20 months ago, our team reported a man-in-the-middle (MITM) vulnerability regarding hardware wallets to Trezor and MetaMask. This is a design flaw that, once the communication between the wallet software and hardware device is intercepted or tampered with, can result in significant asset loss for users. This article explains the entire attack process and preventive measures well.

https://zhangzhao.name/%E7%A1%AC%E4%BB%B6%E9%92%B1%E5%8C%85%E4%B8%8A%E7%9A%84%E8%BE%BE%E6%91%A9%E5%85%8B%E5%88%A9%E6%96%AF%E4%B9%8B%E5%89%91-%E9%9A%90%E7%A7%98%E7%9A%84%E4%B8%AD%E9%97%B4%E4%BA%BA%E5%A8%81%E8%83%81-522af4897bab