CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

Laser Attack Resets Tangem Wallet Passwords on Cards That Can’t Be Patched

July 10, 2026

Researchers at Ledger’s Donjon security team have demonstrated a laser fault injection attack that can reset the password on Tangem crypto wallet cards. The attack requires physical possession of the card, cutting it open to expose the chip, and a lab setup costing approximately $250,000. Once the password is reset, the attacker gains full control of the wallet and can move the cryptocurrency.

The vulnerability lies in the password reset feature of the Tangem card, which uses a Samsung S3D232A secure element chip certified to EAL6+. A precisely timed laser pulse can cause the chip’s recovery mode check to misfire, allowing a new password to be set without the old one or a second card. This flaw cannot be patched because Tangem cards do not support firmware updates, a design choice intended to prevent remote tampering.

Tangem has disputed the practical risk, noting that the attack is expensive, physically invasive, and requires knowing which card holds significant value. The company also pointed out that Donjon is part of Ledger, a competitor. However, the researchers emphasize that the flaw is real and permanent, affecting every card already sold. Users with lost or stolen cards holding substantial funds are advised to move their assets immediately using a backup card or seed phrase.

This is not the first such attack by Donjon; earlier in 2026, they used similar techniques on the Trezor Safe 7 wallet, though Trezor was able to implement mitigations due to its updatable firmware. The Tangem vulnerability highlights the trade-off between security through immutability and the inability to fix critical flaws.

CVEs: CVE-2026-55200, CVE-2026-46817

Companies: Tangem, Ledger, Trezor, Tropic Square, Samsung

Products: Tangem Wallet, Samsung S3D232A, Trezor Safe 7, TROPIC01

Certifications: EAL6+