Ledger researchers use laser pulse to bypass Tangem card password
Security & Exploits ·
A physical fault-injection technique let Ledger's Donjon team override the password protection on Tangem hardware wallet cards, exposing a flaw the companies say cannot be fixed through software.
The Donjon security unit reported that a single nanosecond-length laser strike, aimed at a precise spot on the card's EAL6+ certified chip, was enough to manipulate one conditional check inside Tangem's firmware and force the device to accept an attacker-chosen password, according to donjon.ledger.com. The technique got around the platform's built-in fault-detection safeguards, and researchers noted the attacker does not need the card's original password or a paired backup card to pull it off, nor does disabling the recovery option block the exploit.
Because the flaw sits in firmware baked into the card's secure element, and Tangem cards have no mechanism for firmware updates, every card currently in circulation is described as permanently exposed to the method, with no software patch possible. The disclosure follows earlier Donjon findings against Tangem's ecosystem, including a bypass of the genuine-device check in the Android app and a brute-force weakness in the card's authentication protocol, with the laser-based attack representing a deeper look at the card hardware itself.
Executing the attack is not simple: Ledger says it required a lab setup costing roughly $250,000, deep expertise in hardware and software security, and considerable upfront work to map out the chip's behavior before the fault could be reliably triggered. Those barriers, the researchers say, put the technique out of reach for an individual attacker, even though the underlying vulnerability itself cannot be remediated. Ledger disclosed the issue to Tangem on February 10th, 2026, ahead of publishing its findings.
Tangem has pushed back on the practical significance of the discovery, telling theblock.co that the risk to everyday users is virtually non-existent given the cost and specialized equipment the attack demands. What remains unresolved is whether Tangem will offer any mitigation, such as a hardware revision or altered recovery design, for cards already in the hands of users, since the current generation cannot receive a firmware fix. Further detail on the vulnerability and related wallet security research is tracked at leviathan.news.