Side-Channel Vulnerability in Trezor Hardware Wallets
CVE-2025-69893

4.6MEDIUM

Key Information:

Vendor

Trezor

Vendor
CVE Published:
14 April 2026

What is CVE-2025-69893?

A side-channel vulnerability has been identified in the BIP-39 mnemonic processing of Trezor hardware wallets. The vulnerability affects Trezor One, Trezor T, and Trezor Safe models running versions v1.13.0 to v1.14.0. This issue arises from the inherent non-constant time execution and predictable branching patterns during word searches according to the BIP-39 guidelines. An attacker with physical access during the wallet setup phase can exploit this vulnerability to collect a single side-channel trace. Utilizing advanced Deep Learning Side-Channel Analysis (DL-SCA) techniques, the attacker may successfully recover the wallet's mnemonic code, leading to potential asset theft. Security patches have been released to address this vulnerability.

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.