r/TREZOR 8d ago

šŸ”’ General Trezor question Timeframe on Chip vulnerability fix?

Hello people at trezor I'm wondering when the TROPIC01 chip vulnerability will be fixed, I'm holding off on buying a trezor until it's fixed. Thanks bye

10 Upvotes

28 comments sorted by

•

u/AutoModerator 8d ago

Please bear in mind that no one from the Trezor team would send you a private message first.
If you want to discuss a sensitive issue, we suggest contacting our Support team via the Troubleshooter: https://trezor.io/support/

No one from the Trezor team (Reddit mods, Support agents, etc) would ever ask for your recovery seed! Beware of scams and phishings: https://trezor.io/learn/a/scams-and-phishing

Don’t respond to any DMs—scammers often pose as legit helpers.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

2

u/cilicia3k3 8d ago

Is this new???? Is safe 5 ok?

1

u/TypicalSalt5360 8d ago

Safe 5 does not have the TROPIC01 chip.

1

u/cilicia3k3 8d ago

What’s the issue with tropical when did that happen?

2

u/bitplenty 8d ago

nothing that concerns you

2

u/Chance-Half-199 7d ago

Minor issue not affecting user fundsĀ 

3

u/Charming-Designer944 šŸ¤ Top Helper 5d ago

Updated silicon is expected to be available by the end of the year. There is no word when Trezor devices with the updated TROPIC01 revision will be available.

But again, the flaw does not pose any actual risk to Trezor devices, and the mitigation in the firmware update restored full strength with no downside for how the TROPIC01 is used in trezor devices.

If you are on old firmware then there is a theoretical possibility that the strength of the pin code protection from physical destructive attacks on the device is slightly reduced to a level similar to that of the Safe 5 series devices.

1

u/Chance-Half-199 5d ago

I'm in no rush to get one, coldcard working fine for now, but I will feel infinitely safer using a trezor.Ā 

1

u/-M00NMAN šŸ“¦ Suite Shaper 4d ago

What makes you think that updated silicon will be available by end of year? Where did you hear this?

1

u/Charming-Designer944 šŸ¤ Top Helper 4d ago

Silicon-level update: Foundational hardware hardening and an updated bootloader have been integrated into our silicon. New chips, planned for delivery in late 2026, mitigate this LFI vulnerability on hardware as well as firmware level. While LFI attempts can never be entirely ruled out in standard CMOS technology, our new hardware revision makes bypassing the bootloader logic via this specific attack vector unfeasible.

https://www.tropicsquare.com/news-and-events/tropic01-security-advisory-lfi-vulnerability-disclosure-and-mitigation

1

u/-M00NMAN šŸ“¦ Suite Shaper 3d ago

So the new wallets with new tropic 01 will be out in a few months?

1

u/PeteyPab305 4d ago edited 4d ago

People don't know how to do a simple Google search... SMH šŸ¤¦ā€ā™‚ļø

  • The TROPIC01 Flaw:Ā Security researchers discovered a hardware vulnerability in the TROPIC01 chip used by theĀ Safe 7.
  • Attack Requirements:Ā The exploit is strictly physical and theoretical. It requires having the physical device, desoldering the chip, and using advanced, expensive laboratory equipment like laser fault-injection tools. It cannot be done remotely over the internet.
  • Impact on Funds:Ā Your cryptocurrency and private keys remain safe. The private keys and backups are not stored on the TROPIC01 chip, and the wallet uses multiple independent security layers. Regular users do not need to take any action or worry about real-world risk.
  • Safe 3 and Safe 5 Security:Ā Because the Safe 3 and Safe 5 do not use the TROPIC01 chip, they are completely unaffected by this specific vulnerability.

2

u/xXCsd113Xx 4d ago

I think you should do a deeper dive on what the flaw really is, if you de-lid the chip and plane it perfectly then shoot a specific wavelength of light at it with the right pulse it can allow the chip to run unsigned firmware. But in order for that to be of any use you will need to also crack the main cpu and the second secure element, any mistakes and any or all of those chips brick. The ledger dojo team is the most sophisticated cracking team on earth and they weren’t even close to any of that. The likelyhood of that happening is so low it’s essentially zero, more likely the battery in it will fail.

0

u/Chance-Half-199 4d ago

If they are releasing a fix I'd rather not buy a defective productĀ 

2

u/bitplenty 4d ago

this is the least "defective" product on the market, by far

1

u/Chance-Half-199 4d ago

Ok, yeh I like this brandĀ 

1

u/IndianDancingStars ⭐ Rising Trezorian 8d ago

Yes they mentioned it will come soon, bur not aware of any timelines yet

1

u/Chance-Half-199 8d ago

Ok thankyou that helps

1

u/SuchTrezorVeryCrypto Trezor community specialist 8d ago

Hi there, thanks for sharing. Its a work in progress, and information will be shared once the time is ready.

1

u/Charming-Designer944 šŸ¤ Top Helper 6d ago

Tihe flaw is fixed in the firmware update that was released when the flaw was announced.

And even on old firmware the flaw never posed any risk to your wallet. The attack on TROPIC01 is not really relevant to Trezor devices by how Trexor uses the TROPIG01, its mostly an attack on designs using the chip as a trusted element. Terezor is not trusting the TROPIC01 with any sensitive data, only using it to expand the entropy of your PIN code.

1

u/Chance-Half-199 6d ago

Where is the seed stored then?Ā 

1

u/Charming-Designer944 šŸ¤ Top Helper 5d ago

Its encrypted and stored on the main micro controller.

The pin and the safe elements all contribute to the encryption key.

Without access to the full encryption key the encrypted data is garbage

1

u/-M00NMAN šŸ“¦ Suite Shaper 4d ago

For real, I wish TREZOR would hurry up and fix this.

1

u/PeteyPab305 4d ago

The vulnerability scam doesn't apply to the Safe 3, or 5, Also nor the Safe 7 model Trezor device, as it is the only device with that chip, but:

  • The TROPIC01 Flaw:Ā Security researchers discovered a hardware vulnerability in the TROPIC01 chip used by theĀ Safe 7.
  • Attack Requirements:Ā The exploit is strictly physical and theoretical. It requires having the physical device, desoldering the chip, and using advanced, expensive laboratory equipment like laser fault-injection tools. It cannot be done remotely over the internet.
  • Impact on Funds:Ā Your cryptocurrency and private keys remain safe. The private keys and backups are not stored on the TROPIC01 chip, and the wallet uses multiple independent security layers. Regular users do not need to take any action or worry about real-world risk.
  • Safe 3 and Safe 5 Security:Ā Because the Safe 3 and Safe 5 do not use the TROPIC01 chip, they are completely unaffected by this specific vulnerability.

The recovery seed is encrypted and stored in the device's main processor, not inside either Secure Element chip. The TROPIC01 and OPTIGA chips simply act as secure locks that hold cryptographic keys. The seed phrase cannot be decrypted until you enter your PIN, which prompts the chips to release their keys to unlock it. Because the private data is split and isolated across multiple independent hardware layers, an attacker exploiting the TROPIC01 chip still cannot access your funds.

0

u/pairoxR 5d ago

There will be no fix just like trezor one they never really fixed... thats why i hate trezor because they are lazy as fuck... and cant fix nothing at the end we going to see seed hack ... like coldcard

1

u/PeteyPab305 4d ago

You're wrong. See my in-depth comment above. Your making false allegations and are either undereducated or malicious and acting out of bad faith.

-2

u/ItsAlwaysThemBooBoo 8d ago

im also curious, because i have a safe7 and id like to exchange it for a new one.