All

What are you looking for?

All
Projects
Results
Organizations

Quick search

  • Projects supported by TA ČR
  • Excellent projects
  • Projects with the highest public support
  • Current projects

Smart search

  • That is how I find a specific +word
  • That is how I leave the -word out of the results
  • “That is how I can find the whole phrase”

Large-Scale Security Analysis of Hardware Wallets

The result's identifiers

  • Result code in IS VaVaI

    <a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216224%3A14330%2F25%3A00141766" target="_blank" >RIV/00216224:14330/25:00141766 - isvavai.cz</a>

  • Result on the web

    <a href="http://dx.doi.org/10.1007/978-3-032-00633-2_21" target="_blank" >http://dx.doi.org/10.1007/978-3-032-00633-2_21</a>

  • DOI - Digital Object Identifier

    <a href="http://dx.doi.org/10.1007/978-3-032-00633-2_21" target="_blank" >10.1007/978-3-032-00633-2_21</a>

Alternative languages

  • Result language

    angličtina

  • Original language name

    Large-Scale Security Analysis of Hardware Wallets

  • Original language description

    Cryptocurrency hardware wallets (HWWs) are dedicated offline devices that securely store cryptographic keys and perform internal message signing to prevent key exposure. Signing typically requires physical user interaction – such as pressing a button or using a fingerprint sensor – which provides strong protection against compromised hosts. However, this physical requirement significantly hinders independent, automated testing on real devices, often forcing reliance on software emulators or vendor claims. We introduce a low-cost, fully automated, and reproducible testing platform to address this limitation. The platform replicates essential human interactions, including physical button presses and touchscreen inputs, incorporates Optical Character Recognition (OCR) for extracting screen content, and records precise timing metadata. These capabilities enable us to perform a comprehensive evaluation of HWWs. Using this automated platform, we collected a dataset containing 3.4 million wallet recovery phrases, 3.4 million Elliptic Curve Digital Signature Algorithm (ECDSA) signatures, and the corresponding timing measurements. Data acquisition was performed on 17 hardware wallet models from 11 different vendors, using firmware versions available in 2023 and in 2025 to enable a comparative analysis. The data examination revealed several details about internal implementation characteristics, yet no significant cryptographic weaknesses were identified. This outcome is particularly interesting given the recent emergence of elliptic-curve cryptography (ECC) vulnerabilities, such as TPM-Fail, Minerva, or TPM-Scan, for example. Several factors are proposed to explain the comparatively stronger security posture observed in HWWs, including domain-specific design choices and operational constraints that may provide inherent resilience, even in the absence of formal certification processes.

  • Czech name

  • Czech description

Classification

  • Type

    D - Article in proceedings

  • CEP classification

  • OECD FORD branch

    10200 - Computer and information sciences

Result continuities

  • Project

  • Continuities

    S - Specificky vyzkum na vysokych skolach

Others

  • Publication year

    2025

  • Confidentiality

    S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů

Data specific for result type

  • Article name in the collection

    Lecture Notes in Computer Science, LNCS 15995

  • ISBN

    9783032006325

  • ISSN

    0302-9743

  • e-ISSN

    1611-3349

  • Number of pages

    18

  • Pages from-to

    360-377

  • Publisher name

    Springer, Cham

  • Place of publication

    Cham

  • Event location

    Ghent, Belgium

  • Event date

    Jan 1, 2025

  • Type of event by nationality

    WRD - Celosvětová akce

  • UT code for WoS article

    001582782000021