The most concerning part of this story is malware fooling a hardware wallet. Trusting an ETH L2 is pretty reckless on its own.

Reply to this note

Please Login to reply.

Discussion

I wonder the security practices for HWW manufacturing now, especially ones with an STM32 handling keys or whatever.

I don't think it speaks directly to an issue with malware and hardware wallets generally; they had some kind of custom procedure for authorising transactions which got sent to a HW in the background, from what it says there (the medium link 404s so I'm just going on what's reported in cointelegraph). It sounds like the transactions did actually trigger warnings but in the software layer above the HW? Anyway details, basically this was not an attack on HW unless the article is completely wrong?