Dark Skippy: A New Attack on Bitcoin Hardware Wallets? With Nick, Lloyd and Robin SLP597

Dark Skippy: A New Attack on Bitcoin Hardware Wallets? With Nick, Lloyd and Robin SLP597

Dark Skippy is a new attack that in theory, makes it much easier for a malicious person to steal your coins. Listen in to learn about some of the ins and outs here, as well as mitigation and the path forward for the industry from @utxoclub , @LLFOURN & @robin_linus .

  • Why air gapping is not the be all end all

  • Dark Skippy in context with other attacks

  • Security while signing transactions, and security while generating keys

  • RFC6979 Deterministic nonce generation

  • Updating PSBT to help mitigate this attack

Summary

The conversation discusses the ‘Dark Skippy’ attack, a new method for leaking secret keys from a malicious signing device. The attack takes advantage of the nonces used in the Schnorr and ECDSA signature schemes. The new attack vector can potentially extract private keys and seed words from hardware wallets. The attack targets the nonce generation process during key generation and signing. The previous versions of this attack were inefficient, but Dark Skippy improves upon them. The contributors explain how the attack came about and its implications for hardware wallet security. They also discuss the RFC6979 deterministic nonce generation and the concept of anti-klepto signing protocols as mitigations against the attack.

While Dark Skippy is a sophisticated attack, it requires a high level of expertise and is not currently seen in the wild. The discussion highlights the importance of secure boot, upgrading the Partially Signed Bitcoin Transaction (PSBT) process, and improving the randomness of upfront key generation as potential mitigations.

However, it is emphasized that current reputable hardware wallets still provide a high level of security, and there is no immediate action required for users.

Takeaways

  • Dark Skippy is a new attack that leaks secret keys from a malicious signing device.

  • The attack exploits the nonces used in the Schnorr and ECDSA signature schemes.

  • Previous versions of this attack were inefficient, but Dark Skippy improves upon them.

  • Mitigations against the attack include the RFC6979 deterministic nonce generation and anti-klepto signing protocols. Dark Skippy is a sophisticated attack that targets the nonce generation process during key generation and signing.

  • Mitigations for Dark Skippy include implementing secure boot, upgrading the PSBT process, and improving the randomness of upfront key generation.

  • Reputable hardware wallets currently provide a high level of security, and there is no immediate action required for users.

  • The discussion highlights the importance of ongoing research and development to enhance the security of hardware wallets and protect against potential future attacks.

Timestamps:

(00:00) - Intro

(00:45) - What is ‘Dark Skippy’?

(04:39) - Is it an old attack vector? Bitcoin’s security evolving with time

(12:41) - Sponsor

(15:22) - What is a nonce?, RFC6979 Deterministic nonce generation

(22:55) - Common ways of people losing their Bitcoin

(31:08) - Sponsor

(32:07) - Anti-klepto signing protocols; ways to mitigate risks of losing coins

(39:51) - Updating PSBT to help mitigate this attack

(43:26) - The role of Multisig in preventing the attack

(49:57) - Other attack vectors in malicious actor’s toolkit

(56:49) - Summarizing the steps to improve the ecosystem security

(1:00:18) - Closing thoughts

Links:

Sponsors:

Stephan Livera links:

Avsnitt(733)

BTC Prague 2026 with Matyas Kuchar | SLP733

BTC Prague 2026 with Matyas Kuchar | SLP733

In this episode Stephan speaks with Matyas Kuchar, co-founder of BTC Prague, about the upcoming Bitcoin conference in Prague. They discuss the conference's focus on Bitcoin and its intersection with o...

3 Apr 42min

The Physics of Bitcoin with Giovanni | SLP732

The Physics of Bitcoin with Giovanni | SLP732

In this conversation, Giovanni Santostasi discusses his new book 'The Physics of Bitcoin' and the application of power law analysis to understand Bitcoin's growth, value, and long-term behavior. The c...

27 Mars 59min

There's Hope for Bitcoin with James Van Straten | SLP731

There's Hope for Bitcoin with James Van Straten | SLP731

In this episode, Stephan Livera chats with James Van Straten, senior analyst at CoinDesk, to explore the current state of Bitcoin and macro markets. They discuss the nature of bear markets, cycle theo...

17 Mars 42min

Cluster Mempool Explained with Pieter Wuille | SLP730

Cluster Mempool Explained with Pieter Wuille | SLP730

Stephan Livera and Pieter Wuille discuss Cluster Mempool for Bitcoin Core, its motivations, and its implications for Bitcoin users and miners. Where does the current mempool design have issues? Why is...

12 Mars 52min

UTXOs, Spam & Bitcoin's Integrity with Martin Habovstiak | SLP729

UTXOs, Spam & Bitcoin's Integrity with Martin Habovstiak | SLP729

In this conversation, Stephan Livera interviews Bitcoin developer Martin Habovstiak about his website Knotslies and the controversies surrounding data contiguity in Bitcoin transactions. They discuss ...

11 Mars 58min

NumoPay: Tap-to-Pay Bitcoin with Calle | SLP728

NumoPay: Tap-to-Pay Bitcoin with Calle | SLP728

In this episode, Calle introduces Numopay, an open-source Bitcoin payment terminal that enables tap-to-pay experiences similar to fiat systems. We explore its technical foundations, privacy features, ...

10 Mars 44min

Can Bitcoin help you retire early? with Trey Sellers | SLP727

Can Bitcoin help you retire early? with Trey Sellers | SLP727

In this episode, Stephan Livera interviews Trey Sellers about Bitcoin and FIRE (Financial Independence, Retire Early). They explore how Bitcoin can accelerate FIRE, different strategies for retirement...

6 Mars 47min

Will Stablecoins help in Bitcoin adoption? with Gareth Grobler | SLP726

Will Stablecoins help in Bitcoin adoption? with Gareth Grobler | SLP726

In this conversation, Stephan Livera and Gareth Grobler discuss the innovative features of the Layerz Wallet, focusing on its multi-layered approach to cryptocurrency transactions, the importance of s...

25 Feb 42min

Populärt inom Teknik

uppgang-och-fall
elbilsveckan
market-makers
rss-technokratin
natets-morka-sida
skogsforum-podcast
har-vi-akt-till-mars-an
rss-laddstationen-med-elbilen-i-sverige
bilar-med-sladd
bli-saker-podden
rss-en-ai-till-kaffet
dom-kallar-oss-krypto
teknikveckan
hej-bruksbil
rss-veckans-ai
rss-snacka-om-ai
rss-elektrikerpodden
developers-mer-an-bara-kod
rss-uppgang-och-fall
rss-upplyst-entreprenordirektor