In close cooperation with Joe Grand and Grand Idea Studio, the Netherlands Forensic Institute (NFI) is offering a training course for the exploitation of cryptocurrency hardware wallets.
This two-day course focuses on advanced hardware hacking tools and techniques used to exploit common cryptocurrency hardware wallets and their associated STM32-based microcontrollers. It is a hands-on environment where students will learn how to recover the PIN and seed phrase/wallet backup from Trezor One, Trezor Model T, and KeepKey devices using electromagnetic (EMFI) and voltage (VFI) fault injection. Students will be able to apply the same or similar processes to future targets outside of the classroom.
The course is two days in length. It is required to have completed NFI’s Hardware Hacking and Reverse Engineering Basic and Advanced courses, either this time or in the past, or with prior approval from instructor.
Content
The training course combines lecture and hands-on exercises for the following topics:
- Fault Injection (EMFI and VFI)
- Side Channel Analysis (SCA)
- STM32 Device Exploration
- Target Device Characterization
- Trezor One (STM32F205) Attack
- Trezor Model T (STM32F427) Attack
- PIN Cracking and Seed Phrase Decryption
A complete agenda for the training course is available here.
Objectives
Once you have successfully completed the course you will have:
- An understanding of the complete analysis and characterization process of a target device in order to exploit fault injection.
- Hands-on experience with a full attack chain for Trezor One, Trezor Model T, and KeepKey cryptocurrency hardware wallets.
- Experience to apply the same or similar processes to future devices outside the classroom.
Prerequisites
NFI's Hardware Hacking and Reverse Engineering Basic and Advanced courses or with prior approval from instructor.
Target group
Only from ENFSI-labs and/or NATO countries:
- digital police investigators
- forensic investigators in other law-enforcement agencies
Dates and venue
19-20 October 2026 in Amsterdam (fully booked)
25-26 October 2027 at the Netherlands Forensic Institute in the Hague (spaces available)
Daily schedules: 9.00-17.00 h
Number of participants
12-24 participants
Costs
€ 2.995,- per participant
- N.B.: No VAT will be added.
- Hotel and travel costs are not included.
- This includes lunches, slides, source code, Trezor One and Trezor Model T hardware wallets, custom breakout boards, and additional reference documentation.
Materials
- Students should bring their own laptop running MacOS, Linux, or Windows (administrator access is required).
- The laptop will be used to control test equipment and hardware hacking tools. Software and drivers will need to be installed.
- Participants will be provided with all tools and materials necessary for the course.
Additional information
The course is taught in English.
Registration
Registration can be made by filling out the registration form.
For more information, of if you want to register a group, you can complete our contact form.
Please indicate on the form you are interested in the training Cryptocurrency Wallet Exploitation.