Ledger’s Donjon security team has disclosed a hardware attack against Tangem wallet cards that can reset a card’s password by disrupting its secure element with a precisely timed laser pulse. The technique was demonstrated in a lab setting and, according to the report, cannot be carried out remotely. It requires physical access to the card, invasive preparation, specialist expertise and equipment costing about $250,000.

How the attack works

According to the disclosure, the attack targets a specific part of the secure element with a nanosecond laser pulse during the password recovery process. Under normal conditions, a Tangem card needs the current password before a new one can be set. A recovery flow can also reset the password, but only when another linked backup card confirms the request.

Ledger researchers said the laser fault injection interrupts a firmware check that is supposed to verify that the recovery state has been properly approved. By bypassing that step, the attacker can set a new password without knowing the existing one and without using a backup card.

Demonstration and disclosure timeline

Ledger Donjon said it successfully carried out the attack on three Tangem cards. Each attempt reportedly took around two hours to prepare and execute. The team said it reported the flaw to Tangem on Feb. 10.

The disclosure does not suggest a remote compromise path. The method cannot be performed through the Tangem mobile app, over the internet, or through NFC alone. Instead, it depends on direct physical possession of the card as well as invasive work on the hardware itself.

Why the issue matters

A central concern is that Tangem cards already in circulation do not support firmware updates. That means a software fix cannot be pushed to devices that customers already hold, leaving the issue effectively unpatchable for existing cards.

Ledger’s report also highlights a broader point about hardware-wallet security: a high-grade secure element, including one rated at EAL6+, is not by itself a complete defense if the surrounding firmware logic can still be bypassed under fault conditions.

Tangem’s response

Tangem did not challenge the reported lab result, but it cast doubt on the practical risk to ordinary users. The company said the threat to everyday users is virtually non-existent because the attack demands expensive laboratory gear, technical know-how and physical control of the card.

Tangem advised users to keep their cards physically secure. The report likewise indicates that loss of physical control is the key exposure in this case, and that a missing card should be treated as a security incident, with funds moved to a new wallet to reduce risk.

The case adds to a recurring lesson in hardware security: even when remote attack avenues are absent, physical attacks can still expose weaknesses in design or implementation. In this instance, the findings do not point to a mass remote exploit, but they do underline the limits of hardware protections once a device falls into the hands of a capable attacker.

Source: crypto.news