According to Gate.io News bot, Protos reported that the ESP32 chip has a serious security vulnerability (CVE-2025-27840). This chip is widely used in Bitcoin hardware wallets such as Blockstream Jade.
The vulnerability originates from insufficient entropy in the chip’s random number generator, allowing hackers to sign unauthorized transactions through brute-forcing key pairs or module updates. The cybersecurity company Crypto Deep Tech has completed the vulnerability verification and successfully demonstrated the process of forging transaction signatures and extracting private keys, including decrypting a private key that contains 10 BTC Wallet. White hat researchers pointed out that the vulnerability has reached a national-level attack scale.
Source: Protos