logo

New Eucleak attack lets threat actors clone YubiKey FIDO keys

ID: 72bff3cc-36f6-5f22-9d5e-b8edcc3713fc

STIX ID: report--72bff3cc-36f6-5f22-9d5e-b8edcc3713fc

Feed Name: Bleeping Computer

Threat Score
35/100

Date Published: 2024-09-04

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A side-channel vulnerability named EUCLEAK affects devices using the Infineon SLE78 security microcontroller (notably many YubiKey 5 Series, some YubiHSMs, Infineon TPMs, Optiga Trust M, and other products). The flaw enables extraction of ECDSA private keys via electromagnetic analysis, but exploitation requires extended physical access, specialized equipment, and high technical skill; Yubico rated the issue moderate (CVSS 4.9) and provides mitigations and affected firmware versions, noting limited risk to general users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.