Global Feed Post Login
Replying to Avatar semisol

Mk3 is broken

ATECC608B

Mk4 also uses ATECC608B + a DS SE that is also broken.

The ATECC and DeepCover SEs user by the Coldcard lack critical protections aginst LFI/EMFI.

There are also architectural flaws in the design of the Coldcard device that also allow the easy production of counterfeit devices

And these attacks only get cheaper by the day… a reasonable DIY setup may run $1K at most with pretty good capabilities.

Avatar
semisol 5mo ago

The Coldcard blog conveniently doesn’t mention the Mk3/4 ATECC SE being broken, or the fundamental flaws in the chips they use.

Note: I develop firmware for secure elements, primarily a product I am working on right now.

Reply to this note

Please Login to reply.

Discussion

No replies yet.