Skip to content

Commit 478e93c

Browse files
authored
Update software-supply-chain-attacks-crypto.md
1 parent 4f9f1e0 commit 478e93c

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

software-supply-chain-attacks-crypto.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -115,6 +115,12 @@ Secbit has discovered that Trust Wallet did not correctly use a dependency (`tre
115115

116116
Ref: <https://secbit.io/blog/en/2024/01/19/trust-wallets-fomo3d-summer-vuln/>
117117

118+
### Attack through AI generated code, Nov 2024
119+
120+
@r_cky0 [reported](https://x.com/r_cky0/status/1859656430888026524) that ChatGPT generated code containing links to scamming website, incl. executable key exfiltration.
121+
122+
Ref: <https://x.com/r_cky0/status/1859656430888026524>
123+
118124
## Hardware attacks
119125

120126
It is possible to tamper with hardware devices used in crypto, typically a hardware wallet. Who would do that: an employee at the company that designed the wallet, the factory that produced it, and everyone involved in shipping it. Ref: <https://vitalik.ca/general/2021/01/11/recovery.html>. Such a real hardware supply chain attack has happened on Trezor wallets (2022): <https://www.kaspersky.com/blog/fake-trezor-hardware-crypto-wallet/48155/>

0 commit comments

Comments
 (0)