
Ledger Donjon said a laser fault injection flaw in Tangem’s secure element firmware could let attackers with physical access reset card passwords; existing cards cannot be patched because they lack firmware updates.
Ledger’s Donjon security team said a laser fault injection attack can bypass password protection on Tangem hardware wallet cards by disrupting a firmware check during a password reset. The attack requires physical possession of the card, specialist hardware-security expertise, invasive preparation and laboratory equipment costing about $250,000, which Tangem said makes the everyday risk “virtually non-existent.” Donjon disclosed the issue to Tangem on Feb. 10 and said it reproduced the attack on three cards, with later tests taking about two hours each to prepare and complete. Because Tangem cards do not support firmware updates, the vulnerability cannot be patched on devices already in circulation. Ledger said the main risk applies if a card is lost or stolen, while Tangem urged users to keep their cards physically secure and noted the attack cannot be carried out remotely through the mobile app, the internet or NFC alone.