How We Hacked Keystone: From a USB SDK Vulnerability to Mnemonic Extraction

Key Takeaways
• The USB SDK lacks validation for host-controlled lengths, resulting in out-of-bounds read and write operations on a fixed buffer
• Attackers can hijack the USB class callback table to escalate out-of-bounds writes into MCU arbitrary code execution
• Erroneous MPU configuration allows shellcode residing in SRAM to be executed directly
• By acquiring the Passcode, OTP, and cryptographic material from the secure element chips, the AES Key can be reconstructed to extract BIP39 mnemonic phrases
• Third-party SDKs also constitute part of the core security boundary of hardware wallets and must be included in comprehensive audits






