Ledger Donjon finds Tangem card PIN reset via laser

Researchers say a focused laser fault injection can reset Tangem card PINs if attackers have physical access and specialist lab equipment; Tangem calls the user risk ‘virtually non-existent.’

Ledger Donjon, the security research unit within Ledger, reported a vulnerability in Tangem hardware wallet cards that allows a PIN reset using a laser fault injection. The group told Tangem about the issue in February.

The exploit requires removing or exposing the card's secure element, connecting custom hardware, and applying a focused nanosecond laser pulse to a precise area of the chip. The researchers said their laboratory setup cost about $250,000 and that the attack also requires side‑channel analysis tools and hardware security expertise.

In testing, the fault injection bypassed a firmware check that confirms whether a card is in an authorized recovery state. That bypass allowed the SetPin instruction to accept a new PIN without the existing password or a backup card. After a PIN reset, an attacker can use the card to sign transactions and move funds tied to the wallet.

The team reproduced the exploit on two additional Tangem cards after the initial demonstration. Each reproduction took roughly two hours of preparation and exploitation. Because the affected cards do not support firmware updates, the researchers said devices already in circulation cannot be patched.

Ledger Donjon recommended several firmware hardening measures, including adding multiple independent checks for sensitive operations, strengthening state validation, and ensuring password changes stay protected when recovery features are disabled. The group noted that high‑level certifications such as EAL6+ do not prevent fault injection if firmware contains exploitable logic errors.

Tangem posted a response on X, calling the practical threat to everyday users “virtually non‑existent” given the need for expensive equipment, physical possession of the card and specialist expertise. The company also highlighted Ledger Donjon's relationship to Ledger and wrote that, with sufficient time and resources, firmware on any secure element can be reverse‑engineered and exploited.

Ledger Donjon emphasized the attack is physical and invasive and cannot be performed covertly with the card returned intact. The researchers said the primary exposure is a lost or stolen card; cards that remain in their owners' possession cannot be targeted by the described method.

The content on The Coinomist is for informational purposes only and should not be interpreted as financial advice. While we strive to provide accurate and up-to-date information, we do not guarantee the accuracy, completeness, or reliability of any content. Neither we accept liability for any errors or omissions in the information provided or for any financial losses incurred as a result of relying on this information. Actions based on this content are at your own risk. Always do your own research and consult a professional. See our Terms, Privacy Policy, and Disclaimers for more details.

Articles by this author