Table of Contents

A case study of Trezor One being hacked by Kraken Security Labs. So, who is Kraken Security Labs?

Kraken Security Labs is not a hacker group but a team that works on security research and system robustness testing.

In 2020, the Kraken Security Labs team published research stating that they could extract the Recovery Seed (24 words) from Trezor One.

This news shocked many and led to questions like,

"Is Hardware Wallet still secure?"

The short answer is:

It is still secure for general users.

But this case helps us better understand the "boundaries of security."

What Kraken Labs did is not the type of hacking people commonly fear.

When people hear the word "hacked," many envision a computer being remotely hacked, leading to money disappearing unknowingly. However, the Trezor One case is not like that at all. Kraken Labs did not attack via the internet but rather through what is called a Physical Attack, which requires direct access to the hardware.

What an attacker needs

  • A Trezor One device
  • Time
  • Specialized equipment
  • Expert-level hardware knowledge

In other words, the attacker must "steal the device first" before they can begin the attack.

The technique used attacks the "chip," not the software.

The internal structure of Trezor One uses a Microcontroller (MCU) chip, which is not a Secure Element. Kraken used a technique called "Voltage Glitching."

The concept is:

  • Briefly disrupt the electrical voltage in the chip.
  • This causes the security verification system to "malfunction."
  • Allowing data to be read from memory.

The result is that the "Recovery Seed can be extracted."

⚠️ Very important: This is not something just anyone can do. It requires specialized equipment, high precision, and a deep understanding of hardware.

Should general users be concerned?

Many friends are starting to feel uneasy because if the Seed can be extracted, does that mean their money is not safe?

The answer is yes, technically, but no, in the real lives of general users, because it relies on specific conditions, such as:

  • The device must be stolen.
  • Specialized equipment is needed.
  • Skills at the level of a Security Researcher are required.
  • It takes a lot of time and effort; it's not a plug-and-play money extraction.

Compared to other targets in the crypto world, attacking general users using this method is hardly worth the effort.

How Trezor responded

What's interesting is that the developer company, SatoshiLabs, did not try to suppress the news or deny this discovery. They honestly admitted that Trezor One indeed has hardware limitations and chose to focus on helping users understand the risks and prevention methods, while also developing new models with stronger security structures. One of the most frequently mentioned recommendations is setting a Passphrase. Even if an attacker extracts the Seed, they cannot access our funds without knowing the Passphrase.

What's interesting is that the developer company, SatoshiLabs, did not try to suppress the news or deny this discovery. They honestly admitted that Trezor One indeed has hardware limitations and chose to focus on helping users understand the risks and prevention methods, while also developing new models with stronger security structures. One of the most frequently mentioned recommendations is setting a Passphrase. Even if an attacker extracts the Seed, they cannot access our funds without knowing the Passphrase.

Lessons this case leaves for us

The Trezor One case does not mean that Hardware Wallets are unusable. Instead, it tells us that Hardware Wallets are tools, and every tool has its limits. The better we understand those limits, the more securely we can use them.

Leave a comment

Please note, comments need to be approved before they are published.

This site is protected by hCaptcha and the hCaptcha Privacy Policy and Terms of Service apply.