Executive Summary
In July 2026, Ledger's Donjon security team disclosed a vulnerability in Tangem crypto wallet cards, revealing that a precisely timed laser pulse aimed at the card's secure element chip can reset the card's password without the original password or backup card. This allows an attacker to gain control over the wallet and transfer funds. The attack requires physical possession of the card, specialized equipment estimated at $250,000, and leaves visible damage, making it impractical for widespread exploitation. However, due to Tangem's design, which lacks firmware update capabilities, this vulnerability cannot be patched, leaving all existing cards susceptible.
This incident underscores the challenges in securing hardware wallets against sophisticated physical attacks and highlights the importance of considering firmware update mechanisms in device design. While the attack's complexity limits its immediate threat, it raises concerns about the long-term security of devices that cannot receive updates to address discovered vulnerabilities.
Why This Matters Now
The Tangem wallet vulnerability highlights the critical need for hardware devices to have mechanisms for firmware updates to address potential security flaws. As physical attack methods become more sophisticated, the inability to patch devices post-production poses significant risks to users' assets.
Attack Path Analysis
An attacker with physical access to a Tangem wallet card uses a laser fault injection to reset the card's password without the original, gaining control over the wallet and its funds. This process involves precise timing and specialized equipment to manipulate the chip's behavior during password verification.
Kill Chain Progression
Initial Compromise
Description
The attacker gains physical possession of the Tangem wallet card.
MITRE ATT&CK® Techniques
Hardware Additions
Weaken Encryption: Disable Crypto Hardware
Firmware Corruption
Supply Chain Compromise: Compromise Hardware Supply Chain
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Device Security
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Hardware attacks on crypto wallets threaten secure asset storage, requiring enhanced physical security controls and encrypted traffic monitoring for digital financial infrastructure.
Computer Hardware
Laser-based chip manipulation exposes fundamental hardware vulnerabilities in secure devices, demanding improved tamper-resistant designs and enhanced manufacturing security protocols.
Computer/Network Security
Physical attack vectors bypassing cryptographic protections highlight gaps in security device design, necessitating comprehensive threat detection and anomaly response capabilities.
Semiconductors
Precise laser attacks on chip components demonstrate semiconductor supply chain vulnerabilities, requiring enhanced manufacturing controls and zero trust segmentation for production environments.
Sources
- Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patchedhttps://thehackernews.com/2026/07/laser-attack-resets-tangem-wallet.htmlVerified
- Laser Fault Injection (LFI) Attacks Against Secure Elementshttps://tangem.com/en/blog/post/laser-fault-injection-attack/Verified
- Tangem Bitcoin Wallet Cards Face Physical Attack Risk, Ledger Sayshttps://bitcoinfoundation.org/news/crypto-companies-news/tangem-bitcoin-wallet-cards-face-physical-attack-risk-ledger-says/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it can limit unauthorized access and reduce the blast radius of attacks by enforcing strict segmentation and identity-based policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Physical possession of the device may not be mitigated by CNSF controls, as they primarily address network-based threats.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation could limit the attacker's ability to access other network resources, reducing the potential impact of the compromise.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely prevent the attacker from moving laterally to other devices or workloads within the network.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control could provide insights into unauthorized access attempts, aiding in the detection of compromised devices.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement could restrict unauthorized outbound transactions, potentially preventing the exfiltration of funds.
While CNSF cannot recover lost funds, its controls could limit the scope of the attack, potentially reducing overall financial impact.
Impact at a Glance
Affected Business Functions
- Wallet Security
- User Authentication
Estimated downtime: N/A
Estimated loss: N/A
Potential unauthorized access to cryptocurrency funds if the physical card is lost or stolen.
Recommended Actions
Key Takeaways & Next Steps
- • Implement hardware security measures to detect and prevent physical tampering.
- • Regularly audit and update firmware to address potential vulnerabilities.
- • Educate users on the importance of physical security for hardware wallets.
- • Develop mechanisms to detect unauthorized access attempts.
- • Consider implementing multi-factor authentication to enhance security.



