Close Menu
  • Home
  • Trending News
    • Companies
    • Markets
    • People
    • Technology
  • Learn
  • Policy
  • Research
  • Finance
  • All Posts
What's Hot

Entertainment Mogul David Geffen Files Counterclaim Against Justin Sun Regarding Contested Multimillion-Dollar Sculpture

Apr. 18, 2025

Yemenis Embrace DeFi as Sanctions Sever Traditional Banking Access: Report

Apr. 18, 2025

Bitcoin Remains Resilient Around $84.6K—Panama and ETFs Boost Bullish Sentiment

Apr. 17, 2025
Facebook X (Twitter) Instagram
Thursday, July 3
Pioneer WebPioneer Web
Facebook X (Twitter) Instagram YouTube
  • Home
  • Trending News
    • Companies
    • Markets
    • People
    • Technology
  • Learn
  • Policy
  • Research
  • Finance
  • All Posts
Latest From Tech Buy Now
Pioneer WebPioneer Web
Home » New Vulnerability in ESP32 Chip Allows Hackers to Extract Bitcoin Keys from Widely Used Wallets
Research

New Vulnerability in ESP32 Chip Allows Hackers to Extract Bitcoin Keys from Widely Used Wallets

By adminApr. 16, 2025No Comments3 Mins Read
New Vulnerability in ESP32 Chip Allows Hackers to Extract Bitcoin Keys from Widely Used Wallets
New Vulnerability in ESP32 Chip Allows Hackers to Extract Bitcoin Keys from Widely Used Wallets
Share
Facebook Twitter LinkedIn Pinterest Email

New ESP32 Chip Flaw Lets Hackers Steal Bitcoin Keys from Popular Wallets

A dangerous security flaw has been discovered in the Chinese-manufactured ESP32 chip, a microcontroller embedded in billions of IoT devices, including several popular crypto wallets. Cybersecurity firm Crypto Deep Tech found the vulnerability, which was officially cataloged as CVE-2025-27840 in March. This bug allows attackers to forge cryptographic signatures and steal private keys without users’ knowledge.

ESP32 Chip Vulnerability Targets Core Cryptographic Operations

Researchers revealed that the flaw stems from multiple weaknesses in the ESP32 architecture, including a weak pseudo-random number generator (PRNG) that makes cryptographic keys dangerously predictable and a failure to reject invalid private keys (≤ 0).

Cryptographic flaws in ESP32 chip/ Source: Crypto Deep Tech These design lapses make the chip vulnerable in crypto use cases. “The ESP32 acts as a gateway to sensitive networks and cryptographic credentials,” the report warns. Wallets like Blockstream Jade face high risks. Attackers can also exploit the chip’s Bluetooth and Wi-Fi capabilities to spoof MAC addresses, manipulate memory, and inject malicious code to steal Bitcoin keys. In one simulated attack, researchers extracted the private key to a wallet containing 10 BTC without alerting the owners. One of the exploit’s most alarming aspects is the electrum_sig_hash function, which is used in Electrum-based wallets. The function’s flawed logic allows attackers to exploit non-standard message formatting and generate forged ECDSA signatures that validate legitimate Bitcoin transactions. Due to the ESP32’s support for message prefixing, Bitcoin addresses can be encoded before applying double SHA256 hashing, bypassing typical safeguards and allowing forgery.

Wider Implications Beyond Crypto Wallets

ESP32 chips are embedded in millions of smart home devices, routers, and automation systems. Experts warn that the bug could lead to massive state-level cyberattacks and supply chain compromises. “This is not just about Bitcoin. It’s about the security of the internet-connected world,” the researchers stated. Although commercial wallets like Ledger and Trezor incorporate enhanced security, they are not invincible. A March 13 security audit by Ledger found that Trezor’s Safe 3 and Safe 5 models are vulnerable to supply chain attacks due to their reliance on microcontrollers for key verification and cryptographic operations. Despite including secure elements, operations such as transaction signing are still carried out on potentially vulnerable microcontrollers.

Ledger CTO Charles Guillemet emphasized that although these wallets include EAL6+ certified Secure Elements, attackers could still target the microcontroller layer in supply chain attacks.

Growing Threat of Hardware Vulnerabilities

The ESP32 flaw is not an isolated case. In March 2024, researchers uncovered a serious side-channel vulnerability in Apple’s M-series chips that allowed attackers to extract encryption keys via microarchitectural design flaws, rendering them unpatchable by software updates. Even browser-based wallets aren’t safe. On April 14, a developer filed a lawsuit against Phantom Technologies, claiming the popular Solana-based wallet left private keys exposed in unencrypted browser memory. The breach resulted in over $500,000 in crypto stolen from three wallets.

Related Posts

Entertainment Mogul David Geffen Files Counterclaim Against Justin Sun Regarding Contested Multimillion-Dollar Sculpture

Apr. 18, 2025

Yemenis Embrace DeFi as Sanctions Sever Traditional Banking Access: Report

Apr. 18, 2025

Bitcoin Remains Resilient Around $84.6K—Panama and ETFs Boost Bullish Sentiment

Apr. 17, 2025

Trump’s Tariffs Pose a Risk to U.S. Bitcoin Mining with Potential Import Duties of Up to 36% on Asian Equipment

Apr. 17, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Entertainment Mogul David Geffen Files Counterclaim Against Justin Sun Regarding Contested Multimillion-Dollar Sculpture

Apr. 18, 2025

Yemenis Embrace DeFi as Sanctions Sever Traditional Banking Access: Report

Apr. 18, 2025

Bitcoin Remains Resilient Around $84.6K—Panama and ETFs Boost Bullish Sentiment

Apr. 17, 2025

Trump’s Tariffs Pose a Risk to U.S. Bitcoin Mining with Potential Import Duties of Up to 36% on Asian Equipment

Apr. 17, 2025

Fraud Scandal: Richard Kim of Zero Edge Arrested for Allegedly Misappropriating $7 Million in Investor Funds for Gambling Activities

Apr. 17, 2025

SEC Action Prohibits UAE Crypto Market Maker CLS Global for 98% Wash Trading, Imposing a $425K Fine

Apr. 17, 2025

Cardano Price Analysis: What is the Future Direction of ADA?

Apr. 17, 2025

Russian Finance Ministry Official Advocates for the Development of Domestic Stablecoins

Apr. 17, 2025
Website Introduction
Website Introduction

Pioneer Web is your premier destination to explore the world of cryptocurrency. We offer comprehensive coverage and in-depth analysis, encompassing the latest developments in Bitcoin, Ethereum, and other digital assets. From market trends to technological innovations, we partner with industry leaders to present cutting-edge insights, empowering you to navigate future developments with confidence.

Facebook X (Twitter) Instagram Pinterest YouTube
NAVIGATION
  • Trending News
  • Technology
  • Policy
  • Research
  • Finance
Industry Trends
© 2025 Pioneer Web All rights reserved.

Type above and press Enter to search. Press Esc to cancel.