Side-Channel Vulnerability in Trezor Hardware Wallets
CVE-2025-69893
What is CVE-2025-69893?
A side-channel vulnerability has been identified in the BIP-39 mnemonic processing of Trezor hardware wallets. The vulnerability affects Trezor One, Trezor T, and Trezor Safe models running versions v1.13.0 to v1.14.0. This issue arises from the inherent non-constant time execution and predictable branching patterns during word searches according to the BIP-39 guidelines. An attacker with physical access during the wallet setup phase can exploit this vulnerability to collect a single side-channel trace. Utilizing advanced Deep Learning Side-Channel Analysis (DL-SCA) techniques, the attacker may successfully recover the wallet's mnemonic code, leading to potential asset theft. Security patches have been released to address this vulnerability.
