BUSD)$1.000.11%
    • cardanoCardano(ADA)$0.4016655.08%
    • dogecoinDogecoin(DOGE)$0.0938211.86%