Ledger's Donjon security team demonstrated that a precisely timed laser pulse can reset the password of a Tangem crypto wallet card, allowing attackers to set any password they choose. While the attack gives full control of the wallet, most users face low immediate risk due to the specialized equipment required.

मुख्य बिंदु (Key Takeaways)

  • A laser pulse can reset the password on a Tangem hardware wallet card.
  • Once reset, the attacker gains complete control over the wallet.
  • Physical attacks remain feasible despite modern cryptographic safeguards.

Ledger’s Donjon security team recently showcased a sophisticated physical attack where a laser pulse was directed at the chip embedded in a Tangem crypto wallet card. The precise timing and focus of the laser cause the card’s password to be overwritten, enabling the attacker to set a password of their choosing.

Technical Background

Tangem cards are prized for their secure encryption and offline storage, often serving as a hardware wallet for crypto assets. The new research reveals that a laboratory‑grade 1550 nm laser, delivering roughly 100 mW of power in a 10 ns burst, can target the internal microcontroller with enough energy to flip the password bits to a default state.

Impact and Risks

After the password reset, the original owner cannot recover the card using any previous backup or PIN. The attacker, now holding full access, can move funds without restriction. However, executing such an attack demands highly specialized equipment and precise knowledge of the card’s architecture, limiting the immediate threat to a relatively small audience.

Industry Implications

This discovery forces hardware wallet manufacturers to reassess their threat models. Traditional software‑only defenses are insufficient; manufacturers must consider optical shielding, multi‑layer chip packaging, and active laser‑detection sensors that can lock the device upon detecting abnormal light intensity.

Future Outlook

Ledger is reportedly evaluating firmware updates and potential redesigns to mitigate this vulnerability, though a true “patch” at the card level is technically challenging. Users are advised to store their wallets in environments where laser exposure is improbable and to employ additional layers of security such as two‑factor authentication and multi‑signature wallets.