**Laser Attack on Tangem Crypto Wallets: A Critical Look at Physical Security Risks**
A recent demonstration by researchers at Ledger’s Donjon security team has raised concerns about the physical security of Tangem crypto wallet cards. The team successfully used a precisely timed laser pulse to reset the card’s password, allowing unauthorized access to the funds without needing the original password or backup card. This vulnerability highlights a critical flaw in Tangem’s security model, with significant implications for users holding high-value crypto assets.
**How the Attack Works**
Tangem wallets are designed to be secure, utilizing a Samsung S3D232A chip certified to EAL6+ standards for tamper resistance. The wallet’s security relies on two factors: physical possession of the card and knowledge of the password. However, the password reset feature introduces a weakness.
Tangem sells cards in linked sets, allowing users to reset a forgotten password by placing two cards together. During this process, the card enters a recovery mode, accepting a new password without verifying the old one. The Donjon researchers discovered that a laser pulse timed precisely when the card checks for recovery mode can trick the chip into believing it is in recovery mode even when it is not. This allows an attacker to set a new password and gain full control of the wallet.
**The Practical Challenges**
While the concept is alarming, executing this attack is far from trivial. It requires:
– Physical access to the card
– A sophisticated laser rig
– Sensitive measuring equipment
– Deep hardware expertise
– A controlled lab environment (estimated cost: ~$250,000)
Additionally, the attack involves opening the card, causing visible damage. This makes it unsuitable for remote execution and difficult to perform discreetly.
**Tangem’s Response**
Tangem acknowledged the flaw but downplayed its immediate risk. The company emphasized:
– The attack is a physical, lab-based method, not a remote exploit
– Tangem cards contain no identifying or balance information, making targeted attacks unlikely
– Average users face minimal risk due to the high cost and complexity of the attack
However, the researchers argue that the flaw is inherent and unfixable, as Tangem cards cannot receive firmware updates. This design, intended as a security strength, also ensures that vulnerabilities discovered post-production remain permanent.
**Broader Implications**
This finding is part of a pattern of physical attacks on hardware wallets. Earlier this year, Donjon used similar laser fault injection techniques against Trezor’s TROPIC01 chip. While Trezor’s multi-layer security prevented fund loss, the incident underscores the evolving landscape of hardware wallet vulnerabilities.
Unlike earlier attacks on devices using standard microcontrollers, Tangem’s hardened chips raise the bar significantly—but as this research shows, they do not eliminate the threat.
**Recommendations for Users**
For most users, the advice remains unchanged: keep your wallet card secure and physically protected. If a Tangem card containing significant value is lost or stolen, the safest course of action is to move funds immediately using a different card or recovery seed, rather than relying on password protection.
**Conclusion**
While the laser attack on Tangem wallets is complex and costly, it exposes a fundamental vulnerability in an otherwise robust security design. It serves as a reminder that even the most secure hardware can be compromised under precise physical conditions, and that firmware-level flaws can have lasting consequences. For high-value holders, treating a lost or stolen Tangem card as a security breach is the most prudent response.
—
**Original Article Source:**
Ledger Donjon research team, “Laser Attack on Tangem Wallet,” *Ledger Donjon Security Research*, 2026. [https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh0BbJcQ3TUJxFvOCpAChyC5saD3RGgDCtLtVG-Wupee7poBksO2TzSWFtzQmjjoXuZ-9hnCNR3HuWdSsBv7YZl477fdOcjoOBh72RY4vJ9R0hxUWktV2R7wgTsRa-_Zz5Bj_ZGfQOVT8v292QJ55C9hMumk-IgXd-PVZ6LFu2ZDyCGwjNtJhCYb4W-mPDO/s1600/ll.jpg](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh0BbJcQ3TUJxFvOCpAChyC5saD3RGgDCtLtVG-Wupee7poBksO2TzSWFtzQmjjoXuZ-9hnCNR3HuWdSsBv7YZl477fdOcjoOBh72RY4vJ9R0hxUWktV2R7wgTsRa-_Zz5Bj_ZGfQOVT8v292QJ55C9hMumk-IgXd-PVZ6LFu2ZDyCGwjNtJhCYb4W-mPDO/s1600/laaser-flow.png)



