The post Tangem wallet brute force vulnerability revealed by rival Ledger appeared on BitcoinEthereumNews.com. A security flaw allowing hackers to brute force the PIN code of Tangem’s cold wallet cards by cutting off their source of power was revealed yesterday by Ledger’s white hat hacker team, Donjon. Ledger CTO, Charles Guillemet, announced the “tearing attack” on X after disclosing the exploit with the rival hardware wallet firm. Unfortunately for Tangem, Donjon noted that it can’t be patched on already existing Tangem cards.  In order to perform the attack, Donjon discovered that cutting a Tangem card’s source of power before it acknowledges a password attempt stops it from registering a failed password.  A hacker would then need to determine if they’ve found the right password. Donjon discovered that by analyzing the electromagnetic emissions the card emits with each attempt, they can see a pattern of peaked electromagnetic emissions indicating that the correct combination was found. By doing this, hackers can attempt as many passwords as they like without fear of activating any security protocols.  The makeshift antenna Donjon created to focus on the chip’s electromagnetic emissions Read more: Ledger exec’s alleged kidnap mastermind arrested in Morocco Donjon says it would normally take five days to brute force a four-digit code with Tangem’s security protections, and roughly 148 years to brute force an eight-digit code.  However, the “tearing attack” reduces this time to ~1 hour for a four-digit code, and ~460 days for an eight-digit code, as it allows for two and a half password attempts every second.   It estimates that the cost to carry all this out would come to $5,000, adding that, “While the setup cost is relatively low, making it accessible to a wider range of attackers, the need for physical proximity to the target card remains a prerequisite.” Regardless, there’s not much that can be done to fix the exploit for the… The post Tangem wallet brute force vulnerability revealed by rival Ledger appeared on BitcoinEthereumNews.com. A security flaw allowing hackers to brute force the PIN code of Tangem’s cold wallet cards by cutting off their source of power was revealed yesterday by Ledger’s white hat hacker team, Donjon. Ledger CTO, Charles Guillemet, announced the “tearing attack” on X after disclosing the exploit with the rival hardware wallet firm. Unfortunately for Tangem, Donjon noted that it can’t be patched on already existing Tangem cards.  In order to perform the attack, Donjon discovered that cutting a Tangem card’s source of power before it acknowledges a password attempt stops it from registering a failed password.  A hacker would then need to determine if they’ve found the right password. Donjon discovered that by analyzing the electromagnetic emissions the card emits with each attempt, they can see a pattern of peaked electromagnetic emissions indicating that the correct combination was found. By doing this, hackers can attempt as many passwords as they like without fear of activating any security protocols.  The makeshift antenna Donjon created to focus on the chip’s electromagnetic emissions Read more: Ledger exec’s alleged kidnap mastermind arrested in Morocco Donjon says it would normally take five days to brute force a four-digit code with Tangem’s security protections, and roughly 148 years to brute force an eight-digit code.  However, the “tearing attack” reduces this time to ~1 hour for a four-digit code, and ~460 days for an eight-digit code, as it allows for two and a half password attempts every second.   It estimates that the cost to carry all this out would come to $5,000, adding that, “While the setup cost is relatively low, making it accessible to a wider range of attackers, the need for physical proximity to the target card remains a prerequisite.” Regardless, there’s not much that can be done to fix the exploit for the…

Tangem wallet brute force vulnerability revealed by rival Ledger

For feedback or concerns regarding this content, please contact us at [email protected]

A security flaw allowing hackers to brute force the PIN code of Tangem’s cold wallet cards by cutting off their source of power was revealed yesterday by Ledger’s white hat hacker team, Donjon.

Ledger CTO, Charles Guillemet, announced the “tearing attack” on X after disclosing the exploit with the rival hardware wallet firm. Unfortunately for Tangem, Donjon noted that it can’t be patched on already existing Tangem cards. 

In order to perform the attack, Donjon discovered that cutting a Tangem card’s source of power before it acknowledges a password attempt stops it from registering a failed password

A hacker would then need to determine if they’ve found the right password.

Donjon discovered that by analyzing the electromagnetic emissions the card emits with each attempt, they can see a pattern of peaked electromagnetic emissions indicating that the correct combination was found.

By doing this, hackers can attempt as many passwords as they like without fear of activating any security protocols. 

The makeshift antenna Donjon created to focus on the chip’s electromagnetic emissions

Read more: Ledger exec’s alleged kidnap mastermind arrested in Morocco

Donjon says it would normally take five days to brute force a four-digit code with Tangem’s security protections, and roughly 148 years to brute force an eight-digit code. 

However, the “tearing attack” reduces this time to ~1 hour for a four-digit code, and ~460 days for an eight-digit code, as it allows for two and a half password attempts every second.  

It estimates that the cost to carry all this out would come to $5,000, adding that, “While the setup cost is relatively low, making it accessible to a wider range of attackers, the need for physical proximity to the target card remains a prerequisite.”

Regardless, there’s not much that can be done to fix the exploit for the current Tangem cards out there, as it’s not a patchable fix. As such, Donjon’s advice for at-risk users is to use an eight-character or more password with a mixture of letters, numbers, and symbols. 

Tangem isn’t fazed about card findings

According to Donjon, Tangem wasn’t fazed by Donjon’s findings and concluded it isn’t a vulnerability. “In their opinion, the proposed attack scenario does not pose a significant risk,” Donjon claimed. 

Because of this, a Donjon representative told Protos that Tangem didn’t award them a bounty, despite Donjon “following the responsible disclosure process.”

Indeed, Tangem told Protos that it rewards “practical, real-world vulnerabilities,” and not “a theoretical lab attack that is self-defeating by design and requires immense resources.”

Read more: Hacker could’ve printed unlimited ‘Ether’ but chose $2M bug bounty instead

According to Tanjem, Donjon’s method would essentially “physically destroy the card’s chip long before an access code could be guessed.”

It said that even if it survived, cracking a four-digit code would take months, and over 64 years if it was five digits. 

“The research oddly focused on four-digit PINs, while our cards support much stronger alphanumeric access codes with symbols, making the real-world challenge exponentially harder.

“For these reasons, the scenario remains purely academic. While the research is technically interesting, it does not represent a practical vulnerability or risk to our users,” Tangem concluded. 

Donjon, however, found Tanjem’s response to its findings “disappointing,” and called its arguments “inaccurate.”

  • Donjon claims the cards it tested never died, and that “the tearing process means there’s no writing done to the flash memory to wear it out.”
  • It insists that the exploit would speed up the brute force attack by “100x,” especially for weak passwords, which Tangem rejects.
  • Donjon also says it wasn’t a “sophisticated attack” thanks to the low cost, and the fact that this security test is required for a Basic level certification, such as an “EAL 3 grade.”

Ledger isn’t perfect either

Donjon Ledger is a security research team posted at the crypto hardware wallet firm Ledger. Beyond helping Ledger, it says, “From time to time, the team also works on improving the security of the ecosystem.”

There have been instances, however, where Ledger exploits have led to consequences felt by its users.

Read more: ‘Decentralized’ apps suffer after Ledger Connect Kit attack

One supply chain attack in 2023 allowed hackers to drain the wallets of users who use Ledger’s Connect Kit when a former employee’s account was breached.

In July 2020, Ledger revealed its e-commerce and marketing database had been breached, exposing the personal details of many of its customers.

By December, this data was leaked, and a series of scammers began sending fake Ledger wallets to exposed customers.

Got a tip? Send us an email securely via Protos Leaks. For more informed news, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.

Source: https://protos.com/tangem-wallet-brute-force-vulnerability-revealed-by-rival-ledger/

Market Opportunity
Threshold Logo
Threshold Price(T)
$0.006578
$0.006578$0.006578
+0.70%
USD
Threshold (T) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Is Doge Losing Steam As Traders Choose Pepeto For The Best Crypto Investment?

Is Doge Losing Steam As Traders Choose Pepeto For The Best Crypto Investment?

The post Is Doge Losing Steam As Traders Choose Pepeto For The Best Crypto Investment? appeared on BitcoinEthereumNews.com. Crypto News 17 September 2025 | 17:39 Is dogecoin really fading? As traders hunt the best crypto to buy now and weigh 2025 picks, Dogecoin (DOGE) still owns the meme coin spotlight, yet upside looks capped, today’s Dogecoin price prediction says as much. Attention is shifting to projects that blend culture with real on-chain tools. Buyers searching “best crypto to buy now” want shipped products, audits, and transparent tokenomics. That frames the true matchup: dogecoin vs. Pepeto. Enter Pepeto (PEPETO), an Ethereum-based memecoin with working rails: PepetoSwap, a zero-fee DEX, plus Pepeto Bridge for smooth cross-chain moves. By fusing story with tools people can use now, and speaking directly to crypto presale 2025 demand, Pepeto puts utility, clarity, and distribution in front. In a market where legacy meme coin leaders risk drifting on sentiment, Pepeto’s execution gives it a real seat in the “best crypto to buy now” debate. First, a quick look at why dogecoin may be losing altitude. Dogecoin Price Prediction: Is Doge Really Fading? Remember when dogecoin made crypto feel simple? In 2013, DOGE turned a meme into money and a loose forum into a movement. A decade on, the nonstop momentum has cooled; the backdrop is different, and the market is far more selective. With DOGE circling ~$0.268, the tape reads bearish-to-neutral for the next few weeks: hold the $0.26 shelf on daily closes and expect choppy range-trading toward $0.29–$0.30 where rallies keep stalling; lose $0.26 decisively and momentum often bleeds into $0.245 with risk of a deeper probe toward $0.22–$0.21; reclaim $0.30 on a clean daily close and the downside bias is likely neutralized, opening room for a squeeze into the low-$0.30s. Source: CoinMarketcap / TradingView Beyond the dogecoin price prediction, DOGE still centers on payments and lacks native smart contracts; ZK-proof verification is proposed,…
Share
BitcoinEthereumNews2025/09/18 00:14
U.S. Futures Fall And Betting Odds Rise As Government Shutdown Appears Imminent

U.S. Futures Fall And Betting Odds Rise As Government Shutdown Appears Imminent

The post U.S. Futures Fall And Betting Odds Rise As Government Shutdown Appears Imminent appeared on BitcoinEthereumNews.com. Topline U.S. stock futures fell early on Tuesday after a meeting of Congressional leaders from both parties and President Donald Trump failed to reach a deal on legislation to keep the government funded ahead of Wednesday’s deadline for a government shutdown. Vice President J.D. Vance, accompanied by House Speaker Mike Johnson (R-LA), Senate Majority Leader John Thune (R-SD), and Office of Management and Budget Director Russ Vought, is seen at a press conference following a meeting between President Trump and Congressional Democratic leaders. Anadolu via Getty Images Key Facts Dow Futures dropped 0.22% to 46,518 points in premarket trading early on Tuesday, while the benchmark S&P 500 Futures fell 0.15% to 6,703.50 points. The tech-focused Nasdaq Futures also fell 0.12% to 24,806.75 points. The Bureau of Labor Statistics— which produces monthly nonfarm jobs payroll data and is scheduled to do so on Friday—has warned it will suspend all operations if a shutdown occurs, in a move that could further raise concerns about the health of the job market. In addition to this, the White House budget office has signaled it could use a shutdown to carry out mass firings across several government agencies. What Do The Betting Markets Say About The Odds Of A Shutdown? Bettors believe the odds of a government shutdown have increased significantly after congressional leaders from both parties met with Trump at the White House on Monday but failed to reach a deal. Bookmakers on the crypto betting platform Polymarket now believe there is an 83% chance of a U.S. government shutdown in 2025 and a 79% chance of a shutdown by Wednesday. Both numbers have seen a significant spike in the past 24 hours, rising by around 11 percentage points. Bettors on Kalshi also believe there is a 77% chance of a U.S. government shutdown…
Share
BitcoinEthereumNews2025/09/30 21:54
Uniswap wins again in ‘scam token’ lawsuit

Uniswap wins again in ‘scam token’ lawsuit

Uniswap keeps winning in court. Illustration: Andrés Tapia; Source: Shutterstock.
Share
DL News2026/03/04 01:11