Ledger Donjon Identified Tangem Wallet Vulnerabilities

Researchers published a laser fault injection attack method that compromises Tangem hardware wallets.

Updated on Oct. 6, 2026 in Cybersecurity

Isometric editorial illustration showing a concentrated beam of light striking a microchip on a circuit board to represent cybersecurity research.
Security researchers at Ledger Donjon disclosed a laser fault injection attack affecting Tangem hardware wallets, a vulnerability which remains unpatchable due to the device's immutable firmware design. AI Illustration. Upload story photo >

Live Poll

Do you trust wearable crypto wallets to secure your digital assets as well as traditional methods?

In July 2026, security firm Ledger Donjon disclosed a laser fault injection attack capable of bypassing the security features of Tangem hardware wallets. Because the devices utilize non-upgradable firmware, the identified vulnerabilities cannot be resolved through software patches.

Why it matters

The attack highlights the risks inherent in hardware wallets with immutable firmware designs intended to prevent remote compromise. While the technique requires expensive, specialized equipment, it challenges the long-term security posture of devices that cannot be updated after factory production.

Laser fault injection attacks against Tangem hardware require specialized equipment costing $250,000. These chips maintain a Common Criteria EAL6+ rating, though the physical design remains susceptible to localized tampering.

The players

Ledger Donjon

This is the specialized security research division of the hardware wallet manufacturer Ledger.

Tangem

This is a cryptocurrency wallet company that produced more than six million devices by the end of 2025.

Coldcard

This is a hardware wallet brand that experienced a major security incident involving firmware in mid-2026.

The details

The attack process involves using light-based injection to manipulate the secure element chip within the wearable or card wallet. Users trigger the device by tapping it against an NFC-enabled phone, which sends transaction data to the chip for signature.

Timeline

  1. December 2024: A bug in the Tangem mobile app logged private keys.

  2. May 2025: Tangem secured a third United States patent.

  3. Mid-2026: A Coldcard firmware bug caused $116 million in losses.

  4. July 2026: Ledger Donjon published laser fault injection attack findings.

The Tech Race

This vulnerability follows the industry pattern set by the Coldcard incident, underscoring how firmware integrity remains the primary vector for hardware wallet exploits. As the market approaches a projected $2.65 billion valuation by 2034, hardware security models are shifting toward increasingly complex, factory-sealed chips.

Users of Tangem devices should be aware that the hardware cannot be updated to patch physical security gaps due to its factory-locked firmware. While the equipment required for this specific attack is prohibitively expensive for most, it demonstrates that even highly rated chips are not immune to sophisticated laboratory-level physical tampering.

The takeaway

Hardware wallet users should prioritize keeping their physical devices in secure, controlled environments to mitigate the risk of sophisticated physical tampering. Investors should evaluate whether the convenience of non-upgradable firmware justifies the inherent security trade-offs against potential long-term vulnerability.

Further reading

For additional context on the evolving threat landscape for digital assets, visit our Cybersecurity section.

Source note: This article includes information reported by FinanceFeeds.

Live Poll

Do you trust wearable crypto wallets to secure your digital assets as well as traditional methods?