/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

How hacker Joe Grand used a fault-injection attack to crack a Trezor One hardware wallet to recover $2M in cryptocurrency for two friends who forgot the PIN

In early 2018, Dan Reich and a friend decided to spend $50,000 in Bitcoin on a batch of Theta tokens, a new cryptocurrency then worth just 21 cents apiece.

The Verge Kim Zetter

Context & Ripple Effects

This story sits inside a small but growing genre: legitimate experts breaking into 'unbreakable' crypto storage for owners locked out of their own funds. Joe Grand's fault-injection work follows the same playbook as Unciphered's IronKey crack and the researchers who later recovered ~$2M from a software wallet via an old RoboForm password-manager flaw — each time, the barrier was a forgotten credential, not a thief.

What makes this one notable is the target: a Trezor One hardware wallet, the device category marketed precisely as protection against remote compromise after incidents like the fake Trezor app that drained ~$600K from one user. Grand showed the threat isn't only phishing — it's physical access plus hardware skill.

First-order effects

  • Dan Reich and his friend regain access to roughly $2M in cryptocurrency they had written off after forgetting the PIN on their Trezor One.
  • Trezor faces public proof that its PIN protection yields to a voltage-glitching attack by someone with the wallet in hand, pressuring a firmware or hardware response.

Second-order effects

  • Hardware wallet makers competing with Trezor gain a selling point for secure-element designs that resist fault injection, turning Grand's research into marketing ammunition.
  • A commercial recovery market hardens around specialists like Grand and Unciphered, giving locked-out owners a paid alternative to permanent loss — and giving thieves with physical access a replicable technique.

Third-order effects

  • Self-custody's core promise — no intermediary can touch your keys — collides with the reality that physical possession plus expertise can too, forcing the industry to treat glitching attacks as a first-class threat model rather than an academic curiosity.
  • If recovery-by-attack keeps succeeding, custody decisions split into tiers: convenience-oriented holders accept recoverable-but-attackable devices, while large balances migrate toward institutional or multi-signature arrangements immune to any single person's hardware.

The trend: Crypto self-custody is splitting into two markets — consumer hardware wallets whose physical defenses are repeatedly breached, and a professional recovery industry that monetizes the breaches' techniques for locked-out owners.

Discussion

  • @kimzetter Kim Zetter on x
    New: Dan Reich and friend invested $50k in cryptocurrency, storing their key to $$ on a hardware wallet. But then they forgot their PIN. When the value shot up to $2 million+ they panicked. Until famous hardware hacker @joegrand helped crack their wallet: https://www.theverge.com…
  • @fleming77 Jane Fleming on x
    Luckily for Grand, there was previous research to guide him. In 2017, a 15-year-old hardware hacker in the UK named Saleem Rashid had developed a method to successfully unlock a Trezor wallet belonging to tech journalist Mark Frauenfelder and helped him free $30,000 in Bitcoin. h…
  • @kimzetter Kim Zetter on x
    To crack the Trezor One wallet, Grand used a fault-injection attack to glitch the wallet's microcontroller and downgrade security of the chip, then grab the PIN/key stored temporarily in RAM. Trezor One fixed part of the problem, but the chip maker won't fix the microcontroller
  • @nick_kapur Nick Kapur on x
    It's estimated 3.7 million Bitcoins worth $66.5 billion have been lost forever due to forgotten PINs and passkeys. Here's an interesting story of how a hacker cracked a hardware crypto wallet to retrieve lost tokens: https://www.theverge.com/...
  • @0xcharlie Charlie Miller on x
    I love me some @joegrand https://twitter.com/...
  • @cmwdotme Chris on x
    “Wow, this is perhaps one of the brightest electrical engineers I've ever met,”. He isn't wrong. @joegrand is the King. https://twitter.com/...
  • @kimzetter Kim Zetter on x
    Some of you may remember the Trezor wallet hacks done by @saleemrash1d in 2017 and the https://wallet.fail/ crew at the CCC conference in 2018. @joegrand's fault-injection hack against a $2 million Trezor One wallet last year borrows elegantly from both of those techniques. https…
  • @kimzetter Kim Zetter on x
    Tried to post this story to two sub-Reddit forums — /r/Theta_network and /r/cryptocurrency — and it gets automatically rejected. Anyone know why that is? https://twitter.com/...