Web Analytics
Cryptopolitan
2026-06-03 18:50:19

Ledger finds vulnerability in older model of Trezor crypto wallet

Trezor and the chip maker Tropic Square have disclosed a hardware vulnerability in the TROPIC01 secure element chip used in the Trezor Safe 7 wallet. The vulnerability was found during an independent audit by rival Ledger’s security research team, Donjon. So far, Trezor claims that user funds and private keys were not compromised. What did Ledger’s audit of Trezor reveal? Researchers from Ledger’s Donjon team, the security division of Trezor’s direct competitor, found a flaw in the TROPIC01 secure element chip during an audit. This chip is made by Tropic Square , Trezor’s sister company, and is billed as the first secure element chip with publicly available hardware design and firmware source code. The researchers used a high-tech method called laser fault injection. The researchers physically opened the chip package and then shot a precise infrared laser at the silicon to mess with the signature verification process. This allowed them to run their own unauthorized code on that specific chip. Tropic Square provided commercial chip samples to Donjon for evaluation, and the team reported the flaw in late January 2026. After receiving Donjon’s findings, Tropic Square’s own engineers found a related attack path that could extract an additional secret tied to the chip’s PIN protection functions. What can Tropic Square or Trezor do to secure users more? Due to the vulnerability being at the hardware level, it cannot be patched through a software update for existing Safe 7 devices, Trezor confirmed . Tropic Square said it is already producing a new chip batch that addresses the flaw, but users do not need to take any action. The company stressed that the Safe 7 uses three independent physical security layers, and the TROPIC01 chip is only one of them. Private keys and wallet backups are not stored on the affected chip. Exploiting the vulnerability also requires physical possession of the device, disassembly, backside decapsulation of the chip package, and access to specialized laser fault injection equipment. Blockchain security firm Cyvers said that the attack appears “highly impractical” for real-world use. “Hardware wallet security should not be evaluated only by whether a chip can eventually be attacked in a lab,” Cyvers CEO Deddy Lavid said. In his view, phishing , seed phrase theft, and blind-signing are far larger threats for most users. Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free .

Crypto 뉴스 레터 받기
면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.