Ledger's research department, known as Donjon, has presented a detailed analysis of a vulnerability in Tangem hardware wallets. The attack method is based on laser fault injection, which allows resetting the card's password and gaining full control over the crypto assets stored on it. This discovery raises important questions about the real security of even certified devices.
How the attack works and why it is dangerous
At the core of Tangem wallets is the Samsung S3D232A secure element with EAL6+ certification, which generates and stores private keys and signs transactions. Access to funds is traditionally protected by two factors: physical possession of the card and knowledge of the password. However, as experts discovered, the logic of the SetPin instruction in the firmware contains a critical vulnerability. Using a single nanosecond laser pulse directed at a specific area of the chip, it is possible to disrupt the recovery state check and force the card to accept a new password without entering the old one or using a backup.
Conducting the attack requires physical access to the card: it must be opened, the chip exposed, and connected to a specialized hardware platform. After calibrating parameters for a specific model, each new attempt takes about two hours. After resetting the password, an attacker can sign transactions and withdraw funds. It is important to note that the vulnerability affects all issued Tangem cards and cannot be fixed through a firmware update, as the devices do not support this function.
Tangem's response and risk assessment
Tangem representatives called the risk for ordinary users "practically non-existent," emphasizing that the scenario requires expensive laboratory equipment (about $250,000), deep knowledge of hardware security, and physical access to the card. They also noted that Ledger Donjon, being the research division of their direct competitor, may not be entirely objective. In their opinion, with sufficient resources, the firmware of any secure element can be studied and potentially hacked.
Nevertheless, Ledger Donjon expert pointed out the limitations of EAL6+ certification: it confirms the resilience of the chip itself but does not guarantee the absence of vulnerabilities in the firmware logic running on top of it. He recommended implementing multiple independent checks for critical operations and more robust state encoding.
My analysis: This situation is a classic example that even the most secure hardware solutions are not absolutely invulnerable. The attack is certainly complex and expensive, but the very fact of its existence undermines trust in the concept of "ironclad" security. For the average user, the risk is minimal, but for large asset holders or institutional investors, this is a serious signal about the need to diversify storage methods and understand all attack vectors, including physical ones.