Def Con 25 Demo Claiming to Break Bitcoin Hardware Wallets Draws Attention

Def Con 25 Demo Claiming to Break Bitcoin Hardware Wallets Draws Attention

N
News Editor 01
2026-07-09 19:13:13
A Def Con 25 presentation by Cryptotronix claims to demonstrate attacks against bitcoin hardware wallets using side-channel techniques on chips used by Trezor and KeepKey, reigniting debate over physical device security.
Def Con 25Bitcoin Hardware WalletsSide-Channel AttacksTrezorKeepKey

A presentation scheduled for Def Con 25 in Las Vegas has drawn attention across the crypto community after claiming it will show how to break bitcoin hardware wallets. According to the event listing, the roughly 20-minute session will be led by Cryptotronix researchers Josh Datko and Chris Quartier, who plan to discuss methods involving fault injection, timing analysis, and power analysis.

Focus on side-channel techniques and wallet hardware

In the session summary, Cryptotronix says it will use the open-source hardware tool Chip Whisperer to explain side-channel attack techniques. The researchers also say they will apply those methods to the STM32F205 microcontroller, the chip used in Trezor and KeepKey hardware wallets. The team claims to have identified a timing attack vulnerability and says it will conclude with software and hardware recommendations aimed at improving wallet security.

The topic has resonated because hardware wallets are widely regarded as a key defense against malware and other software-based threats targeting private keys. But while users often focus on digital attack vectors, physical and side-channel attacks remain an important area of concern for security researchers evaluating device resilience.

A 2015 case showed private-key extraction with a $70 oscilloscope

The report points to earlier research as background for the claim. In 2015, developer Jochen Hoenicke demonstrated that a Trezor private key could be extracted using an oscilloscope costing about $70. An oscilloscope is an electronic testing instrument used to observe signals inside a device, and the case suggested that some side-channel attacks do not necessarily require expensive lab-grade equipment.

Hoenicke said at the time that side-channel attacks were not as difficult as many people assumed. In his view, a basic power analysis attack could be carried out with a simple oscilloscope, basic soldering skills, and a deep understanding of the code running on the device. That finding added to the broader debate over how secure hardware wallets are against hands-on attackers.

Patched issues, but questions remain about additional attack paths

The article notes that Trezor patched the vulnerabilities disclosed in 2015, and that Hoenicke had been in contact with manufacturer Satoshi Labs during his investigation. Even so, Cryptotronix argues that additional side-channel attack opportunities may still exist, despite earlier fixes, and suggests that further scrutiny of hardware wallet design is warranted.

Reaction in the bitcoin community has been mixed. Some forum users remain skeptical and say they want to see whether the live demonstration can actually prove the claims. Others argue that any serious findings should first be shared with manufacturers through responsible disclosure before being presented publicly. Another view is that research of this kind could ultimately benefit the market by pushing wallet makers to improve the physical security of future devices.

More broadly, the Def Con 25 session highlights a familiar reality in crypto security: hardware wallets can significantly reduce exposure to software-based key theft, but they are not automatically immune to hardware-level attacks. As tools, methods, and open-source research continue to evolve, manufacturers may face growing pressure to strengthen chips, firmware, and overall device architecture against more sophisticated physical threats.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.