Skip to content
Critical Flaw in Tangem Crypto Cards Exposed by Ledger Researchers

Critical Flaw in Tangem Crypto Cards Exposed by Ledger Researchers

First seen 10 Jul 2026, 19:01 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 14:16 UTC
  • •A critical vulnerability allows password resets on Tangem cards via laser attacks.
  • •The attack requires specialized equipment costing approximately $250,000 and physical access.
  • •The vulnerability is unpatchable due to the lack of firmware updates for Tangem cards.

Ledger Donjon researchers disclosed a critical vulnerability in Tangem hardware wallet cards that allows an attacker to reset the card’s password through a laser fault injection attack. This exploit requires physical access to the card and specialized equipment costing around $250,000. The vulnerability affects all Tangem cards currently in circulation and cannot be patched due to the lack of a firmware update mechanism. The attack bypasses the firmware check that verifies the card's recovery state, allowing unauthorized password resets. Although the attack requires significant resources and expertise, it poses a risk if a card is lost or stolen. Tangem has disputed the practical significance of the findings, claiming the risk to everyday users is virtually non-existent. The vulnerability was disclosed to Tangem in February 2026, prior to public announcement.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-02-10
Vulnerability disclosed to Tangem
Ledger Donjon informed Tangem of the security flaw affecting their hardware wallet cards.
donjon.ledger.com
2026-07-10
Public disclosure of vulnerability
Ledger Donjon published findings on the Tangem card flaw, detailing the laser attack method.
Theblock.Co
2026-07-11
Further reporting on the vulnerability
Additional articles highlighted the implications of the vulnerability and the attack's feasibility.
Korben.Info

More articles in this cluster (5)

Common questions

What is the nature of the vulnerability?
The vulnerability allows an attacker to reset the password on Tangem cards using a laser fault injection attack.
Can this vulnerability be patched?
No, the vulnerability cannot be patched due to the lack of a firmware update mechanism in Tangem cards.
What should users do to protect themselves?
Users should ensure their Tangem cards are kept secure and avoid losing them, as the attack requires physical access.