Trezor developer confirms private keys can be extracted if firmware is corrupt
A developer has acknowledged that a malicious firmware update can “exfiltrate” the seed and record the passphrase of a Trezor device. This revelation emerged during a discussion on Trezor’s official forum. It is weeks after the Ledger Recover feature suggestion that drew even more concern about the security of assets stored in popular hardware wallets. Trezor confirmation The developer emphasized that although open-source software allows for global community scrutiny and the use of hashes and signatures to verify authenticity, these measures do not eliminate the possibility of harmful code being included in an official software release. He said: “The firmware running on your Trezor must have access to private keys – otherwise, it could not sign your transactions. That means if the firmware turned malicious, it could exfiltrate the private keys. The only way to prevent that would be to freeze the device so that it could never be updated – and pray that...