Tangem Wallet Hacked? What Ledger Donjon’s $250,000 Laser Attack Actually Proves

If you’ve seen the headlines, you’re probably wondering whether your Tangem cards are about to be emptied by some guy with a laser. Here’s the short answer: No Tangem card has ever been remotely hacked, and no funds or private keys have been compromised. Full stop.

What actually happened is three separate stories got mashed into one scare. First, Ledger Donjon, the security lab owned by rival wallet maker Ledger, demonstrated a laser attack that needs the physical card, a quarter-million dollars of lab gear, and a destroyed card to pull off. Second, the same team showed a brute-force technique that also needs the card in hand, and only works well against weak passwords. Third, a logging bug in the Tangem app briefly exposed seed phrases for fewer than 0.1% of users. It’s been patched, and no keys were compromised.

None of these is a hack in the way the headlines imply. Every demonstrated attack requires the card physically in someone’s hands. Three events, three very different severity levels, zero real-world losses. That’s the whole picture, and the rest of this article is just the details.

Key Takeaways

No Tangem card has ever been hacked remotely or lost funds; every demonstrated attack, including Ledger Donjon’s ~$250,000 laser attack, requires physical possession of the card.

The tearing brute-force attack cracks a 4-digit PIN in about an hour instead of 5 days, but a random 8+ character password stays impractical to break, and the whole rig costs under $5,000.

The logging bug affected only users who activated with a seed phrase AND contacted support in-app within 7 days (under 0.1% of users); it was fixed in app 5.19.1/5.19.2, and all logs were permanently deleted.

How Tangem cards are supposed to protect you

Before the scary stuff, you need to know what you’re working with. A Tangem wallet is a credit-card-sized thing that taps your phone. The private key is generated on the card itself and never leaves it. That’s the core promise, and honestly, it’s a good one.

Under the hood is a Samsung S3D232A secure element, certified EAL6+. Your protection boils down to two things: holding the card, and knowing the password on it. Lose either half and you’ve got a problem. Backup works by pairing two or three cards together, so if you lose one, you tap another. Low drama, practical.

Now, the design fact everything in this story turns on: there’s no USB port and no firmware updates, ever. Tangem sells that as tamper-resistance. Nothing can be changed remotely, so nothing can be messed with. The awkward part is that the same immutability is exactly what makes the flaws below permanent.

The feature and the bug are the same thing. Keep that in your back pocket.

The Ledger Donjon laser attack

The Ledger Donjon laser attack is a lab-demonstrated physical attack that resets a Tangem card’s password without knowing the old one. It requires the card in hand, roughly $250,000 of lab equipment, and the card gets destroyed in the process. That’s the definition. Everything else is detail.

How the laser actually breaks in

The mechanism is one weird timing trick, not a Hollywood hack. A precisely timed laser pulse makes the card’s recovery-mode check misfire, and once that check fails, the SetPin function then lets the attacker set a fresh password, with no knowledge of the previous one required. Attacker’s in.

You might be tempted to open the app and disable recovery mode. Don’t bother. The same check runs on every card regardless of that setting, so flipping it off doesn’t save you. The attacker pries the card open, removes the metal panel over the silicon, and fires the pulse.

And here’s the detail that makes the scenario feel less hypothetical: it needs no backup card. Just the one card in hand is enough. Once inside, they can sign transactions and drain the wallet.

What it actually takes to pull off

The numbers are the reassurance. The rig costs roughly $250,000. Nobody’s building this in a garage. Add deep hardware expertise, the kind you don’t get from a YouTube tutorial, and a card that’s visibly cut open, so you’d know immediately if someone gutted yours.

Even fully tuned, the attack takes about 2 hours per card. It’s reliable and repeatable, but slow and hands-on. And there’s no remote version. It takes the card, the lab, and the hours. Remote hackers need not apply.

Here’s the uncomfortable part said plainly: this affects every Tangem card in circulation, and there’s no patch coming, because the cards have no firmware update mechanism at all. Donjon itself put it as “there’s no patch, but the attack is physical and invasive.” They called the finding critical, and it carries weight, because that lab has broken other wallets too. The disclosure was reported on February 10, though the year is inconsistent across coverage, so I won’t pretend to know which one.

Tangem’s response and the disputed disclosure

Tangem pushed back hard. Their position: the attack is lab-only, doesn’t scale, required destroying cards just to map the chip, and poses “virtually non-existent” practical risk for everyday users. They declined to classify the findings as vulnerabilities. They also said the product is “fully safe against real-world attack scenarios,” and pointed out there’s never been a real-world laser-attack loss on any hardware wallet, plus, Donjon belongs to rival Ledger, so take the framing with that in mind. Honestly, the assessment holds up given what the attack demands.

Their argument isn’t crazy, and it deserves a fair airing. The technique works against secure elements generally, not just Tangem, so no brand gets to feel smug. Another point from Tangem: the cards don’t show what they hold. A thief with your card can’t tell $50 from $50 million, so there’s no picking targets.

And yes, there’s spice here: Donjon belongs to Ledger, a direct competitor. Acknowledge it, note that it doesn’t automatically make the finding fake, and move on.

One fact deserves its own beat: zero known real-world losses from laser fault injection on any hardware wallet, ever. That’s the single most reassuring number in this whole mess. It’s history, not a guarantee, but it’s history.

The disclosure timeline, walked

It started June 12, 2025, with the report and a proof-of-concept video. Tangem acknowledged it the same day, which is a decent start for everyone involved. Follow-ups came July 15 and August 19, with Tangem still reproducing the issue on July 18 and August 20. That’s weeks of back-and-forth rather than a standstill. On September 8, Donjon asked for mitigation or at least aligned communication, which was the pressure point before things went public.

Then September 11: Tangem said the findings don’t qualify as vulnerabilities and told Donjon to go ahead and publish. That’s a bold move, and you can weigh it however you like. Publication was set for September 16, five days after the go-ahead, under a 90-day responsible disclosure window. No villains, no heroes.

Just dates. The report was authored by security engineer Baptistin Boilot.

Why three clean audits and two demonstrated attacks coexist

Here’s the part that confuses people. Kudelski Security audited Tangem in 2018, Riscure in 2023, Cure53 in 2026. Three independent audits, no vulnerabilities found. Over a million cards shipped with no known systematic incident. The certificates and audit reports are published openly, so you can read them yourself.

So how do both things stay true? Because audits and Donjon-style fault injection measure different threat tiers. Audits look at code, logic, and standard attack surfaces. Donjon straps a card under a laser and attacks the physics of the chip. Different games.

Where both sides actually agree is narrow: a lost, stolen, or seized high-value card. That’s the one scenario where this matters, and it’s targeted, not random. If a valuable card of yours goes missing, move the funds immediately, using another card in the set or the seed phrase. Speed is the whole play here.

Bottom line: Audits check code and logic; laser fault injection attacks the chip’s physics. Both can be true at once — a clean audit never rules out a lab-grade physical attack.

The tearing brute-force attack and what it means for your password

Yes, this one is demonstrated, and it’s cheap by comparison, under $5,000 of gear. But it still needs the physical card, and a random 8+ character password makes it impractical anyway. That’s the answer.

How it beats the security delay

First, the defense as designed: after 6 wrong password tries, the card adds a 1-second delay, growing to 45 seconds. Since you can’t erase the card without the password, that delay is the entire game. Six tries, then wait. Do the math on a 6-digit PIN and it stops being worth anyone’s time.

The bypass exploits the failure counter that runs the delay. Cut the card’s power within about 6700 microseconds of sending the command, give or take 1000 depending on the card and even the temperature, and the delay never triggers. Cut the wire before the alarm wires up. Meanwhile, the card’s electromagnetic emissions differ slightly between a correct and incorrect password before the cutoff, so the card leaks an answer through physics.

The researchers timed it all with a Proxmark 3 rdv4, and yes, they scalpeled the card open and soldered on their own antenna. One sentence of heist movie, moving on.

The result: roughly 2.5 guesses per second versus 1 per 45 seconds. That’s over 100x faster. One honest note: Donjon also tried an EM attack on the read-wallet command authentication and it didn’t pan out. Inconclusive, partly because they had no source code access and the reader field added noise.

Their own read is that path doesn’t look vulnerable. Credit where due.

The dormant secure channel

This is the detail that made me put my coffee down. Tangem shipped a secure channel in the app and on the card, then never turned it on. Built, shipped, unused. Dead code.

The researchers switched it on by flipping a single boolean in the smartphone app. One line of code. And because the channel’s encryption key derives from your password, cracking the channel key means cracking the password. The way in was a security feature Tangem doesn’t even use. I’m not going to speculate on why it was left off, but that’s the finding.

What your password is actually worth

Here’s the money table:

PasswordNormal (1 guess/45s)With the attack
4-digit PIN~5 days~1 hour
6-digit PIN~520 days~4.5 days
8-digit PIN~143 years~460 days

Notice the pattern: every extra digit helps way less than people assume. And a million common dictionary passwords can be tried in about 4.5 days. If your password is on a list, that’s your clock, not the theoretical 460 days.

The honest nuance: a fully random 8-character password mixing digits, letters, and symbols stays impractical to crack. The real threat is human-chosen passwords. So be random. Donjon proposed that Tangem enforce 8+ characters with a digit, letter, and symbol, and block junk like “passw0rd!” you’ve seen that form on every website you’ve ever used. Note those are proposed, not confirmed shipped, and if you already run a weak password, changing it is on you.

The logging bug: was your seed phrase exposed?

The Tangem app logging bug exposed seed-phrase keys only for users who activated with a seed phrase AND contacted support through the app within 7 days. That’s under 0.1% of users. Still, incidents like this raise what are the disadvantages of tangem? The honest answer covers single-device backup questions, the seed phrase approach, closed-source elements, and vendor lock-in. No keys were compromised, no funds were lost, and if you never messaged support in-app, you weren’t affected, that settles it for most readers.

What actually happened

During seed-phrase activation, imported or generated, the app wrote the private key straight into its logs. The exact thing logs must never contain. The bug lived in an NFC performance-logging feature built to speed the app up, and it slipped past code review and testing. A performance tweak broke a security rule. Every software shop has one of these in its past.

The leak path is the unusual part: those logs could be pulled during support interactions. Customer service, of all things. This was a plain software screw-up, nothing like the lab attacks, and worth keeping in a separate mental box.

Who was actually in the blast radius

You only got burned if you activated with a seed phrase and contacted support in-app within 7 days. Both conditions had to line up. Two filters, so the overlap is tiny. Seedless users were never exposed at all, because their keys were generated on the card chip and never touched the app. Logs were kept briefly and erased, which shrinks the window further without eliminating it.

Want to check yourself in under a minute? Logs only went out if you manually contacted support, never auto-sent. Search your email history, drafts included, for support messages and compare against your activation date. Then open the app: the wallet info bar shows “Seed phrase” after the device count if you activated with one. Ten-second answer.

The fix, and the drill

Fixed in app 5.19.1 on the App Store and 5.19.2 on Google Play, and no private data gets logged anymore. All support logs and attachments were permanently deleted, closing the exposure path retroactively. Tangem also pinged possibly-affected seed users with an in-app notification. If you got one, take it seriously.

If you were affected, the drill is: update the app, move funds out, factory reset, reactivate fresh, move funds back. Tedious but straightforward, and if you want the full picture of the device itself, this hands-on tangem wallet review covers setup, security, and everyday use. And a blunt scam guard: real Tangem employees never DM first on Telegram or social. Anyone who does is fishing. The company runs a bug bounty with real rewards, which is how they’d rather hear about problems.

Why the flaws can’t be patched, and what EAL6+ doesn’t cover

No, EAL6+ doesn’t mean a wallet can’t be hacked. The certification covers only the Samsung S3D232A chip and its built-in defenses, not the wallet-maker code Tangem layered on top. Good cert, wrong floor. And that’s exactly where these flaws live: the wallet code, not the certified chip. So “we’re EAL6+” doesn’t answer anything.

The tradeoff here is the same design choice wearing two hats. Sealed, non-updatable firmware gets sold as tamper-resistance: nothing can be changed remotely, so nothing can be tampered with. The same immutability makes Donjon’s findings permanent on every card already shipped. I wish I could soften that, but I can’t.

The only fixes that can actually land are app-side. Donjon’s idea of bumping the failure counter before checking the password is impossible without firmware changes. The 8+ character password policy is the realistic path, and again, it’s proposed, not confirmed implemented.

Tangem isn’t uniquely exposed: Trezor, Coldcard, and the wider record

No brand comes out of this clean. Donjon cracked the TROPIC01 chip in the Trezor Safe 7 with the same laser technique, pulled seeds from the Trezor One and T years ago with a rig that cost about $100, and Coldcard’s five-year entropy flaw led to $116M to $130M in actual thefts. The grass is not safer.

Donjon’s other targets

The TROPIC01 work bypassed the firmware signature check, but Trezor’s three security layers held, including the one guarding the PIN, and a stopgap shipped alongside hardened next-gen silicon. Land the contrast: Trezor could patch. Tangem’s cards can’t.

The cost gradient tells the whole story: about $100 to gut a Trezor One or T, which had no secure element, under $5,000 for the Tangem tearing attack, $250,000 for the laser. What wallet makers spend on security shows up directly as attacker cost. It also answers why laser and fault-injection research matters for every secure element chip: it’s the class of attack that tests what certifications can’t, and no vendor is exempt.

The Coldcard inversion

Firmware 4.0.0, shipped in March 2021, and on-device seed generation bypassed the randomness chip in favor of a predictable software stand-in. Nobody caught it for five years. That’s the scariest part, not the bug itself. Affected models run Mk2 through Mk5 and the Q, depending on which firmware created the seed, and updating doesn’t fix an existing weak seed. You’d need a new one and a full migration.

Since July 31, 2026, over $116M, with some estimates near $130M, has drained from more than 5,200 addresses. The pace is the story: 594 BTC, about $38M, out of roughly 500 wallets in 25 minutes. 1,367 BTC by August 2, another 449 on August 3. And the victims were the careful ones, cold storage, steel-stamped seeds. Vendor selection failed, not user error.

Coinkite said it didn’t know about the “complex and subtle series of bugs” and speculated an attacker used AI to comb their open-source firmware. That’s their speculation, label it as such, and note their own AI-assisted review also missed it. Even the good tools blink. If you migrated a vulnerable Coldcard seed elsewhere, you’re still exposed; Block and Bitkey flagged that. Trezor, Blockstream, Foundation, and Tangem all say their users are safe unless they brought a Coldcard seed over.

So here’s where the whole thing lands: the wallet with two demonstrated lab flaws has lost nothing. The most respected wallet in the space lost everything. On the scorecard: Coinkite has a strong rep now carrying a five-year flaw. Ledger has the messiest corporate record, the 2020 shop breach with over a million records, the 2023 Ledger Recover blowup, the December 2023 Connect Kit phishing that took about $484,000, yet none of it touched the hardware.

Tangem has clean audits, two unpatchable findings, and a patched app bypass, which was Donjon’s third Tangem finding overall. No overall winner. That’s the honest result.

Field note: Attacker cost tracks vendor security spend — about $100 for a Trezor One, under $5,000 for the tearing attack, $250,000 for the laser. None of these attacks has ever worked remotely.

What to actually do: a ranked risk ladder

Protecting your Tangem funds comes down to an 8+ character mixed password, an updated app, and basic phishing and seed hygiene. The threats that actually cause losses are ordinary ones, not lab lasers.

Where real losses come from

Per both sides’ own statements, the overwhelming majority of losses come from everyday failures: slip-ups with seed phrases, malicious apps, fraudulent contracts, and phishing. Then weak-PIN brute force, which needs under $5,000 of gear and drops a 4-digit PIN in about an hour. Last, the laser attack: $250k, per-card destruction. People panic about the headline attack while leaving the ordinary vectors wide open. Don’t be that guy.

The one scenario both parties flag remains a lost, stolen, or seized high-value card. If that happens, move funds immediately.

Concrete moves that actually matter

  • Set an 8+ character password with digits, letters, and symbols. Tangem’s minimum is 4 alphanumeric characters. The gap between the minimum and the smart choice is the whole point.
  • Update the app, and buy hardware only from official sources.
  • For serious money, set up a 2-of-3 multisignature (multisig) wallet across different manufacturers, meaning any two of the three keys must sign a transaction, so one vendor’s flaw can’t take you down alone. Dice-rolled seeds sidestep firmware RNG bugs entirely, which the Coldcard story just made newly relevant.
  • Spend about 15 minutes a quarter checking your cold storage. Cheap insurance paid in time, not money.

On picking a wallet in the first place: buy on documented incident history and disclosure quality, not spec sheets. Five minutes searching a vendor’s name plus “incident,” “breach,” or “vulnerability” before buying pays off better than any certification logo.

Quick zoom-out, kept separate from the security story: Bitcoin sat around $64,100 on August 5, 2026, amid a rough stretch that included the wallet disaster, two drained perp DEXs, and the first US spot ETF closing. If you DCA through Coinbase in Europe, which runs under a Luxembourg MiCA licence, the default in-app recurring buy costs about 2.5% (3.49% by card), while SEPA plus a monthly limit order in Advanced runs maker fees from 0.6%. On €200 a month, that’s about €60 a year, and it costs you ten extra minutes a month. Also, keep the plan running through ugly news weeks; pausing DCA when headlines are worst tends to cost you.

Where does that leave the keep-or-rethink question? Given that the threat model is entirely physical possession, most owners should keep the cards. The password is the upgrade. It’s exactly the kind of gear decision we like around here: a tradeoff you can actually price, in dollars and hours.

Frequently Asked Questions

Is the Tangem Wallet safe from hackers?

Against remote hackers, yes — no Tangem card has ever been remotely hacked and no private keys or funds have been compromised. Every demonstrated attack, including Ledger Donjon’s ~$250,000 laser attack, requires physical possession of the card, roughly a quarter-million dollars of lab gear, and destroys the card in the process. The realistic threats are ordinary ones: weak passwords, phishing, and seed-phrase slip-ups.

can a tangem wallet be hacked remotely, or does an attacker need the physical card?

An attacker needs the physical card. The laser attack requires the card in hand, ~$250,000 of equipment, deep hardware expertise, and about 2 hours per card — and leaves the card visibly cut open. The tearing brute-force attack also needs the card, and even then a random 8+ character password stays impractical to crack. No remote version of any attack exists.

is the tangem tearing and brute force attack practical for stealing crypto?

Only marginally. The rig costs under $5,000 and boosts guessing to roughly 2.5 attempts per second, cracking a 4-digit PIN in about an hour instead of 5 days — but it still requires the physical card, and a fully random 8+ character password mixing digits, letters, and symbols stays impractical to break. A million common dictionary passwords can be tried in about 4.5 days, so human-chosen passwords are the real exposure.

Photo of author

Oliver

Oliver is an aspiring automotive journalist covering all things cars and motorsports. Drawing on his lifelong passion for vehicles, he provides engaging reviews and stories from his adventures in the automotive world. Oliver pairs his writing with photography to give readers an insider's perspective.

Leave a Comment