Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
No Result
View All Result
Home Crypto News Today Security & Hacks

Ledger Researchers Reveal Laser Flaw in Tangem Cards as Firm Downplays User Risk

Ledger Donjon demonstrated a laser-based password reset attack on Tangem cards, but Tangem says the costly, invasive process poses little risk to everyday users.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
July 10, 2026 - Updated on July 16, 2026
in Security & Hacks
0 0
Ledger Researchers Disclose Tangem Card Flaw

Created by Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

Ledger’s security research unit has disclosed a physical attack that can reset the password on a Tangem hardware wallet card, potentially allowing an attacker to use the device to authorize crypto transactions.

Tangem acknowledged the laboratory demonstration but said the attack requires physical possession, specialist expertise and equipment worth about $250,000, making the risk to everyday users “virtually non-existent.”

Our comment on Ledger Donjon’s latest article. It describes a laser fault injection (LFI), a physical, lab-only attack technique that applies to secure elements in general, not something unique to Tangem.

It’s also worth noting that while Ledger Donjon presents itself as an…

— Tangem (@Tangem) July 9, 2026

Laser Attack Resets Card Password

Ledger Donjon researchers used a precisely timed laser pulse to bypass a recovery-state check in Tangem firmware running on the card’s EAL6+ secure element. The bypass allowed them to set a new password without the existing password or another card from the same wallet set. Once reset, the card could be used to sign transactions.

The attack:

  • Cannot be carried out remotely.
  • Requires the card to be physically dismantled.
  • Does not extract the private key.
  • Reportedly works even when password recovery is disabled.

Ledger said it reproduced the attack on two additional cards. After identifying the correct laser location and timing, each subsequent test took about two hours. The $250,000 estimate represents the laboratory setup, not the cost of attacking each card.

Tangem Says Attack Is Not Practical

Tangem argued that an attacker would need to steal a card, expose its chip and operate precision fault-injection equipment. The process leaves visible damage and requires advanced hardware-security knowledge. The company also said the technique does not scale and presents almost no practical risk to everyday users. Ledger Donjon similarly acknowledged that the attack is relevant mainly when a card is lost or stolen.

The disclosure comes amid broader scrutiny of wallet security, though recent incidents have involved different attack methods. A counterfeit Ledger Live app on Apple’s Mac App Store reportedly stole about $9.5 million after victims entered their recovery phrases, making it a phishing attack rather than a hardware compromise.

Separately, a Cardano holder claimed that 2.3 million ADA left a Ledger-secured wallet without approval, but no widely shared on-chain evidence initially established the cause or showed that Ledger hardware had been breached.

Existing Cards Cannot Be Patched

Ledger said Tangem cards already in circulation cannot receive a firmware fix because the devices do not support firmware updates. Tangem has promoted immutable firmware as a security feature because it prevents malicious updates. The disclosure highlights the trade-off: removing the update mechanism reduces one attack surface but prevents vulnerabilities discovered later from being corrected remotely.

The finding also shows that EAL6+ certification does not automatically protect every software function running on a secure element. Ledger’s attack targeted Tangem’s password-recovery logic rather than extracting or breaking the private key. For most users, the disclosure does not represent an immediate online threat. Its primary relevance is to cards that are lost, stolen or deliberately taken from known high-value holders.

Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.

To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.

Tags: crypto security
Saravana Kumar Mahendran

Saravana Kumar Mahendran

Saravana Kumar Mahendran is a crypto security analyst and blockchain researcher at Cryip, focusing on DeFi protocol exploits, Web3 security systems, and on-chain investigation. His research applies OSINT and fact-checking methodology to security incidents, drawing on certifications in cybersecurity and data analytics (LinkedIn Learning), and DeFi deep-dive training (Binance Academy). His work has been cited by Sherlock, Rekt.news, and Halborn Security.

Related Posts

Operation ASTERIX Shows AI Refusals Are a Speed Bump, Not a Stop Sign
Security & Hacks

Operation ASTERIX Shows AI Refusals Are a Speed Bump, Not a Stop Sign

by Saravana Kumar Mahendran
August 20, 2026

Rapid7 Labs found a crypto-phishing operation’s entire workspace exposed on a misconfigured server, including logs of Claude Code refusing a...

Read moreDetails
Binance Says It Stopped a $1.2M DAO Attack, but Won’t Name the Target

Binance Says It Stopped a $1.2M DAO Attack, but Won’t Name the Target

August 19, 2026
BitBox’s Dixence Update Fixes Three Flaws, and Upgrades an Older One to “Severe”

BitBox’s Dixence Update Fixes Three Flaws, and Upgrades an Older One to “Severe”

August 18, 2026
Ravencoin’s Fix for Its Third Consensus Failure Is Coming From a Mining Pool, Not Its Own Team

Ravencoin’s Fix for Its Third Consensus Failure Is Coming From a Mining Pool, Not Its Own Team

August 11, 2026
Why BONK Is Being Delisted From Upbit: A $20M Hack and a Two-Month Review

Why BONK Is Being Delisted From Upbit: A $20M Hack and a Two-Month Review

August 7, 2026
RippleX and XRP Ledger Foundation Debunk Fake ‘XRP Rewards Scanner’ Scam

RippleX and XRP Ledger Foundation Debunk Fake ‘XRP Rewards Scanner’ Scam

August 7, 2026
Bitcoin Security Consortium Launches With $15M to Strengthen BTC Security

Saylor’s Strategy Joins $15M Bitcoin Security Consortium to Strengthen BTC Security

July 23, 2026
Next Post
AI Agents Now Have a New Internet Court to Settle Disputes

AI Agents Now Have a New Internet Court to Settle Disputes

DOJ Moves to End BitClub Founder’s $722 Million Crypto Fraud Case

DOJ Moves to End BitClub Founder’s $722 Million Crypto Fraud Case

Recommended

  • All
  • Crypto News Today
Base Defends Builder Support After Criticism Over Its Ecosystem

Base Defends Builder Support After Criticism Over Its Ecosystem

August 24, 2026
Saylor's Strategy Makes No BTC Purchase, Raises USD Reserve to $5.10B

Saylor’s Strategy Makes No BTC Purchase, Raises USD Reserve to $5.10B

August 24, 2026
Upbit and Bithumb Flag SAND for Caution, the Review That Has Ended in Delisting

Upbit and Bithumb Flag SAND for Caution, the Review That Has Ended in Delisting

August 24, 2026
Strive CEO Says Bitcoin Bear Market Is Over as BTC Breaks Out Against Gold and Dollar

Strive CEO Says Bitcoin Bear Market Is Over as BTC Breaks Out Against Gold and Dollar

August 24, 2026
Solana Network Revenue Surpasses $1M on Aug. 19

Solana Network Revenue Surpasses $1M on Aug. 19

August 24, 2026
Pakistan’s Crypto Licensing Deadline Arrives With Its Chairman Wearing Two Hats

Pakistan’s Crypto Licensing Deadline Arrives With Its Chairman Wearing Two Hats

August 24, 2026
Kyber Network Says It's Not Regulated by Singapore's MAS. Its Own Contracts Show Why.

Kyber Network Says It’s Not Regulated by Singapore’s MAS. Its Own Contracts Show Why.

August 24, 2026
Trump Team Pulls $3.39M USDC From TRUMP Liquidity Pools

Trump Team Pulls $3.39M USDC From TRUMP Liquidity Pools

August 24, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • Bitmine Buys 32,447 ETH, Pushing Holdings to 5.85 Million Tokens
  • Base Defends Builder Support After Criticism Over Its Ecosystem
  • Saylor’s Strategy Makes No BTC Purchase, Raises USD Reserve to $5.10B

Categories

  • AI News
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Research & Analysis
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.