There are ways to exfiltrate data through a QR or SD card airgap. SD card is easiest; write to hidden blocks.

QRs can be modulated in other ways such as delay time, intentional error faults, or other choices.

There is also the fact that anything that exists emits EMI, and the Coldcard is no exception. This can be abused to create signals that contain your seed + can be detected at quite a distance using a box the size of a Pi.

Reply to this note

Please Login to reply.