logo

YubiKeys Are a Security Gold Standard—but They Can Be Cloned

ID: 388d6d28-230a-5ce4-b06d-81f027fd43aa

STIX ID: report--388d6d28-230a-5ce4-b06d-81f027fd43aa

Feed Name: WIRED Security

Threat Score
70/100

Date Published: 2024-09-05

Date Updated: 2026-04-26

Author: Dan Goodin, Ars Technica

...
...

Researchers disclosed a side-channel cryptographic flaw in the Infineon cryptolibrary used by YubiKey 5 tokens (and potentially other devices using the same microcontroller), enabling cloning and extraction of ECDSA private keys via electromagnetic/timing analysis during modular inversion; devices running firmware prior to 5.7 are permanently vulnerable because firmware cannot be updated on affected tokens, and exploitation requires temporary physical possession and specialized equipment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.