How far can a BootROM exploit take you on a Crypto phone?
All the way to the wallet signing key.
At #
DEFCON34#, CertiK researcher Guanxing Wen (
@hhj4ck) demonstrated the full chain:
BootROM → root → offline PIN recovery → wallet signing key.
Short version ↓