Ledger Donjon's research division has discovered a physical vulnerability in Tangem hardware cryptocurrency wallets. The attack, using laser fault injection, allows resetting the card's password and gaining control over assets. This method, demonstrated by expert Baptiste Boileau, poses a serious security challenge for non-custodial devices.
Tangem produces hardware wallets in the form of plastic NFC cards resembling bank cards. Inside each card is a secure Samsung S3D232A chip with EAL6+ certification, which stores private keys and signs transactions. Typically, access to funds is protected by two-factor authentication: physical possession of the card and knowledge of the password. However, researchers have discovered that the logic of the SetPin instruction in the firmware is vulnerable to hardware manipulation.
The attack involves opening the card, exposing the secure element, and connecting it to a specialized hardware platform. Using side-channel analysis, the researcher identified the moment of the critical recovery state check. Then, using a single nanosecond laser pulse directed at a specific area of the chip, they managed to disrupt this check and force the card to accept a new password without the old one and the backup card.
After resetting the password, the attacker gains full control over the wallet: they can sign transactions and withdraw funds. The vulnerability affects all Tangem cards in circulation and cannot be fixed with a patch, as the devices do not support firmware updates.
Practical Implementation and Risks
A successful attack requires not only a stolen or lost card. According to Ledger Donjon's estimate, the necessary equipment costs around $250,000. Additionally, side-channel analysis tools, deep knowledge of hardware security, and preparation time are needed. After configuring parameters for a specific model, each new attempt takes about two hours.
Tangem called the risk for ordinary users "practically non-existent," emphasizing that the scenario requires physical access to the card, expensive laboratory equipment, and high expertise. The company also noted that Ledger Donjon is the research division of their direct competitor, which could influence the interpretation of the results.
Nevertheless, Boileau pointed out the limitations of EAL6+ certification: it confirms the chip's resistance according to certain criteria but does not guarantee the absence of vulnerabilities in the firmware logic. As protective measures, he recommended introducing multiple independent checks for critical operations, more robust state encoding, and additional protection for password changes.
This incident serves as a reminder that even certified hardware solutions are not immune to physical attacks. For ordinary users, the risk is minimal, but for holders of large sums or corporate clients, it is a serious signal about the need for multi-layered protection.