Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
No Result
View All Result
Home Crypto News Today Security & Hacks

Ledger Researchers Reveal Laser Flaw in Tangem Cards as Firm Downplays User Risk

Ledger Donjon demonstrated a laser-based password reset attack on Tangem cards, but Tangem says the costly, invasive process poses little risk to everyday users.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
July 10, 2026 - Updated on July 16, 2026
in Security & Hacks
0 0
Ledger Researchers Disclose Tangem Card Flaw

Created by Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

Ledger’s security research unit has disclosed a physical attack that can reset the password on a Tangem hardware wallet card, potentially allowing an attacker to use the device to authorize crypto transactions.

Tangem acknowledged the laboratory demonstration but said the attack requires physical possession, specialist expertise and equipment worth about $250,000, making the risk to everyday users “virtually non-existent.”

Our comment on Ledger Donjon’s latest article. It describes a laser fault injection (LFI), a physical, lab-only attack technique that applies to secure elements in general, not something unique to Tangem.

It’s also worth noting that while Ledger Donjon presents itself as an…

— Tangem (@Tangem) July 9, 2026

Laser Attack Resets Card Password

Ledger Donjon researchers used a precisely timed laser pulse to bypass a recovery-state check in Tangem firmware running on the card’s EAL6+ secure element. The bypass allowed them to set a new password without the existing password or another card from the same wallet set. Once reset, the card could be used to sign transactions.

The attack:

  • Cannot be carried out remotely.
  • Requires the card to be physically dismantled.
  • Does not extract the private key.
  • Reportedly works even when password recovery is disabled.

Ledger said it reproduced the attack on two additional cards. After identifying the correct laser location and timing, each subsequent test took about two hours. The $250,000 estimate represents the laboratory setup, not the cost of attacking each card.

Tangem Says Attack Is Not Practical

Tangem argued that an attacker would need to steal a card, expose its chip and operate precision fault-injection equipment. The process leaves visible damage and requires advanced hardware-security knowledge. The company also said the technique does not scale and presents almost no practical risk to everyday users. Ledger Donjon similarly acknowledged that the attack is relevant mainly when a card is lost or stolen.

The disclosure comes amid broader scrutiny of wallet security, though recent incidents have involved different attack methods. A counterfeit Ledger Live app on Apple’s Mac App Store reportedly stole about $9.5 million after victims entered their recovery phrases, making it a phishing attack rather than a hardware compromise.

Separately, a Cardano holder claimed that 2.3 million ADA left a Ledger-secured wallet without approval, but no widely shared on-chain evidence initially established the cause or showed that Ledger hardware had been breached.

Existing Cards Cannot Be Patched

Ledger said Tangem cards already in circulation cannot receive a firmware fix because the devices do not support firmware updates. Tangem has promoted immutable firmware as a security feature because it prevents malicious updates. The disclosure highlights the trade-off: removing the update mechanism reduces one attack surface but prevents vulnerabilities discovered later from being corrected remotely.

The finding also shows that EAL6+ certification does not automatically protect every software function running on a secure element. Ledger’s attack targeted Tangem’s password-recovery logic rather than extracting or breaking the private key. For most users, the disclosure does not represent an immediate online threat. Its primary relevance is to cards that are lost, stolen or deliberately taken from known high-value holders.

Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.

To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.

Tags: crypto security
Saravana Kumar Mahendran

Saravana Kumar Mahendran

Saravana Kumar Mahendran is a crypto security analyst and blockchain researcher at Cryip, focusing on DeFi protocol exploits, Web3 security systems, and on-chain investigation. His research applies OSINT and fact-checking methodology to security incidents, drawing on certifications in cybersecurity and data analytics (LinkedIn Learning), and DeFi deep-dive training (Binance Academy). His work has been cited by Sherlock, Rekt.news, and Halborn Security.

Related Posts

Security & Hacks

Revolut Suspected of Leaking Customer Data After Fake Government Request

by Akil Prasath LV
September 12, 2026

Key Facts Revolut is suspected of responding to a spoofed government data request with real customer records. Exposed data reportedly...

Read moreDetails
Cronos Halts Its Own Blockchain After a $75M Tectonic Exploit

Cronos Halts Its Own Blockchain After a $75M Tectonic Exploit

August 31, 2026
Ledger Denies Hack Claim After OneKey Reproduces Already-Patched Ethereum Bug

Ledger Denies Hack Claim After OneKey Reproduces Already-Patched Ethereum Bug

August 28, 2026
Audited Crypto Platforms Lost $3.2 Billion Anyway, New Report Shows

Audited Crypto Platforms Lost $3.2 Billion Anyway, New Report Shows

August 27, 2026
Core Lightning Tells Node Operators to Go Offline, Not Shut Down Amid Bug Patch

Core Lightning Tells Node Operators to Go Offline, Not Shut Down Amid Bug Patch

August 27, 2026
Operation ASTERIX Shows AI Refusals Are a Speed Bump, Not a Stop Sign

Operation ASTERIX Shows AI Refusals Are a Speed Bump, Not a Stop Sign

August 20, 2026
Binance Says It Stopped a $1.2M DAO Attack, but Won’t Name the Target

Binance Says It Stopped a $1.2M DAO Attack, but Won’t Name the Target

August 19, 2026
Next Post
AI Agents Now Have a New Internet Court to Settle Disputes

AI Agents Now Have a New Internet Court to Settle Disputes

DOJ Moves to End BitClub Founder’s $722 Million Crypto Fraud Case

DOJ Moves to End BitClub Founder’s $722 Million Crypto Fraud Case

Recommended

  • All
  • Crypto News Today
US Bitcoin ETFs Pull in $118.8 Million on October 6 as BlackRock's IBIT Leads Inflows

US Bitcoin ETFs Pull in $118.8 Million on October 6 as BlackRock’s IBIT Leads Inflows

October 8, 2026
21Shares Extends 100% Fee Waiver on Its Ethereum Staking ETF Through October 2027

21Shares Extends 100% Fee Waiver on Its Ethereum Staking ETF Through October 2027

October 8, 2026
US Ether ETFs Bleed $201.9 Million in a Single Day, Almost Entirely From BlackRock's ETHA

US Ether ETFs Bleed $201.9 Million in a Single Day, Almost Entirely From BlackRock’s ETHA

October 8, 2026
VanEck Solana ETF Declares First Quarterly Staking Distribution of $964,960

VanEck Solana ETF Declares First Quarterly Staking Distribution of $964,960

October 8, 2026
NFT Limited Prices $2.48 Million Public Offering to Fund Its Digital Art Trading Platform

NFT Limited Prices $2.48 Million Public Offering to Fund Its Digital Art Trading Platform

October 8, 2026
Super League Tells Shareholders Metaplanet's 2,100 BTC Contribution Is Now Worth $179 Million

Super League Tells Shareholders Metaplanet’s 2,100 BTC Contribution Is Now Worth $179 Million

October 8, 2026
TeraWulf Doubles Muskie Data Campus Capacity to 1 Gigawatt

TeraWulf Doubles Muskie Data Campus Capacity to 1 Gigawatt

October 7, 2026
Morgan Stanley Offers Auto-Callable Notes Linked to Bitcoin Through 2029

Morgan Stanley Offers Auto-Callable Notes Linked to Bitcoin Through 2029

October 7, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • Calamos Resets Caps and Floors on Its Bitcoin Buffer ETFs for a New One-Year Period
  • US Bitcoin ETFs Pull in $118.8 Million on October 6 as BlackRock’s IBIT Leads Inflows
  • 21Shares Extends 100% Fee Waiver on Its Ethereum Staking ETF Through October 2027

Categories

  • AI News
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Research & Analysis
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • Uncategorized
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.