Trezor and Tropic Square revealed a vulnerability affecting the TROPIC01 chip that was identified during an audit conducted by Ledger Donjon, while emphasizingTrezor and Tropic Square revealed a vulnerability affecting the TROPIC01 chip that was identified during an audit conducted by Ledger Donjon, while emphasizing

Trezor Says Ledger-Discovered Safe 7 Chip Flaw Poses No Risk to User Funds

2026/06/03 20:12
3 min read
For feedback or concerns regarding this content, please contact us at [email protected]

Trezor and Tropic Square revealed a vulnerability affecting the TROPIC01 chip that was identified during an audit conducted by Ledger Donjon, while emphasizing that the Safe 7 wallet remains protected and that user funds are not at risk.

Trezor and Tropic Square have disclosed a vulnerability affecting one of the three independent security layers within the Trezor Safe 7 hardware wallet, while stating that the issue does not expose user assets to risk.

According to a statement provided by Trezor , the vulnerability was uncovered during an independent security review carried out by Ledger Donjon, the research division of rival hardware wallet provider Ledger.

Tropic Square supplied the affected TROPIC01 Secure Element chip to the Ledger Donjon for an independent assessment. Trezor stated that even if TROPIC01 were compromised, access to a user’s wallet, PIN, or funds would remain unlikely because the Safe 7 wallet is protected by several independent security mechanisms, including an additional secure element.

The disclosure provides a rare glimpse into how hardware wallet manufacturers respond to chip-level security weaknesses and underscores the increasing role played by independent researchers in evaluating and stress-testing crypto custody hardware.

Security Flaw Discovered During Independent Testing Process

According to Trezor, the vulnerability was identified during an independent security assessment launched by Tropic Square following the release of its TROPIC01 secure element in early 2025.

In January 2026, Ledger Donjon notified Tropic Square that a laser fault injection attack had been successfully executed against the chip, enabling researchers to retrieve certain secrets stored on the device and bypass firmware signature verification in a controlled laboratory environment.

After Ledger Donjon’s findings were examined, engineers at Tropic Square discovered another potential exploitation path that could reveal an additional secret stored on the chip and linked to PIN-related operations.

The company informed its partners, including Trezor, and chose to publicly reveal the vulnerability together with the research findings produced by Ledger Donjon.

Trezor Says No Action Is Required From Users

Trezor said users are not required to take any action following the disclosure, noting that funds stored on the device remain secure since compromising the TROPIC01 chip by itself is insufficient to gain access to a wallet, PIN, or user assets.

Because the flaw is rooted in the hardware itself, it cannot be addressed through a remote firmware update.

“Because the Trezor Safe 7 was built with multiple independent security layers, a vulnerability in TROPIC01 does not put user funds at risk,” Trezor CEO Matej Žák said.

Trezor noted that the Ledger Donjon has previously released independent security analyses of its products, including a study on the Trezor Safe 3 that showcased an attack involving physical supply-chain interception, device desoldering, and hardware modification before the wallet reached end users.

The company issued a public response at the time and has since continued strengthening protections against similar attack methods, adding that no cases involving compromised user funds have been identified.

Trezor for details regarding audits of the other two chips used in the Safe 7, along with the components found in earlier device versions, but no response had been received by the time of publication.

Market Opportunity
USD.AI Logo
USD.AI Price(CHIP)
$0.03842
$0.03842$0.03842
-2.66%
USD
USD.AI (CHIP) Live Price Chart

SPACEX(PRE) Launchpad

SPACEX(PRE) LaunchpadSPACEX(PRE) Launchpad

Register for a chance to win a free lucky draw

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

RealStocks Now Live

RealStocks Now LiveRealStocks Now Live

Trade real U.S. stock via regulated brokerage