Does someone happen to have one of the vulnerable COLDCARDS and would sell it to me at DEFCON?🙏
stacksmashing
@stacksmashing.bsky.social
Security researcher with a focus on hardware & firmware. I occasionally publish stuff on YouTube. Co-founder of hextree.io. Contact: contact@stacksmashing.net
If there's one hardware wallet I always told people not to trust it's COLDCARD. Not surprised in the slightest by the recent events. (They messed up their RNG in multiple ways, leading to - so far - user losses above $38 million USD.)
Hacking random companies is totally okay if I claim my GPU did it?!
Did KiCAD get compromised? Or some over-eager AI-scraping prevention?!
If the sandbox escape was so advanced then publish the details.
My DEF CON talk "Hacking jetskis - from Sea-Don't to Sea-Doo" got accepted 🥳 We'll be having some good fun - such as bypassing the immobilizer using a custom Flipper Zero app, building a custom diagnostic adapter, and some big plot-twists 🛥️
Opposite of solder-pr0n: Messed up the stencil solder application and was hoping for surface tension to fix it for me 🥲 The expired paste probably didn't help either
Non-technical teams are now shipping production vulns
Told someone their "vulnerability report" is bs (result of an automatic scanner that has a false positive...) This was the response 😑
Sometimes it’s nice to go back to basics: Built firmware that’s just 246 bytes, uses no RAM at all, and runs parasitically from a 1-wire bus at just 0.2 mA. Yet it emulates a full jetski key! You can see voltage rising until the chip starts running based on the BOD threshold.
If you ever lose the keys to your older Sea-Doo Jetski you might find these bytes useful when talking to the ECU😇 95 BC 2F 02 04 A4 75 BE
Option A: Upgrade iPhone to iOS26 and have to use liquid glass Option B: Get pwned by DarkSword malware I don't know which one is worse
If the datasheet says to use tantalum capacitors - then use tantalum capacitors! Blue = Ceramics Yellow = Tantalum
Simple age check for Linux: Just have the shell ask the user to check the host IP on first boot. If they type ifconfig they are old enough, if they type ip addr they deserve to be restricted from their computer 😇
Things I didn’t see coming: apparently I own a Game Boy signed by a Eurovision contestant?! 😆 youtu.be/8XR2RvfZ-68
Won today’s bet of “Do I really have no oil pressure, or is the gauge just broken?” 😅
Wow, used Yamaha 01V96 are a steal - and 17 motor faders are a lot of fun 😀
Yes VSCode, I obviously want to use the color-picker to edit the address offsets in Arm assembly 😂
My first post on the RaspberryPi Blog 😍 We've extended the RP2350 side-channel hacking challenge to April 30 - and even better: To make attacks for the challenge easier, we decided to disable the random chaffing and some more mitigations! www.raspberrypi.com/news/rp2350-...
RP2350 Hacking Challenge 2: Less randomisation, more correlation - Raspberry Pi
Our second RP2350 Hacking Challenge has evolved, with prize money still up for grabs.
raspberrypi.com
The new AirTags 2 just arrived! Time to take them apart 🧵
Work: Fix rust issues 🦀 Hobby: Fix rust issues 👨🏭 😭
Call for flash-chips at DEF CON! If you have leftover or rare SPI flash-chips that I can have for testing some tooling I’m building I’d be very thankful. Also if you have devices where you had trouble dumping in-system I’d love to give it a try. I’ll be at Embedded Systems Village :)