How hacker Joe Grand used a fault-injection attack to crack a Trezor One hardware wallet to recover $2M in cryptocurrency for two friends who forgot the PIN
In early 2018, Dan Reich and a friend decided to spend $50,000 in Bitcoin on a batch of Theta tokens, a new cryptocurrency then worth just 21 cents apiece.
Context & Ripple Effects
This story sits inside a small but growing genre: legitimate experts breaking into 'unbreakable' crypto storage for owners locked out of their own funds. Joe Grand's fault-injection work follows the same playbook as Unciphered's IronKey crack and the researchers who later recovered ~$2M from a software wallet via an old RoboForm password-manager flaw — each time, the barrier was a forgotten credential, not a thief.
What makes this one notable is the target: a Trezor One hardware wallet, the device category marketed precisely as protection against remote compromise after incidents like the fake Trezor app that drained ~$600K from one user. Grand showed the threat isn't only phishing — it's physical access plus hardware skill.
First-order effects
- Dan Reich and his friend regain access to roughly $2M in cryptocurrency they had written off after forgetting the PIN on their Trezor One.
- Trezor faces public proof that its PIN protection yields to a voltage-glitching attack by someone with the wallet in hand, pressuring a firmware or hardware response.
Second-order effects
- Hardware wallet makers competing with Trezor gain a selling point for secure-element designs that resist fault injection, turning Grand's research into marketing ammunition.
- A commercial recovery market hardens around specialists like Grand and Unciphered, giving locked-out owners a paid alternative to permanent loss — and giving thieves with physical access a replicable technique.
Third-order effects
- Self-custody's core promise — no intermediary can touch your keys — collides with the reality that physical possession plus expertise can too, forcing the industry to treat glitching attacks as a first-class threat model rather than an academic curiosity.
- If recovery-by-attack keeps succeeding, custody decisions split into tiers: convenience-oriented holders accept recoverable-but-attackable devices, while large balances migrate toward institutional or multi-signature arrangements immune to any single person's hardware.
The trend: Crypto self-custody is splitting into two markets — consumer hardware wallets whose physical defenses are repeatedly breached, and a professional recovery industry that monetizes the breaches' techniques for locked-out owners.