The Donjon research team, a division of Ledger, has identified a serious hardware vulnerability in popular Tangem cryptocurrency wallets. It involves a laser fault injection attack that allows an attacker to reset the card's password and gain full control over the digital assets stored on it. Let's break down why this matters and whether Tangem owners should panic.

The Essence of the Attack: How a Laser Breaks EAL6+ Protection

Tangem produces hardware wallets in the form of NFC cards that resemble bank cards. Inside each card is a secure Samsung S3D232A chip with EAL6+ certification — one of the highest security levels in the industry. This chip generates and stores private keys, as well as signs transactions when connected to a mobile app.

Under normal conditions, access to funds is protected by two factors: physical possession of the card and knowledge of the password. Tangem also provides a recovery mechanism: if the password is lost, it can be reset using a second, backup card. However, Donjon researchers found a way to bypass this protection.

Their attack focuses on the SetPin instruction used when changing the password. The chip's firmware includes a check that allows a reset only in certain states. Laser fault injection disrupts this check: a single nanosecond pulse directed at a specific area of the chip forces the card to accept a new password without entering the old one and without requiring the backup card.

To prepare the attack, the researcher opened the card, exposed the chip, connected it to a custom hardware platform, and analyzed side channels to determine the exact moment the check was executed. After configuring parameters for a specific model, each new attempt takes about two hours. A successful password reset gives the attacker the ability to sign transactions and withdraw funds.

Risk Assessment: Theory vs. Practice

It's important to understand that this attack is physical and invasive. It cannot be carried out remotely and irreversibly damages the card. Moreover, the cost of the equipment for the experiment, according to Donjon, is approximately $250,000, plus it requires deep knowledge of hardware security and side-channel analysis.

Tangem, for its part, calls the risk for ordinary users "practically non-existent." The company rightly notes that with sufficient resources, the firmware of any secure element can be studied. However, they also point to a potential conflict of interest: Donjon is a division of Ledger, a direct competitor of Tangem in the hardware wallet market.

The researcher himself emphasizes that EAL6+ certification confirms the chip's resilience but does not guarantee the absence of vulnerabilities in the firmware running on top of it. He recommends using multiple independent checks for critical operations and more robust state encoding.

In my opinion, this finding is an important reminder that even the most secure hardware wallets are not absolutely invulnerable. However, for the vast majority of Tangem users, the real threat comes not from laser attacks costing a quarter of a million dollars, but from losing the card, phishing, or social engineering. If your card is always with you, the described attack is not a concern. But if you lose it or it gets stolen — the risks, albeit hypothetical, become more tangible.