Bitcoin Theft Risk Found in Popular Wallet Chips

  • Ultramining.com
  • 16 April, 2025 17:35
Bitcoin Theft Risk Found in Popular Wallet Chips

A serious security issue has been discovered in the ESP32 microcontroller, widely used in both crypto wallets and internet-connected devices. Researchers from Crypto Deep Tech warned that the vulnerability allows persistent malware infections through firmware updates.

The flaw has been cataloged as CVE-2025-27840 in the U.S. National Vulnerability Database. It enables attackers to remotely compromise devices and exploit them for future access without physical interference.

Hardware Wallets and Weak PRNG Raise Alarms

The ESP32 chip is used in well-known hardware wallets, including the Blockstream Jade model. Its random number generator (PRNG) produces insufficient entropy, creating a vulnerability in transaction signature generation.

This opens the door for brute-force attacks, allowing hackers to guess key pairs. In some cases, malicious actors could remotely authorize crypto transfers and fake transaction signatures.

Exploits Proven on a Live Wallet Holding 10 BTC

Crypto Deep Tech tested multiple exploit vectors using a hardware wallet containing 10 BTC. Researchers successfully reproduced several attacks that confirmed the real threat posed by the flaw.

They demonstrated how to:

  • create invalid private keys using PRNG weaknesses;
  • forge Bitcoin signatures with manipulated hashing;
  • extract private keys using ECC-based group attacks;
  • generate fake public keys by exploiting elliptic curve ambiguity.

Security Measures Must Be Strengthened

Experts emphasized the urgent need for firmware updates and secure hardware design. As ESP32 remains common in crypto devices, manufacturers must act quickly.

They recommend adopting stronger cryptographic algorithms and reviewing chip-level security standards. Without proper safeguards, users’ digital assets are at high risk.

Share to: