GeistHaus
log in · sign up

Trezor One dry-run recovery vulnerability

blog.inhq.net

In the first half of 2018, I found a number of security issues in the Trezor One hardware wallet during my master thesis on fuzzing and verification. Most of the issues were discovered through the powerful combination of fuzzing with libFuzzer and error detection via sanitizers such as Address Sanitizer and Undefined Behavior Sanitizer.

2 pages link to this URL