- Ledger Donjon identifies a critical hardware vulnerability in Tangem wallets.
- Tangem responds, emphasizing the improbability of real-world exploitation.
- The alleged vulnerability involves a laser fault injection (LFI) attack.
Introduction to the Controversy
In a recent report that has stirred the crypto community, Ledger Donjon claims to have discovered a significant vulnerability in Tangem hardware wallets. The issue pertains to an advanced laser fault injection (LFI) attack, potentially enabling attackers to reset card passwords and access crypto assets. This revelation sparked a public debate between Ledger and Tangem, shedding light on security concerns in cryptocurrency storage technology.
Exploring the Vulnerability
According to Ledger Donjon’s findings, researchers successfully executed an LFI attack on Samsung S3D232A secure element chips used by Tangem cards. They demonstrated how a single laser pulse could bypass password recovery checks and set a new password without prior knowledge of the existing one. Critically, this vulnerability does not require knowledge of the current password or backup card and remains present even if recovery features are disabled.
Tangem countered these claims by asserting that such attacks necessitate physical access to the card, specialized laboratory equipment worth about $250,000, and weeks of intensive work. Hence, they argue it poses no practical threat to most users.
The Technicalities Behind LFI Attacks
The LFI method described by Ledger Donjon involves manipulating secure elements with precise laser pulses. This technique is known for its complexity and is typically confined to controlled laboratory environments. It cannot be executed remotely nor scaled effectively for widespread exploitation.
Despite this technical prowess, implementing such an attack demands specific expertise in hardware security alongside costly resources—making it impractical for targeting everyday users.
Tangem’s Response and Broader Security Concerns
Tangem emphasized that while LFI attacks are not unique to their products but rather a known category of physical attacks on secure microchips. They highlighted that no manufacturer can offer absolute protection against sophisticated physical attacks.
More pressing threats in today’s landscape include phishing attacks, malicious decentralized applications (dApps), fraudulent smart contracts, and social engineering tactics—posing greater risks than elaborate lab-based exploits like LFI.
Community Reactions and Industry Implications
The crypto community has shown varying reactions to this disclosure. Some experts caution against overestimating the practical risk of such vulnerabilities due to their high-cost execution barriers. Others emphasize maintaining basic security practices like safeguarding seed phrases over worrying about expensive lab-centric threats.
This controversy arises amidst increasing warnings from cybersecurity experts regarding evolving cyber threats within the crypto market—a sector already experiencing numerous hacks annually as reported by TRM Labs earlier this year.
As artificial intelligence tools emerge aiding hackers identify vulnerabilities faster than before—particularly within smart contracts—the importance for cryptocurrency projects conducting regular code audits becomes paramount rather than relying solely on pre-launch checks.
While insights from both Ledger Donjon’s discovery and Tangem’s rebuttal provide valuable perspectives into potential hardware wallet vulnerabilities—it ultimately underscores an ongoing need for vigilance across all fronts within cryptocurrency security strategies moving forward.
