Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
No Result
View All Result
Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
No Result
View All Result
Cryip
No Result
View All Result
Home Crypto News Today Security & Hacks

Ledger Researchers Reveal Laser Flaw in Tangem Cards as Firm Downplays User Risk

Ledger Donjon demonstrated a laser-based password reset attack on Tangem cards, but Tangem says the costly, invasive process poses little risk to everyday users.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
July 10, 2026 - Updated on July 16, 2026
in Security & Hacks
0 0
Ledger Researchers Disclose Tangem Card Flaw

Created by Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

Ledger’s security research unit has disclosed a physical attack that can reset the password on a Tangem hardware wallet card, potentially allowing an attacker to use the device to authorize crypto transactions.

Tangem acknowledged the laboratory demonstration but said the attack requires physical possession, specialist expertise and equipment worth about $250,000, making the risk to everyday users “virtually non-existent.”

Our comment on Ledger Donjon’s latest article. It describes a laser fault injection (LFI), a physical, lab-only attack technique that applies to secure elements in general, not something unique to Tangem.

It’s also worth noting that while Ledger Donjon presents itself as an…

— Tangem (@Tangem) July 9, 2026

Laser Attack Resets Card Password

Ledger Donjon researchers used a precisely timed laser pulse to bypass a recovery-state check in Tangem firmware running on the card’s EAL6+ secure element. The bypass allowed them to set a new password without the existing password or another card from the same wallet set. Once reset, the card could be used to sign transactions.

The attack:

  • Cannot be carried out remotely.
  • Requires the card to be physically dismantled.
  • Does not extract the private key.
  • Reportedly works even when password recovery is disabled.

Ledger said it reproduced the attack on two additional cards. After identifying the correct laser location and timing, each subsequent test took about two hours. The $250,000 estimate represents the laboratory setup, not the cost of attacking each card.

Tangem Says Attack Is Not Practical

Tangem argued that an attacker would need to steal a card, expose its chip and operate precision fault-injection equipment. The process leaves visible damage and requires advanced hardware-security knowledge. The company also said the technique does not scale and presents almost no practical risk to everyday users. Ledger Donjon similarly acknowledged that the attack is relevant mainly when a card is lost or stolen.

The disclosure comes amid broader scrutiny of wallet security, though recent incidents have involved different attack methods. A counterfeit Ledger Live app on Apple’s Mac App Store reportedly stole about $9.5 million after victims entered their recovery phrases, making it a phishing attack rather than a hardware compromise.

Separately, a Cardano holder claimed that 2.3 million ADA left a Ledger-secured wallet without approval, but no widely shared on-chain evidence initially established the cause or showed that Ledger hardware had been breached.

Existing Cards Cannot Be Patched

Ledger said Tangem cards already in circulation cannot receive a firmware fix because the devices do not support firmware updates. Tangem has promoted immutable firmware as a security feature because it prevents malicious updates. The disclosure highlights the trade-off: removing the update mechanism reduces one attack surface but prevents vulnerabilities discovered later from being corrected remotely.

The finding also shows that EAL6+ certification does not automatically protect every software function running on a secure element. Ledger’s attack targeted Tangem’s password-recovery logic rather than extracting or breaking the private key. For most users, the disclosure does not represent an immediate online threat. Its primary relevance is to cards that are lost, stolen or deliberately taken from known high-value holders.

AI Disclosure: Cryip uses AI-assisted tools to help refine language — correcting spelling and grammar and simplifying complex terms for readability.

We do this to make crypto topics easier to understand for readers at all experience levels. AI does not draft facts, sources, or conclusions. Every article is reviewed and approved by a human editor before publication. Read our full AI Use & Content Policy.

Disclaimer: Cryip’s content is strictly for informational purposes and does not constitute financial, legal, or investment advice. Asset references are not endorsements, and readers assume full responsibility for any financial decisions.
Tags: crypto securityLedger
Saravana Kumar Mahendran

Saravana Kumar Mahendran

Saravana Kumar Mahendran is a crypto security analyst and blockchain researcher at Cryip, focusing on DeFi protocol exploits, Web3 security systems, and on-chain investigation. His research applies OSINT and fact-checking methodology to security incidents, drawing on certifications in cybersecurity and data analytics (LinkedIn Learning), and DeFi deep-dive training (Binance Academy). His work has been cited by Sherlock, Rekt.news, and Halborn Security.

Related Posts

Why BONK Is Being Delisted From Upbit: A $20M Hack and a Two-Month Review
Market Updates

Why BONK Is Being Delisted From Upbit: A $20M Hack and a Two-Month Review

by Saravana Kumar Mahendran
August 7, 2026

Upbit will end trading support for Bonk (BONK) on September 7, 2026, at 15:00 KST. All open BONK/KRW and BONK/USDT...

Read moreDetails
RippleX and XRP Ledger Foundation Debunk Fake ‘XRP Rewards Scanner’ Scam

RippleX and XRP Ledger Foundation Debunk Fake ‘XRP Rewards Scanner’ Scam

August 7, 2026
Bitcoin Security Consortium Launches With $15M to Strengthen BTC Security

Saylor’s Strategy Joins $15M Bitcoin Security Consortium to Strengthen BTC Security

July 23, 2026
ZachXBT Criticizes Hardware Wallets and Recommends Dedicated iPhone

ZachXBT Criticizes Hardware Wallets and Recommends Dedicated iPhone

July 16, 2026
Hackers Target Injective Wallet Keys Through Compromised npm Package

Malicious Injective SDK Package Targets Private Keys and Seed Phrases

July 10, 2026
Secret Network Proposes SCRT Move to Arbitrum as AI Exploit Risks Reshape Security Priorities

Secret Network Proposes SCRT Move to Arbitrum as AI Exploit Risks Reshape Security Priorities

July 8, 2026
TRON Introduces Quantum-Safe Signatures

TRON Introduces Quantum-Safe Signatures Across Nile Testnet

July 3, 2026
Next Post
AI Agents Now Have a New Internet Court to Settle Disputes

AI Agents Now Have a New Internet Court to Settle Disputes

DOJ Moves to End BitClub Founder’s $722 Million Crypto Fraud Case

DOJ Moves to End BitClub Founder’s $722 Million Crypto Fraud Case

Recommended

  • All
  • Crypto News Today
Saylor Says Bitcoin BIP-110 Lacks Miner Consensus at 2.6% Support

Saylor Says Bitcoin BIP-110 Lacks Miner Consensus at 2.6% Support

August 8, 2026
Treasury Sanctions Shelbit, Aban Tether: Dubai’s Own Fine Changed Nothing

Treasury Sanctions Shelbit, Aban Tether: Dubai’s Own Fine Changed Nothing

August 8, 2026
Trump Media Ends Crypto.com Partnership, Signaling Retreat From Its Crypto Expansion Plans

Trump Media Ends Crypto.com Partnership, Signaling Retreat From Its Crypto Expansion Plans

August 8, 2026
Bybit’s Own Filings Show Recovery Barely Moved in 7 Weeks After Suing North Korea

Bybit’s Own Filings Show Recovery Barely Moved in 7 Weeks After Suing North Korea

August 8, 2026
Brazil Tightens Crypto Transfer Rules With 24-Hour Delay to Combat Fraud

Brazil Tightens Crypto Transfer Rules With 24-Hour Delay to Combat Fraud

August 8, 2026
oung people from the Russian regions looking for easy money

FSB Shuts Down Nine Illegal Moscow Crypto Exchanges Linked to Ukrainian Call-Center Fraud

August 8, 2026
MetaMask's New AI Wallet Caps Loss Protection at $10,000 a Month

MetaMask’s New AI Wallet Caps Loss Protection at $10,000 a Month

August 8, 2026
Why BONK Is Being Delisted From Upbit: A $20M Hack and a Two-Month Review

Why BONK Is Being Delisted From Upbit: A $20M Hack and a Two-Month Review

August 7, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • South Africa’s Rand Stablecoin Lost to Dollar Tokens: Now the IMF Says That’s a Warning Sign
  • Saylor Says Bitcoin BIP-110 Lacks Miner Consensus at 2.6% Support
  • Treasury Sanctions Shelbit, Aban Tether: Dubai’s Own Fine Changed Nothing

Categories

  • AI × Crypto
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Crypto News Today
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.