HARDWARE WALLET RESEARCH / 001

Wallets have
fingerprints too

A demo of a "pseudo-malicious" app;
See what a webpage can learn about a connected hardware wallet over WebHID / WebUSB.
No on-device prompts / taps / notifications disclosing the leak!

Read-only researchAll data stays in your browser
ENVIRONMENT
01

Connect a device

Checking browser

Plug in your wallet, then select a connection method.

Previously authorized devices only

Your browser asks for permission on the first connection.

off

Automatically re-scan granted devices on load, connection, and every 3 seconds.

EXPERIMENTAL

Send 1 "NOP" WebHID req. / 1 sec. to interfere with other wallet apps.

idle
02

Device intelligence

Passive fingerprint

USB / HID
Waiting for a device

USB descriptors reveal common information about the wallet.

Device descriptors MODEL · VENDOR · INTERFACE

Active fingerprint

APDU PROBE
No probe results yet

Read-only queries reveal what’s running.

Device responses APP · FIRMWARE · SETTINGS

Eavesdropped account data

ADDRESSES

Transport log

APDU / PROTOBUF I/O
LOCAL SESSION
↗ TX↙ RX! ERROR