Ledger Researchers Find Laser Attack Can Reset Any Tangem Card Password, With No Patch Possible
Ledger's in-house security team disclosed a hardware vulnerability on July 9 that allows an attacker to overwrite the password on any Tangem NFC card wallet using a precisely aimed laser pulse, with no prior knowledge of the password required and no firmware fix available for any card ever sold.
The finding comes from Ledger Donjon, the Paris-based hardware maker's internal research unit, which privately notified Tangem on February 10, 2026, then published full technical details five months later. The attack exploits a single conditional check inside the password recovery function of the EAL6+-certified Samsung S3D232A secure element used in Tangem cards. That certification is the basis on which users and enterprises trusted the chip; as Ledger Donjon noted in its disclosure, EAL6+ certification does not guarantee immunity from physical fault attacks. By firing a nanosecond laser pulse at the chip at the right moment, a researcher can trick the processor into believing it is in recovery mode and accepting an attacker-chosen password. Ledger Donjon researcher Baptiste Boileau wrote in the disclosure that "the vulnerability does not require knowledge of the existing password or possession of a backup card."
How the Attack Works
Tangem's onboarding flow ties two or three cards together and includes a recovery feature that allows one card to reset another's password when both are physically present. The Ledger Donjon team found that faulting the chip's state check bypasses this requirement entirely, even when users had turned the recovery feature off. After an initial chip characterization phase of roughly two hours per card, the attack reaches a 100% success rate. The full lab setup, covering laser fault injection equipment, electromagnetic probes, and custom power delivery hardware, costs approximately $250,000.
Tangem responded by calling the practical risk "virtually non-existent" for everyday users. The company pointed out that the attack requires physical access to the card, destroys it in the process, and demands a highly trained operator working in a specialist lab. Tangem also questioned Ledger's motives directly, noting in a statement: "While Ledger Donjon presents itself as an independent research unit, it operates within Ledger, one of our largest competitors."
Ledger Donjon has previously disclosed vulnerabilities in hardware wallets from other manufacturers, including Trezor and Coldcard, as part of a documented coordinated disclosure practice. That history provides meaningful context for weighing the conflict-of-interest claim.
Ledger CTO Charles Guillemet pushed back in a thread on X, framing the situation as what he called "The Tangem Immutability Trap." His argument: the same design principle that protects Tangem cards from remote software injection makes it impossible to correct a confirmed physical flaw. "Security is never static… systems should be designed with human error and future failure in mind… users should be able to verify, adapt, and recover when assumptions do not hold," Guillemet wrote.
Tangem has argued that immutability is a deliberate security choice, not an architectural oversight. The company contends that a firmware update mechanism would open the door to "Dark Skippy" style supply-chain attacks, in which malicious code is injected through a fraudulent update. Guillemet's framing captures one side of a genuine trade-off: immutability closes a remote attack surface while leaving physical vulnerabilities permanently unaddressable after manufacture.
A Second Disclosure in Under Two Years
This is not Tangem's first public security incident. In December 2024, a Reddit post revealed that the company's mobile app was logging private seed phrases in support email chains. Tangem patched the issue in app versions 5.19.1 and 5.19.2, and the company said fewer than 0.1% of users were affected with no confirmed fund losses. Critics at the time faulted the company's slow and understated public communication, a criticism some observers are repeating now.
Tangem reported $61.3 million in revenue in 2025, up 102% year-on-year, and holds roughly 12% of the global hardware wallet market. Its user base grew 50% over the same period. The disclosure arrives as the broader hardware wallet market is expanding quickly, with analysts projecting a compound annual growth rate of 25.6% through 2031.
What This Means for Users Outside the United States
The vulnerability carries particular weight in markets where Tangem has been actively positioning itself as a first-time self-custody option. India ranks first globally in crypto adoption for the third consecutive year, with more than 93 million retail users, yet hardware wallet penetration sits below 2%. Tangem distributes through Etherbit.in in India and has explicitly marketed the card format to Pakistani users as a step-up from exchange storage. Pakistan is excluded from Tangem's new Visa payment rollout (Tangem Pay) but remains a growth target for the product line.
In Nigeria and Kenya, Tangem's primary use case centers on remittances and peer-to-peer transfers, where users typically hold smaller balances. Tangem argues that a $250,000 lab attack against a small-balance wallet is not a realistic threat for those users. South Africa presents a distinct profile: users there more commonly hold investment-grade amounts, and the risk calculus is correspondingly more relevant, though still constrained by the physical access requirement.
In July 2025, United Network announced NFC non-custodial card wallets aimed specifically at African and Middle Eastern markets. Tangem's vulnerability disclosure arrives at a moment when the card wallet form factor is gaining traction and new competitors are entering the space, giving the findings weight beyond the immediate question of individual user risk.
Developers integrating Tangem through its NFC or SDK interfaces, a common pattern in African fintech pilots, should review whether their threat models account for physical device seizure, particularly in enterprise or high-value contexts.
What Users Should Do Now
Because Tangem's firmware is immutable by design, no patch can be issued for any card already in circulation. Users who store significant holdings on a single card should consider splitting those holdings across multiple devices or migrating to a wallet platform capable of issuing security updates. For a card that is lost or stolen, the threat is real; moving assets immediately through the companion app remains the most effective mitigation available.