For over three years, @lennert.bsky.social and I have worked on improving fault injection attacks against STM32F2 and STM32F4 devices to make them more repeatable and reliable. We're done! grandideastudio.com/portfolio/se... github.com/joegrand/stm... www.youtube.com/watch?v=4Lah...
Now @joegrand.bsky.social & @lennert.bsky.social about to show STM32 glitches that won't erase your device if you fail at RECON! #hardwarehacking
Finally releasing some work with Lennert! cfp.recon.cx/recon-2026/t...
Failure Is Not an Option: A Reliable Process to Exploit STM32F2/F4 Microcontrollers Recon 2026
The STM32 family of microcontrollers is deployed in billions of embedded systems, making them desirable, high-value targets. In particular, the STM32F2 and STM32F4 series have been heavily scrutinized due to their use in popular cryptocurrency hardware wallets like the KeepKey, Trezor One, and Trezor Model T. Previous research has shown that fault injection can bypass protection mechanisms and enable flash memory extraction. However, those techniques can lead to device corruption or permanent loss of data. In this talk, Joe and Lennert present three years of work refining and extending these attacks into a more repeatable and reliable process for extracting protected flash memory from STM32F2 and STM32F4 devices. They will discuss the practical engineering behind the work, including failures, breakthroughs, and new attack strategies. Using these techniques, they have recovered the cryptocurrency recovery seeds from dozens of customer-owned hardware wallets with a 100% success rate.
cfp.recon.cx
We have started announcing Recon 2026 Presentations recon.cx/2026/en/spea... More talks to be announced soon once we have confirmations #REcon2026 #ReverseEngineering #InfoSec #cybersecurity