Logo Daily Crypto Briefs
Open menu

Tangem Cards Can't Be Patched After $250K Laser Attack, Ledger Says

6 min read
Breaking News
Official black Tangem wordmark on a large off-white hardware-wallet card beside an unbranded greyscale chip under a red laboratory laser beam.

TL;DR

  • Ledger Donjon said it reset a Tangem card password with a precisely targeted nanosecond laser pulse, allowing an attacker with the card to take control of funds tied to it.
  • The researchers said the attack does not need the existing password or a backup card, but requires physical access, specialised lab equipment estimated at about $250,000 and substantial expertise.
  • Ledger said cards already in circulation cannot receive a firmware patch because they have no firmware update mechanism; Tangem said the laboratory attack is not scalable.

ZUG, Switzerland, Aug. 4, 2026

Ledger’s security research team said it used a precisely targeted nanosecond laser pulse to reset a Tangem hardware-wallet card password without knowing the old password, a laboratory attack it said could let an attacker with physical possession of the card take its associated funds.

The disclosure, published July 9 by Ledger Donjon, applies to Tangem cards in circulation, according to the researchers. Ledger said the cards cannot receive a firmware fix because they have no update mechanism, while Tangem said the demonstration requires costly equipment, expert handling and is not scalable.

Bitcoin traded near $64,088 on Aug. 4, up from about $62,528 a month earlier and below its $65,156 July 23 close, according to CoinGecko. The finding concerns a physical self-custody risk, not a flaw in Bitcoin, Tangem’s mobile app or a remote compromise of cards.

In its technical disclosure, Ledger Donjon said the attack needs physical access to one card, a lab setup costing about $250,000, software and hardware expertise, and substantial upfront work to characterize the chip. It said the result does not require the card’s existing password or a backup card.

Bitcoin

BTC
July 3 to Aug. 4, 2026
$64,088
+2.5%
Jul 3 - Aug 4 | High $65,156 Low $62,528

Ledger Says a Laser Reset the Tangem Password

Tangem cards resemble payment cards and hold the cryptographic key used to control wallet funds inside a Samsung S3D232A secure element. Ledger said its researchers bypassed a firmware check with a single laser pulse and then set the access password to a value they controlled.

The company said it reproduced the result on three cards of the same model after finding the relevant region of the chip and timing. Its report described the attack as fault injection, a process that deliberately disturbs electronic hardware while it performs a security-critical instruction.

The published test did not rely on a software exploit or an internet connection. Ledger said its setup used an FPGA-based card to monitor power consumption and cut power at a precise moment, extending the time available to find and reproduce the fault.

That separation is important for interpreting the headline. The research does not mean a Tangem card can be drained through a website, Bluetooth or NFC from a distance. It does show that a physical security assumption can fail even when a secure element is certified and the wallet uses no conventional recovery phrase by default.

The issue arrives days after Coldcard told customers to move Bitcoin whose seeds were made on affected firmware following its own RNG flaw disclosure. The mechanisms differ, but both incidents focus attention on the hardware and key-creation layer beneath a wallet interface.

Tangem Says the Laboratory Attack Is Not Scalable

Tangem acknowledged Ledger’s publication in a July 9 response, saying the research concerns laser fault injection against a secure element and is not a practical mass-market attack.

The company said an attacker needs invasive access to a card, decapping and preparation work, side-channel measurement tools, a laser-fault-injection system and extensive hardware-security knowledge. It added that the process can visibly damage the card and demands time to tune the attack for the target.

Tangem’s response does not dispute that the laboratory demonstration reset a password. Instead, it frames the realistic threat around access, cost and expertise. Ledger’s report likewise says the setup is not within reach of an individual attacker, even while calling the weakness critical because a successful attack can take control of funds.

That distinction leaves users with a more specific risk profile than a typical phishing event. Our report on fake wallet apps targeting Ledger and Trezor users covered attacks that can scale through malicious software and social engineering. The Tangem case is much harder to perform but relies on a card being lost, seized or otherwise physically exposed.

Tangem says its cards have no identifying information tied to an owner or wallet balance, which it argues reduces an attacker’s ability to select a high-value target. Neither company reported evidence that criminals had used Ledger’s technique against customers.

Unpatchable Cards Make Physical Security the Key Test

Ledger said cards already in circulation cannot be patched because Tangem cards do not have a firmware-update mechanism. Tangem describes that immutability as a way to reduce post-deployment software risk, but it also means a discovered card-level weakness cannot be removed with an app update.

The consequence is not a universal instruction to abandon card wallets. The published attack is costly, targeted and physical. But it does mean users should treat custody of every backup card as custody of the wallet itself, rather than assuming a forgotten or stolen card is protected solely by a password.

The same basic lesson surfaced in the reported $2.24 million Trezor wallet break-in, although that case involved a different device and claims that were not a general product advisory. Hardware-wallet risk depends on the model, the attacker and whether the threat is remote, software-based or hands-on.

Alternative.me’s Crypto Fear and Greed Index read 25, or Extreme Fear, on Aug. 4. That reading does not measure any Tangem card’s exposure, but it underscores the risk-sensitive market backdrop for a security disclosure involving self-custody.

Fear & Greed Index

Aug. 4, 2026
25 Fear

The next facts to watch are narrow: whether Tangem publishes further mitigation guidance, whether Ledger releases additional testing detail, and whether either company reports a confirmed real-world use of the method. For now, the confirmed result is a difficult physical laboratory attack, not a remote compromise, and both companies agree that the cards’ physical security remains central to the threat model.

Stay up to date

Get the latest crypto insights delivered to your inbox

Fact-checked by: Daily Crypto Briefs Fact-Check Desk

Frequently Asked Questions

What did Ledger researchers find in Tangem cards?

Ledger Donjon said it used a precisely targeted nanosecond laser pulse to reset a Tangem card password without the old password or a backup card, potentially allowing control of the funds associated with that card.

Can existing Tangem cards be patched after the laser attack disclosure?

Ledger said cards already in circulation cannot receive a firmware patch because they have no firmware update mechanism. Tangem says the attack needs invasive physical access, specialised equipment and expert laboratory work.

Does the Tangem laser attack affect every user remotely?

No. The published demonstration requires physical possession of one card, a laboratory laser-fault-injection setup and substantial security expertise. Neither Ledger nor Tangem described it as a remote attack.

What did Tangem say about Ledger's laser-attack research?

Tangem said the research concerns a physical, laboratory-based attack that is not scalable and requires extensive preparation, side-channel analysis and expensive equipment.

What should Tangem card holders watch next?

Card holders should follow future official security guidance from Tangem, keep cards physically secure and understand that the disclosed risk is physical rather than a remote wallet drain.