๐Ÿ“… Tuesday, 22 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Peneliti Tembak Kartu Dompet Kripto Ini dengan Laser - Password Jebol Tanpa Perlu Tahu Sandinya

Researchers Blast Crypto Wallet Card with Lasers - Password Bypassed Without Knowing the Code

Ledger’s Donjon security team has disclosed a hardware attack capable of resetting passwords on Tangem crypto wallet cards - paving the way for attackers to sign transactions and transfer funds linked to the card. All of this was achieved without ever knowing the original password.

However, before panicking, there are severe requirements that put this threat far out of reach for ordinary thieves.

A Single Laser Pulse at the Exact Spot

According to Ledger Donjon’s technical report, researchers fired a nanosecond laser pulse at a specific area on the card’s secure element. The pulse disrupted a verification check within Tangem’s firmware right as the password reset command was executed. Under normal conditions, Tangem cards require the old password before accepting a new one; the recovery process can only reset the password if the user possesses a backup card linked to the same wallet.

The attack bypassed the check verifying whether the card is genuinely in a legitimate recovery state - allowing a new password to be set without either the old password or a backup card. The team replicated this on three different cards; following initial research, each attempt reportedly took about two hours to set up and complete.

No Patch Available, but Requires a $250,000 Lab

The most troubling news: Tangem cards do not support firmware updates, meaning the company cannot distribute patches to devices already in customers’ hands. The vulnerability remains inherent to cards currently in circulation.

Even so, executing the attack is far from simple. An attacker must possess physical access to the card, master specialized expertise, and utilize laboratory equipment worth roughly $250,000 (around Rp4 billion). Researchers even had to cut the card open, strip away the protective layer to expose the chip, and wire it to specialized hardware - an invasive process that permanently damages the card, making it impossible to perform covertly and return unnoticed. The attack also does not work remotely: not via apps, internet connections, or NFC. Tangem described the risk to everyday users as “virtually non-existent” and noted that Donjon operates under Ledger, one of its primary competitors.

Lessons Behind Security Certifications

Ledger emphasized that these findings show even an EAL6+ certified secure element is not immune to every attack - security ultimately hinges on the firmware running inside it as well. For Tangem holders, the takeaway is straightforward: the greatest risk arises when a card is lost or stolen. Treating a missing card as a security incident and immediately moving funds to a new wallet remains the most sensible course of action.

Reported by crypto.news.


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share