Skip to content
MagnaNet Network MagnaNet Network

  • Home
  • About Us
    • About Us
    • Advertising Policy
    • Cookie Policy
    • Affiliate Disclosure
    • Disclaimer
    • DMCA
    • Terms of Service
    • Privacy Policy
  • Contact Us
  • FAQ
  • Sitemap
MagnaNet Network
MagnaNet Network

Laser Fault Injection Attack Exposes Critical Vulnerability in Tangem Crypto Wallets, Ledger’s Donjon Team Reveals

Cahyo Dewo, July 12, 2026

A significant security vulnerability has been uncovered in Tangem crypto wallet cards, demonstrating that a sophisticated physical attack utilizing precisely timed laser pulses can bypass the card’s password protection. Researchers from Ledger’s Donjon security team have successfully demonstrated how this technique, known as laser fault injection (LFI), can reset a Tangem card’s password to any value chosen by an attacker, thereby granting complete control over the associated cryptocurrency holdings. This discovery highlights the persistent challenges in securing hardware wallets against advanced physical tampering, even those boasting high-grade security certifications.

The Discovered Vulnerability: Laser Fault Injection

The core of the vulnerability lies within the Samsung S3D232A secure element chip embedded in every Tangem wallet card. Donjon’s researchers found that by directing a laser pulse at a specific point on the chip at an exact moment during its operation, they could induce a transient fault. This fault causes the chip to misinterpret its current state, specifically leading it to believe it is in "recovery mode" when it is not. In this manipulated state, the card’s standard password reset function, intended for use with a secondary linked card, can be exploited to set a new password without requiring the old one or the presence of a backup card. Once the password is reset, the attacker gains full control, enabling them to transfer all stored cryptocurrency assets out of the wallet.

This is not a trivial or easily reproducible attack. Donjon estimates the cost of the necessary laboratory equipment, including specialized lasers and sensitive measuring gear, to be approximately $250,000. Furthermore, the attack requires physical possession of the Tangem card, which must be carefully cut open to expose the underlying chip. This invasive process leaves unmistakable physical damage, making it impossible for an attacker to discreetly compromise a card and return it to its owner unnoticed. Crucially, the nature of the attack means it cannot be performed remotely over the internet, offering a degree of protection for cards still in the owner’s possession.

Unpacking the Tangem Wallet and its Security Architecture

Tangem wallets are designed for simplicity and security, resembling standard bank cards. Users interact with them by tapping the card against a smartphone running a companion application. At the heart of each card is a Samsung S3D232A secure element chip, which is specifically engineered to resist tampering. This chip holds the wallet’s private cryptographic keys, which are never meant to leave the secure environment of the chip itself. The secure element boasts an EAL6+ certification (Evaluation Assurance Level 6+), a high-grade security rating that signifies a robust level of assurance against sophisticated attacks. The intended security model for Tangem cards relies on two primary layers of protection: physical possession of the card and knowledge of its password (PIN).

Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched

The flaw, however, targets a specific logical process within the chip’s firmware related to password management. Tangem’s design allows for password recovery by holding two linked cards together. During this process, the card performs an internal check to verify if it is legitimately in recovery mode. The laser fault injection attack precisely interferes with this critical check, causing it to fail in a way that tricks the card into accepting a new password without the usual authentication prerequisites. This bypass renders the usual security mechanisms, including the requirement for the old password or a second card, ineffective under the specific conditions of the LFI attack. Even if a user has disabled the recovery feature, the underlying check still runs, making all cards susceptible.

The Mechanics of the Laser Attack: Bypassing Password Protection

The technique employed by Donjon, laser fault injection, is a well-known method in hardware security research for inducing transient errors in integrated circuits. Unlike traditional side-channel attacks that passively observe power consumption or electromagnetic emissions, LFI actively manipulates the chip’s behavior by disrupting its internal operations. By delivering a focused burst of light (typically from a high-power laser) at a precise location and moment, researchers can temporarily alter the electrical characteristics of transistors, leading to incorrect computations or conditional jumps in the chip’s execution flow.

In the case of the Tangem wallet, Donjon’s team meticulously mapped the internal architecture of the Samsung S3D232A chip. This extensive upfront work involved detailed reverse engineering and analysis to identify the exact physical location on the silicon where the password recovery check is executed. Once this "fault injection point" was identified, the researchers developed a precise timing mechanism to fire the laser pulse at the microsecond when the chip performs the critical "is this card in recovery mode?" verification. The momentary disturbance caused by the laser pulse causes the boolean logic of this check to flip, effectively making the card believe it is in recovery mode, regardless of its actual state. This subtle but critical manipulation then allows the subsequent SetPin command to accept a brand-new password without any further authentication.

The sophistication of this attack cannot be overstated. It demands not only specialized equipment but also a profound understanding of chip-level hardware and firmware interactions. Donjon reports that once the setup was calibrated and the precise parameters locked in, the attack proved consistently successful on every Tangem card they tested, with each successful compromise taking approximately two hours. This efficiency, post-calibration, underscores the systematic nature of the vulnerability once the complex initial setup is complete.

The Impracticality and Permanence of the Flaw

Despite the technical prowess demonstrated by Donjon, the immediate practical risk for the vast majority of Tangem users remains low. The exorbitant cost of the equipment, the highly specialized skills required, and the inherent invasiveness of the attack—which irrevocably damages the card—create significant barriers for all but the most determined and well-funded adversaries. This is not an attack that can be carried out by a casual thief or via remote means. An attacker would need to physically acquire a card, invest heavily in a laboratory setup, and then spend considerable time to compromise it.

Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched

However, the permanence of the flaw presents a more fundamental concern. Tangem markets its cards as unchangeable, highlighting the inability to update firmware as a security feature, preventing remote tampering. While this design choice indeed protects against certain types of attacks, it simultaneously means that any vulnerabilities discovered within the card’s firmware, like this laser fault injection flaw, cannot be patched or corrected. Every Tangem card ever sold carries this inherent susceptibility. As the Donjon researchers succinctly put it, "there’s no patch, but the attack is physical and invasive." This immutable design, while offering benefits in some contexts, becomes a significant liability when a critical flaw is found in the underlying code.

Donjon reported the flaw to Tangem on February 10, 2026. [Assuming this is a typo and refers to a past date, e.g., 2024, given the journalistic context of reporting a discovery.] This responsible disclosure allowed Tangem time to prepare a response before the public announcement of the vulnerability.

Official Responses: Tangem vs. Ledger’s Donjon

The disclosure of the vulnerability prompted a public response from Tangem, which sought to contextualize and downplay the severity of the findings. In its official statement, Tangem characterized Donjon’s findings as a "lab-only physical method" that is not unique to its cards but rather a general vulnerability applicable to secure element chips across the industry. Tangem also highlighted the competitive relationship between itself and Ledger, suggesting that Donjon’s research might be influenced by Ledger’s position as a major rival in the hardware wallet market.

Tangem’s sharpest argument centered on the economic impracticality of the attack. The company pointed out that its cards contain no identifying information about the owner or the value of the assets they hold. Therefore, an attacker investing $250,000 and destroying cards in the process would have no prior knowledge of whether a stolen card is worth $50 or $50 million. This uncertainty, coupled with the high cost and effort, makes the attack economically irrational for most potential adversaries. Tangem further asserted that no funds have ever been lost to a laser attack on any hardware wallet to date, reinforcing their conclusion that "the practical risk is virtually non-existent" for everyday users.

Ledger’s Donjon team, while acknowledging the high cost and physical invasiveness, maintains that the flaw is real, present in every card, and fundamentally unpatchable. They argue that the existence of the vulnerability, regardless of its difficulty, demonstrates a breach in the intended security model. The common ground between both parties appears to be narrow, focusing on a specific scenario: a lost, stolen, or seized Tangem card where the attacker has a pre-existing reason to believe it holds significant value and is therefore worth the considerable investment and effort to compromise.

Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched

A Broader Look at Hardware Wallet Vulnerabilities

This isn’t the first instance of Ledger’s Donjon team uncovering advanced physical attacks on hardware wallets. In early June, Trezor, in collaboration with its chip partner Tropic Square, disclosed a related finding. Donjon had employed the same laser fault injection technique against the TROPIC01 chip used in the new Trezor Safe 7. In that instance, the LFI attack was used to bypass the chip’s firmware signature check, allowing Donjon to run its own unauthorized code. However, Trezor stated that user funds remained secure due to the Safe 7’s multi-layered security architecture, specifically the layer guarding the PIN, which held firm. Unlike Tangem, Trezor and Tropic Square were able to respond by releasing a stopgap measure for existing chips and implementing hardening measures for future silicon versions, demonstrating the advantage of patchable firmware.

The history of hardware wallet vulnerabilities also includes less sophisticated, but still effective, attacks. Years ago, Donjon successfully extracted recovery seeds from stolen Trezor One and Trezor T wallets using a rig costing merely around $100. These older generation wallets relied on ordinary microcontrollers without the robust defenses of a secure element, making them softer targets for physical exploitation.

The Tangem case illustrates a critical distinction: the presence of a hardened, EAL6+ certified secure element significantly raises the bar for attackers. It transforms what might have been a relatively inexpensive attack into one requiring a quarter-million-dollar laboratory. However, this research unequivocally demonstrates that even high-grade certifications and secure elements do not eliminate all danger. An EAL6+ rating primarily vouches for the inherent security features of the chip itself and its built-in defenses, not necessarily for the higher-level code or firmware that a wallet manufacturer layers on top. It is within this layered code, specifically the password recovery logic, that the Tangem flaw resides.

This is also Donjon’s third reported finding concerning Tangem’s security. Earlier, they identified an Android application bypass, which, being a software flaw, could be addressed and patched by Tangem. However, both this recent laser attack and a previously discovered password brute-force method are embedded within the card’s immutable firmware, rendering them unfixable through updates. This recurring pattern underscores the unique security challenges presented by hardware with unalterable firmware.

Implications for Crypto Security and User Action

The Donjon team’s discovery serves as a potent reminder that even highly certified hardware wallets are not impervious to all forms of attack, particularly sophisticated physical ones. While the immediate practical threat to the average Tangem user is indeed low due to the high barrier to entry for this specific attack, the underlying vulnerability is a permanent fixture in every Tangem card.

Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched

For the vast majority of Tangem users, the primary recommendation remains unchanged: rigorously protect the physical card from theft or loss. This attack cannot be performed remotely, meaning if you retain physical possession of your card, your funds are secure against this specific threat.

However, a crucial call to action emerges for a specific subset of users: those whose Tangem cards have been lost or stolen and who are guarding significant value. In such scenarios, where an attacker might have a strong incentive to invest in compromising the card, immediate action is warranted. Users in this situation should prioritize moving their funds to a new, secure wallet as quickly as possible. This can be done using another card in their linked set (if available) or by utilizing a seed phrase if one was previously set up during the wallet’s initialization. Relying on the password to protect a card that is no longer in your control, especially if it contains substantial assets, is no longer a sufficient safeguard against this type of targeted, high-resource attack.

Ultimately, this incident contributes to the ongoing discourse in the cryptocurrency ecosystem about the robust security measures required for self-custody solutions. It highlights the continuous cat-and-mouse game between security researchers and malicious actors, pushing the boundaries of what is considered "secure" in the realm of hardware-based cryptographic protection. Users are encouraged to remain vigilant, stay informed about security disclosures, and adopt best practices for safeguarding their digital assets.

Cybersecurity & Digital Privacy attackcriticalCryptoCybercrimedonjonexposesfaultHackinginjectionlaserledgerPrivacyrevealsSecuritytangemteamvulnerabilitywallets

Post navigation

Previous post
Next post

Recent Posts

Categories

  • AI & Machine Learning
  • Blockchain & Web3
  • Cloud Computing & Edge Tech
  • Cybersecurity & Digital Privacy
  • Data Center & Server Infrastructure
  • Digital Transformation & Strategy
  • Enterprise Software & DevOps
  • Global Telecom News
  • Internet of Things & Automation
  • Network Infrastructure & 5G
  • Semiconductors & Hardware
  • Space & Satellite Tech
©2026 MagnaNet Network | WordPress Theme by SuperbThemes