Laser Hack Bypasses Tangem Wallet Security, Resetting Passwords on Unpatchable Cards

0
16

Key Takeaways

  • A precisely timed laser pulse can force a Tangem crypto‑wallet card into recovery mode, allowing an attacker to set a new password without the old one or a second card.
  • The exploit requires physical access to the card, a ~$250,000 laser‑fault‑injection lab, and visible damage from opening the card; it cannot be performed remotely.
  • Tangem cards lack firmware update capability, so the vulnerability is permanent and affects every card already sold.
  • For most users the risk is negligible because the attack is costly, invasive, and provides no way to gauge the card’s value before attempting it.
  • Owners who lose or steal a card holding significant value should immediately move funds using another card from the set or a seed phrase, and stop relying on the password for protection.
  • Similar laser‑fault attacks have been demonstrated on other hardware wallets (e.g., Trezor Safe 7), but Tangem’s design leaves no path for a software patch.

How the Tangem Wallet Is Supposed to Protect Users
A Tangem wallet resembles a standard bank card; tapping it to a phone activates a companion app that communicates with a Samsung S3D232A secure element chip inside. Certified to EAL6+, the chip is engineered to resist tampering and never releases the private key that controls the user’s cryptocurrency. Security relies on two factors: possession of the card and knowledge of the password. If a user forgets the password, Tangem provides a recovery method that uses two cards from the same set to reset the PIN without needing the old one.

The Laser Fault‑Injection Weakness
During the password‑reset process the chip executes a single check: “Is this card in recovery mode?” If the answer is yes, it accepts a new PIN without requesting the old one. Researchers from Ledger’s Donjon team discovered that firing a precisely timed laser pulse at the chip while this check runs disturbs the circuitry just enough to make the check misfire. The chip then behaves as if it were in recovery mode even when it is not, allowing the ordinary SetPin command to accept any new password chosen by the attacker.

Why the Attack Is Difficult but Feasible
Carrying out the exploit is far from trivial. It demands a laser‑fault‑injection setup, sensitive measurement equipment, deep hardware expertise, and weeks of preparatory work to map the chip and pinpoint the exact laser spot and timing. The card must be cut open to expose the chip, leaving obvious physical damage that reveals tampering. Once the parameters are calibrated, Donjon reported that the attack succeeded on every tested card, taking roughly two hours per card. The team disclosed the flaw to Tangem on February 10, 2026.

The Permanent Nature of the Flaw
Tangem markets its cards’ inability to receive firmware updates as a security advantage: nothing can be altered remotely, so no remote tampering is possible. Unfortunately, this same design means the vulnerability cannot be patched. The flaw resides in the card’s firmware, which is immutable after manufacture. As the researchers noted, “there’s no patch, but the attack is physical and invasive,” so the only mitigation is preventing physical access to the card.

Tangem’s Response and Perspective
Tangem pushed back, characterizing the laser method as a lab‑only physical technique that could affect any secure‑element chip, not a unique weakness of its products. The company highlighted that Donjon is part of Ledger, a major competitor, and argued that because Tangem cards contain no identifying information about the owner or the amount stored, an attacker spending $250,000 to ruin cards cannot know whether a stolen card holds $50 or $50 million. Tangem also pointed out that no funds have been lost to a laser attack on any hardware wallet to date, asserting that for everyday users the practical risk is virtually nonexistent.

Where the Two Views Converge
Both sides are partially correct. Donjon’s researchers are right that the flaw is real, present in every Tangem card, and permanent. Tangem is correct that the high cost, the visible destruction of cards, and the uncertainty about a card’s value make the attack impractical for most threat actors. The intersection where the attack becomes worthwhile is narrow: a lost, stolen, or seized card that an attacker already has reason to believe contains substantial value.

Precedent: Similar Laser Attacks on Other Wallets
This is not Donjon’s first laser‑fault demonstration on a hardware wallet. In early June 2026 they disclosed a related result on the TROPIC01 chip used in the Trezor Safe 7, where laser fault injection bypassed the chip’s firmware signature check to run arbitrary code. Trezor maintained fund safety because the Safe 7 employs three independent security layers, and the layer guarding the PIN remained intact. Unlike Tangem, Trezor and its chip partner could issue a stop‑gap for existing chips and are hardening the next silicon generation. Earlier, the same team extracted recovery seeds from a stolen Trezor One or Trezor T using a ~$100 rig, because those devices relied on an ordinary microcontroller without a secure element. Tangem’s use of a hardened EAL6+ secure element raises the attack bar to roughly a quarter‑million‑dollar lab, but does not eliminate the risk entirely.

What Users Should Do
For the vast majority of Tangem owners, the recommended actions remain unchanged: keep the card in a secure location where a thief cannot obtain it. The attack cannot be executed remotely, and it requires the attacker to have the physical card in hand. If a Tangem card is lost or stolen and it guards significant value, the prudent step is to transfer the funds immediately using another card from the same set (or a seed phrase, if one was created during setup) and cease relying on the password for protection of a card you no longer control. This limits exposure to the only realistic scenario where the laser fault injection could be profitable.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here