Hacker News new | ask | show | jobs
by jstanley 850 days ago
When you plug a hardware wallet into a computer it can't get the keys off the wallet. It can only ask the hardware wallet to sign a transaction, and the hardware wallet asks the user to confirm.

When you plug a thumbdrive with keys on it into a computer the computer can just take the keys.

It's the same as the difference between a YubiKey and a thumbdrive with GPG keys on it.

1 comments

They exploited the change address which most crypto hardware wallets don't show when verifying a transaction.