<- ALL CYBER NEWS
Notable
Tangem, hardware wallet, laser fault injection, Ledger Donjon, crypto, physical attack

A Laser Pulse Can Reset a Tangem Wallet Card's Password, and the Card Cannot Be Fixed
Ledger's Donjon researchers showed that a precisely timed laser aimed at the chip in a Tangem crypto wallet card can reset its password to anything the attacker chooses. The flaw is in silicon that cannot be patched.
Researchers at Ledger's Donjon security team have shown that a precisely timed laser pulse, aimed at the chip inside a Tangem crypto wallet card, can reset the card's password to a value the attacker picks, as reported by The Hacker News. No knowledge of the old password is needed.
This is a physical attack, not a remote one, and that framing matters. It requires the attacker to have the card in hand and specialized equipment, so it is not a threat to a wallet sitting safely in someone's pocket. It is a threat to a card that is lost, stolen, or seized, where the owner assumed the password stood between an intruder and the funds.
The harder problem is that the weakness lives in hardware. Unlike a software bug, a flaw baked into a chip cannot be patched in the field, which means existing cards carry it for their lifetime. For a product whose entire pitch is safeguarding crypto keys, a hardware-level bypass is a difficult thing to live with.
The lesson generalizes beyond one vendor. Hardware security assurances are only as strong as the chip underneath, and physical access changes the threat model entirely. For high-value holdings, assume that a device an attacker can physically hold is a device an attacker may eventually open.
Sources: The Hacker News.