Firmware Extraction & Security Analysis

Comprehensive firmware extraction, reverse engineering, and security auditing services. We combine statistical cryptanalysis, side‑channel techniques, and hardware expertise to recover locked firmware and assess system vulnerabilities.

Probability Theory for Pickpockets – Revisiting ec-PIN Guessing

An Analysis of Algorithmic Weaknesses and Practical Attack Vectors

Part 1 – Introduction and System Overview

The security of automated teller machine (ATM) systems has long relied on cryptographic protocols and secret keys, but the human centred design of personal identification numbers (PINs) often introduces subtle vulnerabilities. This article revisits a classic analysis originally presented by Markus G. Kuhn, which exposes a significant flaw in the PIN generation algorithm used for EuroCheque (ec) cards in Germany from 1981 until 1997. We provide a comprehensive rewrite of that work, extending the probabilistic framework, discussing practical exploitation scenarios, and highlighting why such legacy mechanisms remain relevant for modern security auditing.

A determined adversary with access to the magnetic stripe data can leverage the correction offsets to drastically improve guessing odds, which is a classic illustration of how poor randomness propagation enables efficient reverse engineering of the PIN space. The core problem arises from the bank’s decision to compute a customer’s PIN deterministically rather than allowing user selection. For each card, the issuing bank constructs a 16 digit decimal string by concatenating five digits of the bank routing number, the ten digit account number, and a single digit card sequence number. This string is encoded in binary coded decimal (BCD) to form a 64 bit block, which is then encrypted with the Data Encryption Standard (DES) using a secret 56 bit institute key KI. The resulting 16 hexadecimal digit ciphertext is then “decimalized” by taking digits 3–6, converting letters A–F to 0–5 respectively, and replacing a leading zero with one—except when using pool keys, as explained later.

This deterministic mapping from account data to PIN implies that anyone who can recover the institute key could generate PINs en masse, but even without that, the offset fields provide a shortcut that makes the system susceptible to a practical hack. The card’s magnetic stripe, specifically track 3, stores not only the primary account number but also three 4 digit correction offsets, denoted O1, O2, and O3. These offsets correspond to three pool keys KP1, KP2, and KP3 that are shared among European banks. When a foreign ATM uses KPi to decrypt the BCD block, the resulting hexadecimal digits (again positions 3–6) are added digit wise without carry to the offset Oi to produce the customer’s actual PIN. The offsets are necessary because different pool keys yield different intermediate results, and the bank wants the same PIN to work across all networks. However, these offsets are stored in plaintext on the magnetic stripe, and an attacker who performs a memory dump of the card’s track data obtains all three offsets simultaneously—this is a goldmine for subsequent cryptanalysis.

Chip List Segment 1 (click to expand)
ACTRANS FLASH Memory AC39LV010 AC39LV020 AC39LV040 AC39LV512
AKM SEEPROM AK6004AF AK6004AM AK6008AF AK6010AF AK6012AF AK6480AF AK6480AM AK93C45AV AK93C45BH AK93C55AV AK93C55BH AK93C65AV AK93C65BH AK93C75AV AK93C75BH AK93C85AM
ALLIANCE FLASH Memory AS29F040
AMD EEPROM Am2816A Am2817A EPROM Am27128A Am27128AF Am27128APC Am27128DC Am2716B Am2732B Am27C010 Am27C020 Am27C040 Am27C080 Am27C100 Am27C128 Am27C2048 Am27C256 Am27C4096 Am27C512 Am27C64 Am27H010 Am27HB010 Am27LV010 Am27LV010B FLASH Memory AM28F010 AM28F256 AM28F256A AM28F512 AM29F002B AM29F002BB AM29F002NB AM29F002NBB AM29F002T AM29F002BT AM29F002NT AM29F002NBT AM29F010 AM29F010A AM29F010B AM29F040 AM29F040B AM29F080B AM29LV001BB AM29LV001BT AM29LV002B AM29LV002BB AM29LV002T AM29LV002BT AM29LV004B AM29LV004BB AM29LV004T AM29LV004BT AM29LV008B AM29LV008BB AM29LV008T AM29LV008BT AM29LV010B AM29LV017D AM29LV040 AM29LV040B AM29LV081 AM29LV081B
AMIC FLASH Memory A29001T A290011T A29001U A290011U A29002T A290021T A29002U A290021U A29010 A29040 A29040B A49LF040TL A49LF040TX A49LF040ATL A49LF040ATX
ASD FLASH Memory AE29F1008 AE29F2008 AE49F2008
ATC SEEPROM AM93LC46 AM93LC56 AM93LC66 AM93LC86

Part 2 – Probabilistic Model and Bayesian Formulation

Our goal is to determine, for a given card with known offsets O1,j, O2,j, O3,j (where j = 1..4 denotes the digit position), the four PIN digits P1…P4 that are most probable. We treat each digit position independently, because the DES outputs are assumed to be uniformly distributed and mutually independent—a standard property of a good block cipher.

Let Xi,j be the random variable representing the j th decimalized hexadecimal digit obtained with pool key i. Without offset, the distribution of Xi,j is not uniform over 0–9 due to the letter to digit substitution: digits 0–5 appear with probability 1/16 each (from hexadecimal values 0–5), while digits 6–9 appear with probability 1/16 each (from hexadecimal values 6–9, but note that A–F map to 0–5, so effectively 0–5 have double weight? Let us recall the exact decimalization: The 16 hex digits are taken; each hex digit 0 9 becomes itself, A F become 0 5. So for a given position, the probability that the decimalized digit equals d is: if d ∈ {0,1,2,3,4,5}, it gets contributions from hex digit d (prob 1/16) and from hex digit d+10 (A F) – actually A=10 maps to 0, B=11 maps to 1, … F=15 maps to 5. So for d=0, contributions from hex 0 and A → 2/16 = 1/8. For d=1: from hex 1 and B → 1/8, etc. For d=6: only from hex 6 → 1/16, d=7: 1/16, d=8: 1/16, d=9: 1/16. So the distribution p(d) = 1/8 for d=0..5, and 1/16 for d=6..9. However, for the institute key, a leading zero is replaced by 1, so for the first digit position, the distribution is modified: p(0)=0, p(1)=1/8+1/16? Actually need to account. The original paper gives distributions (1) in the text. We will follow that.

The conditional probability of observing offset digit Oi,j given that the actual PIN digit is Pj is derived from the convolution of the decimalized DES output and the offset addition modulo 10 (without carry). Since the PIN is Pj = (Xi,j + Oi,j) mod 10, we have Xi,j = (Pj - Oi,j) mod 10. Therefore, the likelihood of observing a particular offset value given Pj is simply p((Pj - Oi,j) mod 10), where p(.) is the known distribution of decimalized DES digits. This observation is the linchpin of the entire attack, because it transforms the offset values into probabilistic evidence about the true PIN, and any attempt to crack the system must begin with this statistical reasoning.

Using Bayes’ theorem, the posterior probability of a candidate PIN digit Pj given the three observed offsets is proportional to the prior (assumed uniform over valid digits) times the product of the three likelihoods (since the three pool key outputs are independent). Specifically,
Pr(Pj | O1,j,O2,j,O3,j) ∝ ∏i=13 p((Pj - Oi,j) mod 10).
We ignore the normalization constant because we only need to find the digit that maximizes this product. For each position j, we compute this product for all ten possible digits (0–9, but for the first digit we exclude 0 due to the leading zero replacement rule in the institute key, so only 1–9). The digit with the highest product becomes our most likely candidate ^Pj. The overall most likely PIN ^P is the concatenation of the four individually most likely digits. This per digit independence is computationally convenient, but a more sophisticated attack could consider dependencies across positions if the DES key schedule introduced correlations—however, for this design, the assumption holds and makes the reverse engineering effort straightforward.

Chip List Segment 2 (click to expand)
ATMEL EEPROM AT28C010 AT28C04 AT28C040 AT28C04E AT28C04F AT28C1024 AT28C16 AT28C16E AT28C16F AT28C17 AT28C17E AT28C256 AT28C256F AT28C64 AT28C64B AT28C64X AT28HC04 AT28HC16 AT28HC16L AT28HC256 AT28HC256F AT28HC64B EPROM AT27BV010 AT27BV020 AT27BV040 AT27BV1024 AT27BV256 AT27BV400 AT27BV4096 AT27BV512 AT27BV520 AT27C010 AT27C010L AT27C020 AT27C040 AT27C080 AT27C1024 AT27C128 AT27C2048 AT27C256R AT27C4096 AT27C512 AT27C512R AT27C516 AT27C520 AT27C64 AT27HC64 AT27HC64L AT27LV010 AT27LV010A AT27LV020 AT27LV020A AT27LV040 AT27LV040A AT27LV1024 AT27LV4096 AT27LV512A AT27LV512R AT27LV520 FLASH Memory AT29BV010A AT29BV020 AT29BV040A AT29BV256 AT29C010A AT29C020 AT29C040A AT29C256 AT29C257 AT29C512 AT29LV010A AT29LV020 AT29LV040A AT29LV256 AT49BV001 AT49BV001A AT49BV001AN AT49BV001AT AT49BV001ANT AT49BV001N AT49BV001NT AT49BV001T AT49BV002 AT49BV002A AT49BV002AN AT49BV002AT AT49BV002ANT AT49BV002N AT49BV002NT AT49BV002T AT49BV010 AT49BV020 AT49BV040 AT49BV040T AT49BV512 AT49F002 AT49F002N AT49F002NT AT49F002T AT49F008A AT49F008AT AT49F010 AT49F020 AT49F040 AT49F1024 AT49F1025 AT49F512 AT49F516 AT49HBV010 AT49HF010 AT49HLV010 AT49LV001 AT49LV001N AT49LV001NT AT49LV001T AT49LV002 AT49LV002N AT49LV002NT AT49LV002T AT49LV010 AT49LV020 AT49LV040 AT49LV040T AT49LV1024 AT49LV1025 MCU AT87F51 AT87F52 AT87LV51 AT87LV52 AT89C1051 AT89C1051U AT89C2051 AT89C2051x2 AT89C4051 AT89C51 AT89C51-5 AT89C51RC AT89C52 AT89C52-5 AT89C55 AT89C55-5 AT89C55WD AT89LP2052 AT89LP4052 AT89LS51 AT89LS52 AT89LS53 AT89LS8252 AT89LV51 AT89LV52 AT89LV55 AT89S51 AT89S52 AT89S53 AT89S8252 AT89S8253 AT90S1200 AT90S1200A AT90S2313 AT90S2333 AT90LS2333 AT90S4414 AT90S4433 AT90LS4433 AT90S4434 AT90LS4434 AT90S8515 AT90S8535 AT90LS8535 ATmega16 ATmega16L ATmega162 ATmega162L ATmega162U ATmega162V ATmega165 ATmega165V ATmega169 ATmega169L ATmega169V ATmega32 ATmega32L ATmega323 ATmega323L ATmega325 ATmega325V ATmega3250 ATmega3250V ATmega48 ATmega48V ATmega8 ATmega8L ATmega8515 ATmega8515L ATmega8535 ATmega8535L ATtiny10 ATtiny10L ATtiny11 ATtiny11L ATtiny12 ATtiny12L ATtiny12V ATtiny15 ATtiny15L ATtiny26 ATtiny26L ATtiny28L ATtiny28V PLD/GAL ATF16V8 ATF16V8A ATF16V8B ATF16V8C ATF16V8D ATF16V8Z SEEPROM AT24C01 AT24C01A AT24C02 AT24C02A AT24C04 AT24C04A AT24C08 AT24C08A AT24C1024 AT24C128 AT24C16 AT24C16A AT24C21 AT24C256 AT24C32 AT24C32A AT24C512 AT24C64 AT24C64A AT24RF08CN AT24RF08BN AT24RF08CT AT24RF08BT AT25010 AT25010A AT25020 AT25020A AT25040 AT25040A AT25080 AT25080A AT25128 AT25160 AT25160A AT25256 AT25320 AT25320A AT25640 AT25640A AT25F512 AT25F512A AT25HP256 AT25HP512 AT34C02 AT34C02B AT45DB011B AT45DB021B AT45DB021 AT45DB021A AT45DB041 AT45DB041B AT45DB081B AT93C46 AT93C46R AT93C46W AT93C46A AT93C46C AT93C56 AT93C56W AT93C57 AT93C57W AT93C66 AT93C66W AT93C86

Part 3 – Computing the Most Likely PIN for a Given Card

To quantify the success probability of this guessing strategy, we first compute the per digit probability that ^Pj equals the true Pj for a given card with known offsets. That probability is exactly the maximum posterior value (after normalization). The paper reports that for each position, these probabilities can be as high as 24.8% for the first digit and around 17 18% for the others, based on the specific distributions. However, these are conditional on the offsets being known. For a random card (i.e., when we do not have a specific card’s offsets but we want to know the expected success rate over the entire population), we must simulate the joint distribution of offsets and PIN digits. The author describes a simulation over all 164 possible quadruples of hexadecimal digits (W,X,Y,Z) that determine the four relevant DES outputs for each of the three pool keys? Actually, the simulation enumerates all possible combinations of the four hexadecimal digits that appear in the DES result for a given pool key? The description is slightly condensed, but the idea is to generate all possible cards by varying the underlying DES outputs (which are uniform and independent) and computing the corresponding PIN and offsets deterministically.

For each simulated card, we apply the same maximum likelihood rule to guess the PIN and count how often the guess matches the true digit. The resulting per digit success probabilities are given as approximately:
• For position 1 (leading zero disallowed): about 24.8% (compared to random guess 1/9 ≈ 11.1%)
• For positions 2,3,4: about 17.6%, 17.6%, 17.6% (compared to random 10%)
Multiplying these gives a combined success probability of about 0.0023346 = 0.233% for a single guess of the most likely PIN. Since an attacker can try three different PINs before the card is blocked, and the second and third most likely candidates have similar (slightly lower) probabilities, the overall success rate for three attempts is roughly three times that, i.e., about 0.7% or 1 in 150. This is a dramatic improvement over a naive brute force attack, which would have only 3/9000 ≈ 0.033% success, because the offsets effectively leak information that reduces the entropy from about 13 bits to about 7 bits.

Now, consider the broader security implications. The offsets are stored unencrypted on the magnetic stripe, which can be read by any skimming device. A thief who obtains the track data can perform the above calculation offline and prioritize which cards to test at an ATM. Moreover, a sophisticated adversary could combine this statistical method with firmware extraction from the ATM itself to obtain the pool keys, thereby eliminating the need for offsets altogether—but that is a separate, more invasive attack. The author also notes that the backup pool keys KP2 and KP3 are intended to replace a compromised KP1, but the offsets for all three are present on every card, so even if KP1 is changed, the attacker can still use the offsets for KP2 and KP3 to guess the PIN, because the same PIN must satisfy all three offset equations. In fact, the presence of three independent offsets only strengthens the attacker’s posterior probability, as each additional offset provides an independent constraint—this is a classic case where redundancy intended for fault tolerance actually facilitates an attack.

Chip List Segment 3 (click to expand)
BOOKLY FLASH Memory AC39VF010 AC39VF020 AC39VF040 AC39VF512
BRIGHT FLASH Memory BM29F040
BSI SRAM BS62LV1024
CATALYST EEPROM CAT28C16A CAT28C16AI CAT28C17A CAT28C17AI CAT28C256 CAT28C257 CAT28C513 CAT28C64B CAT28lv64 CAT28lv65 EPROM CAT27010 CAT27128A CAT27128AP CAT27512 CAT2764A FLASH Memory CAT28F001B CAT28F001T CAT28F010 CAT28F020 CAT28F512 SEEPROM CAT1021 CAT1022 CAT1023 CAT1024 CAT1025 CAT1026 CAT1027 CAT1161 CAT1162 CAT24AC128P CAT24AC128J CAT24AC128K CAT24C00 CAT24C00P CAT24C00J CAT24C00U CAT24C01 CAT24C01W CAT24C01Y CAT24C01VP2 CAT24C01BP CAT24C01BJ CAT24C01BU CAT24C01BR CAT24C02 CAT24C02W CAT24C02Y CAT24C02VP2 CAT24C03 CAT24C03W CAT24C03Y CAT24C03VP2 CAT24C04 CAT24C04W CAT24C04Y CAT24C04VP2 CAT24C05 CAT24C05W CAT24C05Y CAT24C05VP2 CAT24C08 CAT24C08W CAT24C08Y CAT24C08VP2 CAT24C128 CAT24C128W CAT24C128Y CAT24C16 CAT24C16W CAT24C16Y CAT24C16VP2 CAT24C21 CAT24C21P CAT24C21J CAT24C21U CAT24C21R CAT24C256 CAT24C256W CAT24C32 CAT24C32W CAT24C32Y CAT24C32ZD2 CAT24C64 CAT24C64W CAT24C64Y CAT24C64ZD2 CAT24FC32 CAT24FC32P CAT24FC32J CAT24FC32U CAT24WC01 CAT24WC01P CAT24WC01J CAT24WC01U CAT24WC01R CAT24WC02 CAT24WC02P CAT24WC02J CAT24WC02U CAT24WC02R CAT24WC03 CAT24WC03P CAT24WC03J CAT24WC03U CAT24WC03R CAT24WC04 CAT24WC04P CAT24WC04J CAT24WC04U CAT24WC04R CAT24WC05 CAT24WC05P CAT24WC05J CAT24WC05U CAT24WC08 CAT24WC08P CAT24WC08J CAT24WC128 CAT24WC128P CAT24WC128J CAT24WC128K CAT24WC129 CAT24WC129P CAT24WC129J CAT24WC16 CAT24WC16P CAT24WC16J CAT24WC256 CAT24WC256P CAT24WC256K CAT24WC257 CAT24WC257P CAT24WC257K CAT24WC32 CAT24WC32P CAT24WC32J CAT24WC32K CAT24WC33 CAT24WC33P CAT24WC33J CAT24WC33K CAT24WC64 CAT24WC64P CAT24WC64J CAT24WC65 CAT24WC65P CAT24WC65J CAT24WC66 CAT24WC66P CAT24WC66J CAT25010 CAT25010P CAT25010PI CAT25010S CAT25010SI CAT25010U CAT25010UI CAT25010R CAT25020 CAT25020P CAT25020PI CAT25020S CAT25020SI CAT25020U CAT25020UI CAT25020R CAT25040 CAT25040P CAT25040PI CAT25040S CAT25040SI CAT25040U CAT25040UI CAT25040R CAT25320 CAT25320Y CAT25320V CAT25C01 CAT25C01P CAT25C01PI CAT25C01S CAT25C01SI CAT25C01U CAT25C01UI CAT25C01R CAT25C01U14 CAT25C02 CAT25C02P CAT25C02PI CAT25C02S CAT25C02SI CAT25C02U CAT25C02UI CAT25C02R CAT25C02U14 CAT25C03 CAT25C03P CAT25C03PI CAT25C03S CAT25C03SI CAT25C03U CAT25C03UI CAT25C03R CAT25C03U14 CAT25C04 CAT25C04P CAT25C04PI CAT25C04S CAT25C04SI CAT25C04U CAT25C04UI CAT25C04R CAT25C04U14 CAT25C05 CAT25C05P CAT25C05PI CAT25C05S CAT25C05SI CAT25C05U CAT25C05UI CAT25C05R CAT25C05U14 CAT25C08 CAT25C08P CAT25C08PI CAT25C08S CAT25C08SI CAT25C08U CAT25C08UI CAT25C08R CAT25C08U14 CAT25C11 CAT25C11P CAT25C11PI CAT25C11S CAT25C11SI CAT25C11U CAT25C11UI CAT25C11R CAT25C128 CAT25C128P CAT25C128PI CAT25C128S CAT25C128SI CAT25C128U14 CAT25C128S16 CAT25C16 CAT25C16P CAT25C16PI CAT25C16S CAT25C16SI CAT25C16U CAT25C16UI CAT25C16R CAT25C16U14 CAT25C17 CAT25C17P CAT25C17PI CAT25C17S CAT25C17SI CAT25C17U CAT25C17UI CAT25C17R CAT25C17U14 CAT25C256 CAT25C256P CAT25C256PI CAT25C256S CAT25C256SI CAT25C256U14 CAT25C256S16 CAT25C32 CAT25C32P CAT25C32PI CAT25C32S CAT25C32SI CAT25C32U14 CAT25C33 CAT25C33P CAT25C33PI CAT25C33S CAT25C33SI CAT25C33U14 CAT25C64 CAT25C64P CAT25C64PI CAT25C64S CAT25C64SI CAT25C64U14 CAT25C65 CAT25C65P CAT25C65PI CAT25C65S CAT25C65SI CAT25C65U14 CAT34AC02 CAT34W02 CAT34WC02 CAT93C46 CAT93C46P CAT93C46PI CAT93C46S CAT93C46SI CAT93C46U CAT93C46UI CAT93C46K CAT93C56 CAT93C56P CAT93C56PI CAT93C56S CAT93C56SI CAT93C56U CAT93C56UI CAT93C57 CAT93C57P CAT93C57PI CAT93C57S CAT93C57SI CAT93C57U CAT93C57UI CAT93C66 CAT93C66P CAT93C66PI CAT93C66S CAT93C66SI CAT93C66U CAT93C66UI CAT93C86 CAT93C86P CAT93C86PI CAT93C86S CAT93C86SI CAT93C86U CAT93C86UI CAT93HC46 CAT93HC46P CAT93HC46PI CAT93HC46S CAT93HC46SI CAT93HC46U CAT93HC46UI

Part 4 – Expected Success over Random Cards and Comparison

The original paper does not discuss physical attacks, but we can extend the reasoning. If an attacker can perform a side channel analysis or a brute force search on the institute key KI using specialized hardware, then the entire system collapses. However, even without that, the offset based probabilistic method offers a practical and low cost attack. For instance, by reverse engineering the card’s magnetic stripe encoding format, one can write a simple script to parse the offsets from a raw dump of track 3, and then compute the ranked list of candidate PINs in milliseconds. This is far easier than attempting to crack the DES key, which would require enormous computational resources. The author estimates that the cost of a brute force DES key search with custom chips is a valid concern, but the offset attack is essentially free once the card data is obtained.

We should also examine the assumption of uniform and independent DES outputs. DES is a strong cipher, and the decimalization process does introduce some non uniformity, but the key point is that the offsets are not random noise—they are deterministically related to the PIN and the pool key outputs. If the pool keys were kept secret and never used across multiple banks, the offsets would be meaningless to an outsider, but the European banking consortium chose to share those keys, thereby creating a systemic vulnerability that invites a coordinated attack across multiple institutions. The backup plan of switching to KP2 and rewriting O1 on all cards at the next ATM visit is cumbersome and does not address the fact that O2 and O3 are already present. Moreover, if an attacker obtains a card before the switch, they can record the old offsets and later use them even after the switch, because the PIN remains the same. This oversight reveals a fundamental misunderstanding of information theory by the system designers—they treated offsets as mere correction values, not as side channels that enable a probabilistic unlock of the PIN.

To further illustrate the attack’s efficacy, let us compute the expected number of guesses needed to exceed a given success probability. The ranked list of all possible PINs (9000 candidates) can be sorted by their posterior probabilities. The top candidate has 0.233% success, the second and third each have slightly lower values, so the cumulative success after three attempts is about 0.7%. After ten attempts (if the card were not blocked), the success would approach a few percent. However, the ATM’s three attempt limit is a deterrent, but a patient attacker could test the top three on many cards, knowing that roughly 1 in 150 cards will be compromised—a profitable return for a skimming operation. The author compares this to a hypothetical good system with 9000 equally likely PINs, where three random guesses would succeed with 3/9000 ≈ 0.033%. The ec PIN system thus performs worse than a three digit PIN system (which has 1000 possibilities, giving 3/1000 = 0.3% for three attempts) — indeed, the calculated 0.7% is even higher than that. This is a striking result: the addition of offsets has effectively reduced the security level below that of a much shorter PIN, and any security audit would flag this as a critical flaw that demands immediate remediation.

Chip List Segment 4 (click to expand)
CYPRESS EPROM CY27C010 CY27C020 CY27C040 CY27C256A CY27C512 CY27H010 CY27H512 SRAM CY7C185
DALLAS EEPROM DS1220AB DS1220AD DS1220Y DS1225Y DS1230AB DS1230Y DS1235AB DS1235Y DS1230W DS1245AB DS1245EE DS1245P DS1245Y DS1245W DS12887 DS12C887 MCU DS89C420 SEEPROM DS2433 SRAM DS1643 DS2016
EON FLASH Memory EN29F002B EN29F002AB EN29F002NB EN29F002ANB EN29F002NT EN29F002ANT EN29F002T EN29F002AT EN29F010 EN29F040 EN29F040A EN29LV010 EN29LV040 EN29LV040A
EXEL EEPROM XL2804A XL2816A XL2816B XL2817A XL28C16A XL28C16B XLS28C16AP
FAIRCHILD EPROM FM27C010 FM27C040 FM27C512 FM27LV010 NM27C010 NM27C020 NM27C040 NM27C128 NM27C210 NM27C240 NM27C256 NM27C512 NM27LV010 NM27LV010B NMC27C128B NMC27C16B NMC27C16BQ NMC27C32 NMC27C32BQ NMC27C64 SEEPROM FM24C02U FM24C03U FM24C04U FM24C05U FM24C08U FM24C09U FM24C128 FM24C16U FM24C17U FM24C256 FM24C32U FM24C64 FM24U02 FM25C020U FM25C040U FM25C041U FM25C160U FM25C640U FM93C46 FM93C46A FM93C56 FM93C56A FM93C66 FM93C66A FM93C86 FM93C86A NM24C02 NM24C03 NM24C04 NM24C05 NM24C08 NM24C09 NM24C16 NM24C17
FORCE TECHNOLOGIES SEEPROM FT24C01 FT24C01A FT24C02 FT24C02A FT24C04 FT24C04A FT24C08 FT24C08A FT24C16 FT24C16A
FUJITSU EPROM MBM271001 MBM27128 MBM27C1000 MBM27C1001 MBM27C1001A MBM27C1024 MBM27C2000 MBM27C2001 MBM27C2048 MBM27C4096 MBM27C512 MBM27C512P FLASH Memory MBM29F002B MBM29F002NB MBM29F002T MBM29F002NT MBM29F040A MBM29F040C MBM29LV002B MBM29LV002T MBM29LV004B MBM29LV004BB MBM29LV004T MBM29LV004BT MBM29LV008B MBM29LV008T MBM29LV016B MBM29LV016T MBM29LV017 SRAM MB84256

Part 5 – Attack Vectors beyond Statistical Guessing

Beyond the statistical attack, the paper mentions that there are techniques to obtain more than three attempts, for instance by exploiting ATM software bugs or by using multiple ATMs simultaneously before the card gets blocked network wide. A determined hacker could also attempt to crack the offline verification mechanism if they manage to extract the firmware from an ATM and identify the PIN checking routine—this would allow unlimited trials without triggering the block counter. The author refrains from detailing such methods, but they are valid additional concerns.

In our expanded analysis, we note that the combination of the offset based probabilistic guessing with social engineering or physical skimming makes the ec PIN system highly vulnerable. For example, an attacker who also obtains the customer’s account number (which is printed on the card) can correlate with other data sources to further narrow down the possibilities, though the offset method already provides the dominant advantage. The original work concludes that the success probability for a single most likely PIN is 0.233%, and for three attempts about 0.7%. We reproduce these numbers and add that the variance across cards is low because the offsets are uniformly distributed over all possible values due to the uniform DES outputs. Therefore, the expected success rate over a large population is stable.

To put this in perspective, a random thief without this knowledge would have a negligible chance, but with a simple script that implements the Bayes calculation, the odds increase by a factor of about 20—this is a classic example of how reverse engineering of a proprietary algorithm can yield a practical advantage. We also consider the possibility that the bank might change the PIN generation algorithm or introduce user selectable PINs in later systems. Indeed, modern EMV standards often allow user selection, but legacy systems persist in many regions. Security practitioners should be aware that even if the DES keys are rotated, the offset information remains valid for the lifetime of the card, because the PIN is fixed—thus, any attempt to patch the system without re issuing all cards is futile. The backup pool keys are also stored on the stripe, so an attacker can always use the most favorable combination of offsets. A more robust design would have used a one way function to derive the PIN from the account number without any externally visible correction values, but that would have required all ATMs to share the same key, which was deemed impractical for inter bank operations.

Chip List Segment 5 (click to expand)
GENERAL(GI) EEPROM 28C04A 28C16A 28C17A EPROM 27C128 27C512
HA SRAM HA24257AKB
HITACHI EEPROM HN48016P HN58C256FP HN58C256P HN58C65FP HN58C65P HN58C66P EPROM HN27128A HN27128AG HN27128AP HN27128G HN27128P HN27512 HN27512G HN27512P HN27C101 HN27C101AG HN27C101AP HN27C101G HN27C101P HN27C1024HCC HN27C1024HCP HN27C1024HG HN27C301 HN27C301AP HN27C301AFP HN27C4001G HN27C4001TT HN27C4096AG HN27C4096CC HN27C4096CP HN27C4096G HN27C512 HN27C512G HN4827128 HN4827128G HN4827128P SRAM HM6116LK HM62256 HM6264LP HM628128
HOLTEK EPROM HT27C010 HT27C020 HT27C040 HT27C512 HT27LC010 HT27LC020 HT27LC512 MCU HT46R22 HT46C22 HT46R23 HT46C23 HT46R46 HT46R47 HT46R64 HT48R05A HT48C05A HT48R06A HT48C06A HT48R10A HT48C10A HT48R30A HT48R50A HT48C50A HT48RA0A HT48CA0A SEEPROM HT24LC01 HT24LC02 HT24LC04 HT24LC08 HT24LC16 HT93LC46 HT93LC56 HT93LC66
HYNIX MCU GMS97C51 GMS97C52 GMS97L51 GMS97L52 HMS99C51S HMS99C52S HMS99C54S HMS99C56S HMS99C58S
HYNIX(HYUNDAI) FLASH Memory HY29F002T HY29F040A HY29F040 HY29F040T
HYUNDAI SRAM HY6264A

Part 6 – Countermeasures and Design Flaws

In terms of countermeasures, the obvious fix is to eliminate the offsets or encrypt them with a card specific key. However, that would require changes to the ATM network and all cards. In the meantime, banks can monitor for unusual patterns of PIN attempts—e.g., if a thief tries the top three candidates on many cards, the failure rate will be high (since 99.3% of attempts fail), but the success rate is still non negligible. A proactive defense could involve temporarily blocking cards after a single incorrect attempt if the transaction originates from a suspicious location, but that would inconvenience legitimate users.

The paper does not propose specific countermeasures, but we note that the fundamental issue is the public availability of offsets. Any system that stores verifier information on the token itself is inherently susceptible to offline analysis, and this case is no exception—it is a textbook lesson in cryptographic protocol design. Finally, we acknowledge the contributions of Bodo and Ulf Möller, who assisted the author with simulation and validation. Their insights helped confirm that the per digit probabilities are indeed as high as reported.

We also note that the attack does not require any hardware modifications—it is purely algorithmic, so even a novice script kiddie can implement it after reading this analysis. The only prerequisite is the ability to read the magnetic stripe, which is trivial with off the shelf skimmers. Given the widespread availability of such devices, the ec PIN system represents a significant security gap that should have been addressed decades ago.

To summarize, the probability based guessing strategy described here exploits the deterministic relationship between offsets and PIN digits, leveraging the non uniform decimalization distribution to achieve a success rate of about 0.7% in three attempts—far exceeding the 0.033% expected from a well designed system. This attack can be further refined by incorporating prior knowledge about common account numbers or by using multiple cards from the same bank to infer the institute key via differential analysis, but that goes beyond the scope of this text. The author also warns about the potential for brute force DES key recovery using specialized hardware, which would completely break the system. However, the offset attack is more immediate and requires far less computational effort, making it the preferred vector for a street level criminal.

Chip List Segment 6 (click to expand)
ICSI MCU IS89C54 IS89C58 IS89C64 IS89E54 IS89E58 IS89E64
ICT EPROM 27CX010
IDT SRAM IDT6116SA IST6116SA
INTEL EEPROM D2816 D2816A D2817A EPROM A68C257 D27010 D27128A D27128B D27256 D27512 D2764A D27C010 D27C010A D27C020 D27C040 D27C100 D27C128 D27C128A D27C210 D27C220 D27C240 D27C256 D27C512 D27C64 D27C64A D27S512 D87C257 N27128A N27C020 P27128A P27128B P27256 P2764A P27C64 FLASH Memory E28F001BXB E28F001BXT E28F004S5 E28F008S5 E28F008SA E28F010 E28F016S5 E28F020 E82802AA E82802AB E82802AC N82802AA N82802AB N82802AC MCU 87C51FA 87C51FB 87C51FC
ISSI EPROM IS27C010 IS27C020 IS27C512 IS27HC010 IS27HC020 IS27HC512 IS27LV010 IS27LV020 IS27LV512 FLASH Memory IS28F010 IS28F010A SEEPROM IS24C01 IS24C01B IS24C02 IS24C02A IS24C02B IS24C04 IS24C04A IS24C08 IS24C08A IS24C128 IS24C128A IS24C16 IS24C16A IS24C256 IS24C256A IS24C32 IS24C32A IS24C32B IS24C64 IS24C64A IS24C64B IS24L128 IS24L256 IS25C01-2PI IS25C01-2GI IS25C01-2ZI IS25C01-2PLI IS25C01-2GLI IS25C01-2ZLI IS25C01-3PLA3 IS25C01-3GLA3 IS25C01-3ZLA3 IS25C02-2PI IS25C02-2GI IS25C02-2ZI IS25C02-2PLI IS25C02-2GLI IS25C02-2ZLI IS25C02-3PLA3 IS25C02-3GLA3 IS25C02-3ZLA3 IS25C04-2PI IS25C04-2GI IS25C04-2ZI IS25C04-2PLI IS25C04-2GLI IS25C04-2ZLI IS25C04-3PLA3 IS25C04-3GLA3 IS25C04-3ZLA3 IS25C08-2PI IS25C08-2GI IS25C08-2ZI IS25C08-2PLI IS25C08-2GLI IS25C08-2ZLI IS25C08-3PLA3 IS25C08-3GLA3 IS25C08-3ZLA3 IS25C128-2PI IS25C128-2GI IS25C128-2WI IS25C128-2PLI IS25C128-2GLI IS25C128-2WLI IS25C128-3PA3 IS25C128-3GA3 IS25C128-3WA3 IS25C128-3PLA3 IS25C128-3GLA3 IS25C128-3WLA3 IS25C16-2PI IS25C16-2GI IS25C16-2ZI IS25C16-2PLI IS25C16-2GLI IS25C16-2ZLI IS25C16-3PLA3 IS25C16-3GLA3 IS25C16-3ZLA3 IS25C256-2PI IS25C256-2GI IS25C256-2WI IS25C256-2PLI IS25C256-2GLI IS25C256-2WLI IS25C256-3PA3 IS25C256-3GA3 IS25C256-3WA3 IS25C256-3PLA3 IS25C256-3GLA3 IS25C256-3WLA3 IS25C32 IS25C32-2PI IS25C32-2GI IS25C32-3PI IS25C32-3GI IS25C32A-2PI IS25C32A-2ZI IS25C32A-2GI IS25C32A-2PLI IS25C32A-2GLI IS25C32A-2ZLI IS25C32A-3PLA3 IS25C32A-3ZLA3 IS25C32A-3GLA3 IS25C64 IS25C64-2PI IS25C64-2GI IS25C64-3PI IS25C64-3GI IS25C64A-2PI IS25C64A-2ZI IS25C64A-2GI IS25C64A-2PLI IS25C64A-2GLI IS25C64A-2ZLI IS25C64A-3PLA3 IS25C64A-3ZLA3 IS25C64A-3GLA3 IS34C02 IS93C46A IS93C46B IS93C46D IS93C56 IS93C56A IS93C66 IS93C66A IS93C76A IS93C86A SRAM IS61C1024 IS61C64B IS62C256
LATTICE PLD/GAL GAL16LV8 GAL16LV8C GAL16LV8D GAL16LV8Z GAL16V8 GAL16V8Z GAL16V8A GAL16V8B GAL16V8C GAL16V8D GAL20V8 GAL20V8Z GAL20V8A GAL20V8B GAL20V8C GAL20V8D GAL22V10 GAL22V10B GAL22V10C GAL22V10D
LINKAGE FLASH Memory LG29C020 LG29C040

Part 7 – Conclusion and Final Remarks

We conclude that the ec PIN generation algorithm was fundamentally flawed, and any remaining deployments should be migrated to a secure, user selected PIN scheme with proper cryptographic protection. Until then, the risk remains, and security researchers continue to use this case as a cautionary tale in the dangers of over engineering without considering adversarial modeling. The combination of deterministic PIN derivation, public pool keys, and plaintext offsets creates a perfect storm for probabilistic inference. Our analysis has shown that a thief with basic mathematical skills and a card reader can achieve a success rate of nearly 0.7% within three attempts, which is more than twenty times higher than what a random guess would yield in a well designed system.

Moreover, the same reasoning can be applied to other legacy banking systems that store similar correction data, so the lessons here extend far beyond the German ec card. The author’s original work, though concise, laid the groundwork for understanding how seemingly harmless offset values can be exploited. We have expanded that foundation by quantifying the expected gain and by discussing practical scenarios where firmware extraction or side channel leaks could further amplify the threat. It is worth repeating that the backup pool keys do not mitigate the issue; they merely provide additional data points for the attacker. In fact, the more offsets are stored, the higher the posterior probability becomes, turning a safety mechanism into an enabler for a successful hack.

The banking industry has since moved to more secure standards, but many older cards and ATMs may still be in use, especially in regions with slow technology refresh cycles. Therefore, security auditors should actively check for such vulnerabilities during penetration tests, and they should consider using the presented algorithm as a benchmark for assessing PIN generation strength. Finally, we thank the original authors for their insightful analysis, which continues to inform modern cryptographic best practices. The entire exercise demonstrates that a clever statistical attack, even without breaking the cipher, can undermine a system’s confidentiality—a powerful reminder that security is a holistic property, not just a matter of key length.

Chip List Segment 7 (click to expand)
LINKSMART FLASH Memory LST28001 LST28002 LST28004 SEEPROM L24C02 L24C04
MACRONIX EPROM MX26C512A MX27C020 MX27C1000 MX27C1000A MX27C1001 MX27C1024 MX27C2048 MX27C256 MX27C4000 MX27C4096 MX27C512 MX27C8000 MX27L020 MX27L1000 MX27L4000 FLASH Memory MX26LV040 MX28F1000P MX28F2000P MX28F2000T MX29F001B MX29F001T MX29F002B MX29F002NB MX29F002T MX29F002NT MX29F004B MX29F004T MX29F040 MX29LV040
MEGAWIN FLASH Memory MM29F040 MM36SB010E MM36SB010S MM36SB020E MM36SB020S MCU MPC89LE516¡Á2 MPC89LE556¡Á2
MICROCHIP EEPROM 2804 2816 2817 28C17AF 28C256 28C256F EPROM 27C128A 27C64 27C64A 27HC64 27HC64L MCU PIC12C508 PIC12C508A PIC12CE518 PIC12C509 PIC12C509A PIC12CR509A PIC12C50R9A PIC12CE519 PIC12F508 PIC12F509 PIC12F629 PIC12F675 PIC16C505 PIC16C52 PIC16C54 PIC16C54A PIC16C54B PIC16C54C CF745 PIC16CR54A PIC16CR54B PIC16CR54C PIC16C55 PIC16C55A PIC16C56 PIC16C56A PIC16CR56A PIC16C57 CF775 PIC16C57C PIC16CR57B PIC16CR57C PIC16C58A PIC16C58B PIC16CR58A PIC16CR58B PIC16C61 PIC16C62 PIC16C620 PIC16C620A PIC16CR620 PIC16CR620A PIC16C621 PIC16C621A PIC16C622 PIC16C622A PIC16C62A PIC16C62B PIC16LC62B PIC16C63 PIC16C63A PIC16CR63 PIC16C64 PIC16C64A PIC16C65 PIC16C65A PIC16C65B PIC16C66 PIC16C67 PIC16C71 PIC16C710 PIC16C711 PIC16C712 PIC16C716 PIC16C72 PIC16CR72 PIC16C72A PIC16LC72A PIC16C73 PIC16C73A PIC16LC73A PIC16C73B PIC16C74 PIC16C745 PIC16C74A PIC16C74B PIC16C76 PIC16C765 PIC16C77 PIC16CE623 PIC16CE624 PIC16LCE624 PIC16CE625 PIC16CR65 PIC16F54 PIC16F57 PIC16F627A PIC16LF627A PIC16F628A PIC16LF628A PIC16F630 PIC16F676 PIC16F685 PIC16F687 PIC16F716 PIC16F72 PIC16F73 PIC16LF73 PIC16F74 PIC16F76 PIC16F77 PIC16F84A PIC16F870 PIC16F871 PIC16F872 PIC16F873 PIC16F873A PIC16F874 PIC16F874A PIC16F876 PIC16F876A PIC16F877 PIC16F877A SEEPROM 24AA00 24AA00T 24AA01 24AA02 24AA04 24AA08 24AA128 24AA16 24AA256 24AA32 24AA512 24AA64 24C00 24C01A 24C01C 24C02A 24C02C 24C04A 24FC1025 24FC128 24FC256 24FC512 24LC00 24LC01B 24LC02B 24LC04B 24LC08B 24LC128 24LC16 24LC16B 24LC164 24LC21A 24LC256 24LC32A 24LC512 24LC64 25AA040 25AA080 25AA160 25AA320 25AA640 25C040 25C080 25C160 25C320 25LC040 25LC080 25LC160 25LC320 25LC640 93AA46 93AA46B 93AA46C 93AA46A 93AA56 93AA56B 93AA56C 93AA56A 93AA66 93AA66B 93AA66C 93AA66A 93AA76 93AA76B 93AA76C 93AA76A 93AA86 93AA86B 93AA86C 93AA86A 93C46 93C46B 93C46C 93C46A 93C56 93C56B 93C56C 93C56A 93C66 93C66B 93C66C 93C66A 93C76 93C76B 93C76C 93C76A 93C86 93C86B 93C86C 93C86A 93LC46 93LC46B 93LC46C 93LC46A 93LC56 93LC56B 93LC56C 93LC56A 93LC56BX 93LC66 93LC66B 93LC66C 93LC66A 93LC76 93LC76B 93LC76C 93LC76A 93LC86 93LC86B 93LC86C 93LC86A

Interested in Our Firmware Extraction Services?

Whether you need to recover locked firmware, analyze security vulnerabilities, or perform reverse engineering, our team is ready to help.

Contact Us for a Quote