• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Some Fortune Crypto pricing data is provided by Binance.
CompaniesCryptocurrency

Cyber firm cracks OneKey crypto wallets, raises broader questions of hardware security

Jeff John Roberts
By
Jeff John Roberts
Jeff John Roberts
Editor, Finance and Crypto
Down Arrow Button Icon
Jeff John Roberts
By
Jeff John Roberts
Jeff John Roberts
Editor, Finance and Crypto
Down Arrow Button Icon
February 9, 2023, 12:31 PM ET

When it comes to privacy and security, many in the world of crypto have long touted hardware wallets as a superior option for holding Bitcoin and other digital assets. For proponents, the benefits of such wallets—small USB-like devices that connect to laptops or cell phones—lie in the fact they are physical devices that can be stored offline, safe from hackers, except for the times an owner wants to make a transaction.

But not everyone is convinced they are always a good idea, including a team of white hat hackers at a cybersecurity startup called Unciphered. The team has just published a video that shows them breaking into a device manufactured by OneKey, a Hong-Kong based firm that has raised $20 million in venture capital and that describes its product as an “open source wallet trusted by millions.”

Unciphered shared a preview version of the video with Fortune, explaining that the exploit involved using a “man-in-the-middle” attack to trick the OneKey device into thinking it was still in the factory. By doing this, Unciphered was able to get the device to relay the wallet’s seed phrase—a random, unguessable string of 12 or more words that serves as a password—to another part of the device’s computer system, capturing it along the way.

Taking possession of a seed phrase means it is possible to gain access to the digital assets inside a wallet and steal them by sending them to a different address. Or more simply, it’s like making a copy of the key to someone’s safety deposit box that can be accessed anytime and anywhere.

Here are images showing the exploit, which Unciphered says takes less than a second to conduct once the OneKey device has been disassembled and the “man-in-the-middle” component attached:

Yishi Wang, the founder of OneKey, confirmed the existence of the exploit, and told Fortune the company has since provided an update to repair it.

“We appreciate the assistance of Unciphered and other security white hats. The firmware vulnerability you mentioned above, which required physical access [and] specialized equipment, has now been fixed,” he said by email.

According to Unciphered, OneKey paid the company $10,000 in the form of a “bug bounty”—a term that describes a reward system, offered by many tech and crypto companies, to encourage white hackers to report and share vulnerabilities in a responsible fashion.

How safe are hardware wallets, really?

While the existence of vulnerabilities are always cause for concern, the reality is that not all exploits pose a significant real world danger. As the OneKey founder noted in his reply to Fortune, the vulnerability discovered by Unciphered required a hacker to have physical access to the device and a high degree of technical proficiency—a very different situation than a software exploit that can be sold or used by a low-level cyber-criminal.

Nonetheless, the danger is still real. According to Eric Michaud, the founder of Unciphered, the sort of person who possesses a hardware wallet typically owns a fair amount of digital assets, and is especially likely to be targeted by sophisticated criminals. He notes that crypto conferences provide a particularly target rich environment for thieves, including those who burgle hotel rooms.

In an interview, Michaud also observed that hardware wallets can provide a false sense of security, leading owners to fail to securely store their device on the false assumption hackers can’t crack it. And while hardware makers provide software updates to harden a device’s security—as OneKey did in response to Unciphered’s discovery—there is also the problem of older wallets whose manufacturer is no longer in business, or held by owners who neglect to update them.

More broadly, Michaud says Unciphered—which is staffed by longtime security researchers, some of whom have held national security clearances—is also concerned about a much broader range of hardware wallets than OneKey.

According to Michaud, multiple hardware wallet manufacturers recycle the same code base to make their products, meaning that a vulnerability discovered in one wallet is often found in other ones. The upshot is that those who rely on hardware wallets to guard their crypto need to remain vigilant.

Learn how to navigate and strengthen trust in your business with The Trust Factor, a weekly newsletter examining what leaders need to succeed. Sign up here.

About the Author
Jeff John Roberts
By Jeff John RobertsEditor, Finance and Crypto
LinkedIn iconTwitter icon

Jeff John Roberts is the Finance and Crypto editor at Fortune, overseeing coverage of the blockchain and how technology is changing finance.

See full bioRight Arrow Button Icon

Latest in Companies

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
Fortune Secondary Logo
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Most Popular

placeholder alt text
Success
Japanese companies are paying older workers to sit by a window and do nothing—while Western CEOs demand super-AI productivity just to keep your job
By Orianna Rosa RoyleFebruary 27, 2026
1 day ago
placeholder alt text
Success
Walmart exec says U.S. workforces needs to take inspiration from China where ‘5 year-olds are learning DeepSeek’
By Preston ForeFebruary 27, 2026
2 days ago
placeholder alt text
Personal Finance
Current price of gold as of February 27, 2026
By Danny BakstFebruary 27, 2026
1 day ago
placeholder alt text
Law
China's government intervenes to show Michigan scientists were carrying worms, not biological materials
By Ed White and The Associated PressFebruary 26, 2026
2 days ago
placeholder alt text
Economy
Come 2030, the U.S. deficit will be worth 5.9% of GDP—more than spending on Social Security, and equal to major health programs
By Eleanor PringleFebruary 26, 2026
2 days ago
placeholder alt text
Commentary
'The Pitt': a masterclass display of DEI in action 
By Robert RabenFebruary 26, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.


Latest in Companies

CompaniesVenture Capital
Exclusive: Crypto venture firm CMT Digital raises $136 million for fourth fund
By Ben WeissNovember 5, 2025
4 months ago
A Ferrari race car on a racetrack
CompaniesCryptocurrency
Ferrari to release crypto token to let wealthy fans take part in 499P auction
By Carlos GarciaNovember 3, 2025
4 months ago
Michael Saylor on stage at a Bitcoin conference.
CompaniesBitcoin
Michael Saylor boosts yield, says Strategy is at an ‘inflection point’
By David Pan, Judy Lagrou and BloombergOctober 30, 2025
4 months ago
CompaniesCryptocurrency
Crypto founders are getting very rich, very fast—again
By Jeff John RobertsOctober 30, 2025
4 months ago
A Mastercard credit card peeking out from a pocket.
CompaniesMastercard
Exclusive: Mastercard poised to acquire crypto startup Zerohash for nearly $2 billion, sources say
By Ben Weiss and Leo SchwartzOctober 29, 2025
4 months ago
Three men stand in front a white backdrop.
CompaniesCryptocurrency
Exclusive: Startup Hercle raises $10 million to build out stablecoin-based global money transfers
By Carlos GarciaOctober 29, 2025
4 months ago