Atlas21
  • ‎
No Result
View All Result
Atlas21
No Result
View All Result
Atlas21
Home Bitcoin

Dark Skippy: the (non) new attack that puts the private keys of hardware wallets at risk

Newsroom by Newsroom
August 14, 2024
in Bitcoin
address poisoning
Share on FacebookShare on TwitterShare on Linkedin

Published a method to steal the seed phrase of hardware wallets through malicious firmware: the details.

A “new” attack called Dark Skippy jeopardizes the security of Bitcoin hardware wallets. Discovered by Robin Linus, Lloyd Fournier, and Nick Farrow, this method allows a hacker to steal the seed phrase of a hardware wallet by hiding it within the signatures of Bitcoin transactions.

How the attack works

The attack is based on the use of malicious firmware that alters the standard process of signing Bitcoin transactions.

  1. The hacker installs malicious firmware on the victim’s hardware wallet.
  2. When the user makes a transaction, the firmware hides the first part of the seed phrase in the transaction signature.
  3. With just two transactions, the entire seed phrase can be reconstructed by the attacker.
  4. The hacker can thus gain complete control of the wallet and steal the funds.

Although the attack does not represent a new vulnerability, Dark Skippy exploits this weakness more efficiently: only two transactions are needed to completely compromise the victim’s wallet. In the past, it was thought that many more transactions were necessary.

The attack exploits a technical element called “nonce” used in transaction signatures. Hardware wallets insert these random values every time they sign Bitcoin transactions.
Through the malicious firmware, Dark Skippy makes the nonce predictable, allowing secret information to be hidden in the transaction signature. The attacker can then monitor the blockchain to find transactions with a specific watermark that reveals the presence of embedded data.
Using algorithms such as Pollard’s Kangaroo, the attacker can retrieve the predictable nonces from public signature data, subsequently reconstructing the seed and gaining control over the wallet. Pollard’s Kangaroo algorithm is a useful tool in cryptography for solving problems related to discrete logarithms, but it can also be used in attack contexts to compromise the security of cryptographic systems.

As stated in the official disclosure, Dark Skippy does not affect hardware wallets that use a multi-sig setup.

Possible countermeasures

To defend against this type of attack, hardware wallet users should:

  • Use only official and updated firmware.
  • Purchase hardware wallets only from reliable vendors.
  • Consider using multi-sig wallets for increased security.

Regarding hardware wallet manufacturers, possible mitigations include implementing anti-exfil protocols, which can help prevent unauthorized leakage of secret data from the hardware device. To date, BitBox and Blockstream Jade are the only two hardware wallets that have implemented anti-exfil.

Community reactions

Among the various reactions to the news, some Bitcoin developers immediately allayed concerns, stating that this type of attack has been known for some time.

Stadicus from BitBox commented:

Dark Skippy – amidst all the panic about this "new" attack…
😮😱😨

The #BitBox02 cold wallet implemented a specific protection against this attack over THREE years ago.

Jade is the only other hardware wallet using it.https://t.co/PNfn7vD6zt https://t.co/6Mao9ogwcz

— Stadicus (@Stadicus3000) August 5, 2024

The developer Matt Corallo stated:

This is a novel new construction, but the class of attacks is very, very old – hardware wallets have had years to address this, and those that haven’t (all but Jade and BitBox) should be treated as an incompetent joke and discarded.

Use an offline laptop before a hardware wallet https://t.co/5HhXTQpHex

— Matt Corallo (@TheBlueMatt) August 5, 2024
Previous Post

Fedi is born: the Bitcoin app that puts the community at its center

Next Post

TASS: Putin signs law to legalize mining in Russia

Latest News

ETF Bitcoin USA: quattro settimane di deflussi, ma la pressione si allenta
Bitcoin

USA Bitcoin ETF: four weeks of outflows, but pressure is easing

by Newsroom
June 10, 2026
0

Spot Bitcoin funds in the United States recorded $91.4 million in outflows on Monday, bringing the total since mid-May to...

Read moreDetails
Second lancia Bark su Bitcoin Mainnet: self-custody senza complessità
Bitcoin

Second launches Bark on Bitcoin Mainnet: self-custody without complexity

by Newsroom
June 10, 2026
0

Development lab Second has brought Bark into production, its implementation of the Ark protocol, aiming to make self-custody accessible to...

Read moreDetails
Pump.fun GO: tatuaggio sbagliato diventa token da 600.000 dollari
Bitcoin

Pump.fun GO: wrong tattoo becomes a $600,000 token

by Newsroom
June 9, 2026
0

A typo in a Pump.fun bounty turned a forehead tattoo into a Solana token with over $600,000 in market capitalization.

Read moreDetails
USA: coalizione di 200 aziende chiede al Senato di votare il Clarity Act
Bitcoin

USA: coalition of 200 companies urges Senate to vote on Clarity Act

by Newsroom
June 9, 2026
0

Stand With Crypto and over 200 organizations have written to Senate leaders calling for the Digital Asset Market Clarity Act...

Read moreDetails
Meta paga i creator in USDC
Bitcoin

Meta is paying creators in USDC

by Newsroom
June 8, 2026
0

Meta has chosen USDC for creator payments in 160 countries, but the real obstacle remains converting stablecoins into local currency.

Read moreDetails
Atlas21

© 2026 Atlas21

Navigate Site

  • Editorial Policy
  • Cookie Policy
  • Privacy Policy
  • Team

Follow Us

No Result
View All Result
  • Bitcoin 101
    • What Is Bitcoin? A Complete Guide
    • Bitcoin Security: A Complete Guide
    • Bitcoin Privacy: A Complete Guide
    • Lightning Network: A Complete Guide
    • Bitcoin Mining: A Complete Guide
    • Advanced Bitcoin: A Technical Guide
  • Learn
  • Latest News
  • Interviews
  • Opinion
  • Feature
  • B2B Services
  • About Us
  • Contacts

© 2026 Atlas21

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site, we will assume that you are happy with it.