Worked example · 2025-20
Tangem card physical-access disclosures (Ledger Donjon) — hardware — 2025-09 → 2026-07
Summary
Tangem sells a card-format hardware wallet built on a Samsung S3D232A secure element (EAL6+ certified). Unlike firmware-updatable hardware wallets, Tangem cards are designed without an update path: the firmware is fixed at manufacture. Between September 2025 and July 2026, Ledger's Donjon security research team published two independent physical-access attacks against these cards.
1. Tearing attack (disclosed 2025-09-18). Donjon found that cutting power to the card before a failed password attempt is committed prevents the failure counter from incrementing, defeating the card's brute-force limit and permitting unlimited attempts. Paired with electromagnetic-emission analysis to detect when the correct code is entered, the technique achieves roughly 2.5 attempts per second at an estimated equipment cost of ~$5,000 (including a makeshift antenna for EM capture). The attack requires physical proximity to the card. Its practical impact is entirely a function of access-code length: a 4-digit code that would take ~5 days to brute-force falls in ~1 hour, while an 8-digit code moves from ~148 years to ~460 days.
Tangem declined to treat the finding as a vulnerability, characterising it as "a theoretical lab attack that is self-defeating by design" on the basis that the card would be physically destroyed before a code could be cracked, and declined to award a bug bounty despite Donjon having followed responsible disclosure. Donjon publicly described the response as "disappointing" and "inaccurate", stating that the test cards were not destroyed during testing and that the ~100× speed improvement against weak codes was a real reduction in attack cost.
2. Laser fault-injection attack (reported to Tangem 2026-02-10; published 2026-07-10). Donjon demonstrated that a precisely timed laser pulse directed at the exposed secure-element die resets the card's access code to an attacker-chosen value — with no knowledge of the previous code and no backup card required. The attack requires cutting the card open to expose the chip, approximately two hours per card, and a laboratory Donjon estimates at ~$250,000. The physical intrusion leaves unmistakable damage. It cannot be performed remotely, and no CVE was assigned.
Tangem's response characterised the result as a lab-only physical method that affects secure elements as a class rather than Tangem cards specifically, assessed the practical risk as "virtually non-existent", and noted that no funds have been lost to laser attacks against any hardware wallet — a claim that is, as of this writing, accurate.
Both findings share the property that gives the pair its OAK significance: neither is patchable. Tangem cards have no firmware-update capability, so every card already sold carries both flaws permanently. Where the Kraken/Trezor STM32 result (T11.007.002 canonical anchor, 2020-01) was answered by a hardware revision shipping a secure element, and where Donjon's 2023 Ledger findings were remediated in hardware revisions, here the only defender-side responses available are access-code length, physical custody of the card, and — for holders whose physical-access threat model is non-trivial — device replacement.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| 2025-09-18 | Ledger Donjon publicly discloses the tearing attack (power-cut defeats failure counter + EM analysis detects correct code); announced by Ledger CTO Charles Guillemet. ~$5,000 equipment, ~2.5 attempts/sec | T11.007.002 (brute-force-limit bypass, physical proximity) |
| 2025-09 | Tangem characterises the finding as "a theoretical lab attack that is self-defeating by design"; declines bug bounty. Donjon responds publicly, calling the assessment "disappointing" and "inaccurate" | (vendor dispute — no OAK ref) |
| 2026-02-10 | Donjon reports the laser fault-injection access-code reset to Tangem (responsible disclosure) | T11.007.002 (fault injection against secure-element die) |
| 2026-07-10 | Laser attack published. ~$250,000 lab, card decapping required, ~2 hours per card, visible damage | T11.007.002 (public disclosure) |
| ongoing | No fix possible — Tangem cards carry no firmware-update path by design; all sold cards affected | (mitigation surface = replacement) |
Realised extraction
$0 — coordinated security research. No on-chain exploitation of either technique has been observed. The realistic threat scenario for both is a lost, stolen, or seized card whose holdings are known to the attacker in advance — the same scenario that governs the rest of the T11.007.002 family.
What defenders observed
- Access-code length is the whole mitigation, and the gradient is steep. The tearing attack reduces a 4-digit code to ~1 hour and an 8-digit code to ~460 days. This is the same structural role BIP39 passphrase strength plays for the STM32-class attack: it does not prevent the attack, it bounds the outcome. For card-format hardware with no passphrase layer, code length is the only lever the user controls, and the default-length choice is therefore load-bearing in a way that vendor UX rarely communicates.
- "Unpatchable by design" is a trade-off, not an oversight. Removing the firmware-update path removes an entire remote-attack surface (malicious update, supply-chain firmware substitution — cf. T11.002). The cost is that every hardware-layer finding is permanent and population-wide. Defenders evaluating card-format hardware should price this explicitly: the device is more resistant to remote compromise and structurally unable to respond to physical-layer research.
- EAL6+ certification bounds the attack cost; it does not close the surface. The S3D232A is EAL6+ certified and still yields to a $250,000 laser lab. This is consistent with Donjon's own 2023 findings against Ledger's secure element: certification raises the attacker's floor from commodity to laboratory-grade. It is a cost statement, not an impossibility statement, and marketing that reads it as the latter is misreading it.
- The discloser is a commercial rival, and both risk framings carry interest. Ledger sells competing hardware; Tangem's dismissals defend a shipped product that cannot be fixed. Neither position makes the mechanism false — the tearing and laser results stand on their own technical merits — but a defender taking either vendor's risk assessment at face value is taking it from an interested party. The mechanism is the durable artefact; the severity framing is not.
- Detection is not available here. Neither attack produces on-chain or telemetry signal prior to extraction. The card's physical damage from the laser attack is observable only post-hoc, and the tearing attack leaves the card intact. The controls are all pre-event: code length, physical custody, and hardware selection against a stated physical-access threat model.
Public references
[hackernewstangemlaser2026]— The Hacker News, "Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched" (laser fault injection resets access code; Samsung S3D232A EAL6+ secure element; reported 2026-02-10, published 2026-07-10; ~$250,000 lab; decapping required; ~2 hours per card; no firmware-update path; Tangem's "virtually non-existent" risk assessment): https://thehackernews.com/2026/07/laser-attack-resets-tangem-wallet.html[protostangemtearing2025]— Protos, "Tangem wallet brute force vulnerability revealed by rival Ledger" (tearing attack: power-cut defeats failure counter, EM emission analysis; disclosed 2025-09-18 by Ledger CTO Charles Guillemet; ~$5,000; ~2.5 attempts/sec; 4-digit ~1 hour vs ~5 days, 8-digit ~460 days vs ~148 years; Tangem's "self-defeating by design" response and bug-bounty refusal; Donjon's rebuttal): https://protos.com/tangem-wallet-brute-force-vulnerability-revealed-by-rival-ledger/[incryptedtangemledger2026]— Incrypted, "Ledger and Tangem Publicly Argued Over a Wallet Hack via a Laser Attack" (the public vendor dispute over severity framing): https://incrypted.com/en/ledger-and-tangem-publicly-argued/- Cross-reference: T11.007.002 at
techniques/T11.007.002-physical-access-hardware-seed-extraction.md. - Cross-reference: 2023-01-ledger-donjon-side-channel at
examples/2023-01-ledger-donjon-side-channel.md(same research team; establishes that secure-element hardware raises attack cost to laboratory-grade without eliminating the physical-access surface). - Cross-reference: 2020-01-trezor-kraken-rdp-downgrade at
examples/2020-01-trezor-kraken-rdp-downgrade.md(canonical T11.007.002 anchor; contrast: answered by hardware revision, an option unavailable here).
Discussion
This pair extends T11.007.002 in one specific direction that the existing example set does not cover: a device class whose defender-side answer cannot be "update". Kraken/Trezor (2020) was structural at the STM32 layer and Trezor answered it two hardware generations later with an EAL6+ secure element. Donjon's 2023 Ledger findings were remediated in hardware revisions. In both cases the vendor had a path forward and the installed base had a migration story. Tangem's no-update design forecloses both: the cards in users' hands in July 2026 will carry these findings for their entire service life. That is not a criticism of the design choice — trading firmware-update risk for permanence is a coherent position, and it eliminates a real attack class — but it makes the purchase decision the security decision, permanently, which is a materially different defender posture than the rest of the family.
The second durable finding is quantitative and unusually actionable for retail: the tearing attack's yield is a step function of access-code length. Four digits is one hour of an attacker's time; eight digits is fifteen months. The same user, the same card, the same attacker, and a ~11,000× difference in cost, decided at setup by a person who has no reason to know any of this. Where the STM32-class attack has BIP39 passphrase strength as its bounding primitive, card-format hardware has code length and nothing else — and unlike a passphrase, it is chosen once, under no guidance, at the moment of least engagement.
Finally, the vendor dynamic is worth preserving for investigators as a framing caution rather than a finding. Both attacks were disclosed by a direct commercial competitor, and both were dismissed by a vendor that cannot ship a fix. Those two facts shape the public severity narrative in opposite directions and neither is disinterested. OAK's position is the mechanism: tearing defeats a failure counter for ~$5,000, laser fault injection resets an access code for ~$250,000, both need the physical card, neither can be patched, and code length bounds the first. Everything above that line is the two vendors' commercial argument with each other, and a risk team reading either party's press should price it accordingly.