Laser Pulse Cracks Tangem Crypto Card Password in Seconds
Ledger's Donjon team showed a targeted laser can wipe the PIN on a Tangem wallet card, handing full control to whoever holds it.

Key points
- Researchers at Ledger's Donjon security team demonstrated a laser fault-injection attack that resets the password on a Tangem crypto wallet card.
- The attack needs physical possession of the card and lab equipment with precise timing, so it isn't a mass-market threat today.
- Tangem cards use a chip that can't be updated in the field, meaning already-shipped cards can't be patched.
- Once the password is reset, the attacker can move any cryptocurrency held by that wallet.
- Owners worried about the risk should treat the card like cash and never let it out of their sight.
A crypto wallet card is supposed to be the boring, safe option. You keep it in your drawer, tap it on your phone when you want to move coins, and trust that the PIN protects everything. Researchers just poked a hole in that story.
Ledger's Donjon security team, the in-house hackers at rival wallet-maker Ledger, aimed a laser at the tiny chip inside a Tangem card at exactly the right moment. That pulse nudged the chip into skipping a check, after which the card let them set a brand-new password without ever knowing the old one.
After that, the wallet is theirs. They can drain the coins.
Should Tangem owners panic?
No, and here is why. This is a lab attack, not something a pickpocket can do on the bus. It needs the physical card in hand, a laser rig aimed at a decapped chip (the plastic shaved off to expose the silicon), and timing gear you'd find in a hardware security lab. If a criminal has that much access to your card and that much specialist kit, you already have a bigger problem.
The uncomfortable part is what happens next. Tangem cards are built around a secure element, a locked-down chip that can't receive firmware updates once it leaves the factory. There's no patch coming for cards already in wallets and safes. Any fix ships in a future hardware revision.
The research was first reported by The Hacker News.
What is fault injection, in plain words?
Modern chips run millions of tiny checks a second. Fault injection means deliberately glitching one of those checks so it gives the wrong answer. Attackers use lasers or voltage spikes to do it. Aim at the right transistor at the right microsecond and a "is the password correct?" check can flip to "yes" when it should say "no".
Hardware wallet vendors have known about laser fault injection for years. Ledger's own products have been probed the same way, which is why Donjon exists in the first place: it's genuinely useful research, even when it's aimed at a competitor. Our 9 July story on the poisoned Injective SDK is a reminder that crypto key theft doesn't always require specialist lab gear, which makes the cases where it does a little easier to breathe about.
What should Tangem owners actually do?
Treat the card like a wad of cash in bearer form. Don't lend it, don't leave it in hotel rooms, don't post pictures of it. If you lose physical control of the card even briefly, move the funds to a fresh wallet.
For anyone holding meaningful amounts of crypto, split funds across more than one wallet from different vendors. Keep the bulk in cold storage that requires more than one device to authorise a transfer.
Tangem will need to answer whether a new hardware revision is coming and what it plans to do for existing customers. "Physical attack, out of scope" is a defensible line for a threat model. It's a harder line to hold when the physical attack has a working proof of concept and your chip can't be patched.
The failure mode here isn't the laser. It's shipping unpatchable hardware and hoping no one shows up with the right lab gear.
If your security model assumes attackers never get their hands on the device, you don't have a security model. You have a hope.



