Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Can't this be mitigated by resetting the device when you first get it?

No, he demonstrates a device going through setup and "generating" a predetermined seed. It's not the easier "your wallet has already been set up for you" attack.



To be precise, he overwrites the entropy source with zeroes, so that all words (except the last one) of the seed are "abandon". With a non-zero entropy source, you could generate random looking but deterministic seeds.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: