What the Tangem Laser Attack Teaches Us About Hardware Wallet Security

17 Jul 2026

hackers
logo-ngrave-perfect-key-hardware-wallet-cold-security2
NGRAVE The first end-to-end security solution to manage your crypto.

What the Tangem Laser Attack Teaches Us About Hardware Wallet Security

Understanding Ledger Donjon's Tangem research, Tangem's response, and what every hardware wallet user can learn from it.

  • Article Quick Links:
  • What happened?
  • Tangem's response
  • Physical security is part of wallet security
  • Why multiple layers matter
  • Anti-tamper is not a substitute for good security practices
  • Security is an ongoing process

Hardware wallets are designed to keep your private keys offline and protected, even if your computer or smartphone is compromised. But what happens when an attacker has physical access to the wallet itself?

A recently disclosed attack by Ledger's security research team, Ledger Donjon, has sparked discussion across the crypto community after demonstrating how they bypassed security protections on a Tangem wallet using an infrared laser. While the attack is highly sophisticated and far beyond the reach of ordinary criminals, it offers valuable lessons for anyone using a hardware wallet.

What happened?

Ledger Donjon's researchers demonstrated an attack against a Tangem card that required complete physical access to the device.

The researchers first opened the card to expose its secure element. They then used specialized laboratory equipment to fire precisely timed infrared laser pulses at the chip while it was processing sensitive operations.

Rather than extracting the private key directly, the attack caused the chip to temporarily malfunction at exactly the right moment, allowing the firmware to skip an important security check. This enabled the researchers to reset the wallet's access code without knowing the original one.

It's important to emphasize that this was not a remote hack. The attack required:

  • Physical possession of the wallet
  • Opening and modifying the device
  • Specialized laboratory equipment
  • Significant expertise in hardware security

This is a sophisticated attack that would typically only be realistic for highly capable attackers targeting wallets protecting substantial amounts of cryptocurrency.

Tangem's response

Tangem responded quickly after the disclosure, noting that the demonstrated attack requires invasive physical access, expensive equipment and advanced technical expertise.

We agree that this distinction is important. Most hardware wallet users are far more likely to encounter phishing attempts, malware or social engineering than a laboratory-grade laser attack.

At the same time, security research like this plays an essential role in strengthening the ecosystem. Understanding what is possible, even under highly controlled conditions, helps manufacturers improve future designs and helps users better understand their security model.

Physical security is part of wallet security

Many people think of hardware wallet security primarily in terms of protecting against online attacks.

But physical attacks deserve attention too.

If someone steals your wallet, every additional security layer matters. The goal is not necessarily to make attacks impossible(this lies beyond the realm of physics), but to make them increasingly expensive, time-consuming and technically challenging.

This is why physical security features such as secure elements, tamper-resistant designs and other hardware protections are so important. Each layer increases the attacker's effort and reduces the range of realistic threats.

Why multiple layers matter

One of the key lessons from this research is that no single security feature should be viewed as a complete solution.

A certified secure element provides strong protection for sensitive cryptographic material, but it is only one component of a secure architecture. Equally important are the surrounding security measures, including hardware design, firmware, authentication mechanisms and continuous security review.

At NGRAVE, our approach has always been based on layered security. ZERO combines multiple protective mechanisms, including a certified secure element, anti-tamper protections and an architecture designed to make sophisticated physical attacks significantly more difficult.

This layered approach is based on a simple principle: every additional obstacle increases the attacker's cost and complexity.

Anti-tamper is not a substitute for good security practices

Anti-tamper protections are valuable, but they should never create a false sense of absolute security.

Their purpose is to make physical attacks substantially harder, buy valuable time and increase the likelihood that an attack becomes impractical or detectable.

For that reason, our recommendation remains unchanged.

If you ever suspect that your hardware wallet has been physically compromised, do not continue using it. Instead, create a new wallet on a trusted device and transfer your assets to fresh addresses as soon as possible.

Good hardware security and good operational security always go hand in hand.

Security is an ongoing process

Responsible security research benefits everyone.

The work by Ledger Donjon demonstrates how independent research can uncover new attack techniques, giving manufacturers the opportunity to improve their products and helping users better understand the evolving threat landscape.

No hardware wallet should ever be considered "unhackable." Security is a continuous process of designing strong defenses, learning from new research and continuously raising the bar for attackers.

As the crypto ecosystem matures, this kind of collaboration between researchers and manufacturers ultimately makes everyone's digital assets more secure.

If you'd like to learn more about NGRAVE's layered approach to hardware wallet security and the design principles behind ZERO, you can explore the product here:

logo-ngrave-perfect-key-hardware-wallet-cold-security2
The first end-to-end security solution to manage your crypto.
NGRAVE

NGRAVE is a digital asset security company and the creator of the world’s most secure cryptocurrency wallet, NGRAVE ZERO. NGRAVE ZERO was developed in collaboration with a world-renowned team of cryptography and security experts.