The post Tangem wallet brute force vulnerability revealed by rival Ledger appeared on BitcoinEthereumNews.com. A security flaw allowing hackers to brute force the PIN code of Tangem’s cold wallet cards by cutting off their source of power was revealed yesterday by Ledger’s white hat hacker team, Donjon. Ledger CTO, Charles Guillemet, announced the “tearing attack” on X after disclosing the exploit with the rival hardware wallet firm. Unfortunately for Tangem, Donjon noted that it can’t be patched on already existing Tangem cards.  In order to perform the attack, Donjon discovered that cutting a Tangem card’s source of power before it acknowledges a password attempt stops it from registering a failed password.  A hacker would then need to determine if they’ve found the right password. Donjon discovered that by analyzing the electromagnetic emissions the card emits with each attempt, they can see a pattern of peaked electromagnetic emissions indicating that the correct combination was found. By doing this, hackers can attempt as many passwords as they like without fear of activating any security protocols.  The makeshift antenna Donjon created to focus on the chip’s electromagnetic emissions Read more: Ledger exec’s alleged kidnap mastermind arrested in Morocco Donjon says it would normally take five days to brute force a four-digit code with Tangem’s security protections, and roughly 148 years to brute force an eight-digit code.  However, the “tearing attack” reduces this time to ~1 hour for a four-digit code, and ~460 days for an eight-digit code, as it allows for two and a half password attempts every second.   It estimates that the cost to carry all this out would come to $5,000, adding that, “While the setup cost is relatively low, making it accessible to a wider range of attackers, the need for physical proximity to the target card remains a prerequisite.” Regardless, there’s not much that can be done to fix the exploit for the… The post Tangem wallet brute force vulnerability revealed by rival Ledger appeared on BitcoinEthereumNews.com. A security flaw allowing hackers to brute force the PIN code of Tangem’s cold wallet cards by cutting off their source of power was revealed yesterday by Ledger’s white hat hacker team, Donjon. Ledger CTO, Charles Guillemet, announced the “tearing attack” on X after disclosing the exploit with the rival hardware wallet firm. Unfortunately for Tangem, Donjon noted that it can’t be patched on already existing Tangem cards.  In order to perform the attack, Donjon discovered that cutting a Tangem card’s source of power before it acknowledges a password attempt stops it from registering a failed password.  A hacker would then need to determine if they’ve found the right password. Donjon discovered that by analyzing the electromagnetic emissions the card emits with each attempt, they can see a pattern of peaked electromagnetic emissions indicating that the correct combination was found. By doing this, hackers can attempt as many passwords as they like without fear of activating any security protocols.  The makeshift antenna Donjon created to focus on the chip’s electromagnetic emissions Read more: Ledger exec’s alleged kidnap mastermind arrested in Morocco Donjon says it would normally take five days to brute force a four-digit code with Tangem’s security protections, and roughly 148 years to brute force an eight-digit code.  However, the “tearing attack” reduces this time to ~1 hour for a four-digit code, and ~460 days for an eight-digit code, as it allows for two and a half password attempts every second.   It estimates that the cost to carry all this out would come to $5,000, adding that, “While the setup cost is relatively low, making it accessible to a wider range of attackers, the need for physical proximity to the target card remains a prerequisite.” Regardless, there’s not much that can be done to fix the exploit for the…

Tangem wallet brute force vulnerability revealed by rival Ledger

A security flaw allowing hackers to brute force the PIN code of Tangem’s cold wallet cards by cutting off their source of power was revealed yesterday by Ledger’s white hat hacker team, Donjon.

Ledger CTO, Charles Guillemet, announced the “tearing attack” on X after disclosing the exploit with the rival hardware wallet firm. Unfortunately for Tangem, Donjon noted that it can’t be patched on already existing Tangem cards. 

In order to perform the attack, Donjon discovered that cutting a Tangem card’s source of power before it acknowledges a password attempt stops it from registering a failed password

A hacker would then need to determine if they’ve found the right password.

Donjon discovered that by analyzing the electromagnetic emissions the card emits with each attempt, they can see a pattern of peaked electromagnetic emissions indicating that the correct combination was found.

By doing this, hackers can attempt as many passwords as they like without fear of activating any security protocols. 

The makeshift antenna Donjon created to focus on the chip’s electromagnetic emissions

Read more: Ledger exec’s alleged kidnap mastermind arrested in Morocco

Donjon says it would normally take five days to brute force a four-digit code with Tangem’s security protections, and roughly 148 years to brute force an eight-digit code. 

However, the “tearing attack” reduces this time to ~1 hour for a four-digit code, and ~460 days for an eight-digit code, as it allows for two and a half password attempts every second.  

It estimates that the cost to carry all this out would come to $5,000, adding that, “While the setup cost is relatively low, making it accessible to a wider range of attackers, the need for physical proximity to the target card remains a prerequisite.”

Regardless, there’s not much that can be done to fix the exploit for the current Tangem cards out there, as it’s not a patchable fix. As such, Donjon’s advice for at-risk users is to use an eight-character or more password with a mixture of letters, numbers, and symbols. 

Tangem isn’t fazed about card findings

According to Donjon, Tangem wasn’t fazed by Donjon’s findings and concluded it isn’t a vulnerability. “In their opinion, the proposed attack scenario does not pose a significant risk,” Donjon claimed. 

Because of this, a Donjon representative told Protos that Tangem didn’t award them a bounty, despite Donjon “following the responsible disclosure process.”

Indeed, Tangem told Protos that it rewards “practical, real-world vulnerabilities,” and not “a theoretical lab attack that is self-defeating by design and requires immense resources.”

Read more: Hacker could’ve printed unlimited ‘Ether’ but chose $2M bug bounty instead

According to Tanjem, Donjon’s method would essentially “physically destroy the card’s chip long before an access code could be guessed.”

It said that even if it survived, cracking a four-digit code would take months, and over 64 years if it was five digits. 

“The research oddly focused on four-digit PINs, while our cards support much stronger alphanumeric access codes with symbols, making the real-world challenge exponentially harder.

“For these reasons, the scenario remains purely academic. While the research is technically interesting, it does not represent a practical vulnerability or risk to our users,” Tangem concluded. 

Donjon, however, found Tanjem’s response to its findings “disappointing,” and called its arguments “inaccurate.”

  • Donjon claims the cards it tested never died, and that “the tearing process means there’s no writing done to the flash memory to wear it out.”
  • It insists that the exploit would speed up the brute force attack by “100x,” especially for weak passwords, which Tangem rejects.
  • Donjon also says it wasn’t a “sophisticated attack” thanks to the low cost, and the fact that this security test is required for a Basic level certification, such as an “EAL 3 grade.”

Ledger isn’t perfect either

Donjon Ledger is a security research team posted at the crypto hardware wallet firm Ledger. Beyond helping Ledger, it says, “From time to time, the team also works on improving the security of the ecosystem.”

There have been instances, however, where Ledger exploits have led to consequences felt by its users.

Read more: ‘Decentralized’ apps suffer after Ledger Connect Kit attack

One supply chain attack in 2023 allowed hackers to drain the wallets of users who use Ledger’s Connect Kit when a former employee’s account was breached.

In July 2020, Ledger revealed its e-commerce and marketing database had been breached, exposing the personal details of many of its customers.

By December, this data was leaked, and a series of scammers began sending fake Ledger wallets to exposed customers.

Got a tip? Send us an email securely via Protos Leaks. For more informed news, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.

Source: https://protos.com/tangem-wallet-brute-force-vulnerability-revealed-by-rival-ledger/

Market Opportunity
1 Logo
1 Price(1)
$0,00607
$0,00607$0,00607
+5,98%
USD
1 (1) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Is it ‘over for Solana’? 97% network activity crash sparks fresh debate

Is it ‘over for Solana’? 97% network activity crash sparks fresh debate

The post Is it ‘over for Solana’? 97% network activity crash sparks fresh debate appeared on BitcoinEthereumNews.com. Journalist Posted: December 22, 2025 Solana
Share
BitcoinEthereumNews2025/12/22 11:02
Bitcoin 8% Gains Already Make September 2025 Its Second Best

Bitcoin 8% Gains Already Make September 2025 Its Second Best

The post Bitcoin 8% Gains Already Make September 2025 Its Second Best appeared on BitcoinEthereumNews.com. Key points: Bitcoin is bucking seasonality trends by adding 8%, making this September its best since 2012. September 2025 would need to see 20% upside to become Bitcoin’s strongest ever. BTC price volatility is at levels rarely seen before in an unusual bull cycle. Bitcoin (BTC) has gained more this September than any year since 2012, a new bull market record. Historical price data from CoinGlass and BiTBO confirms that at 8%, Bitcoin’s September 2025 upside is its second-best ever. Bitcoin avoiding “Rektember” with 8% gains September is traditionally Bitcoin’s weakest month, with average losses of around 8%. BTC/USD monthly returns (screenshot). Source: CoinGlass This year, the stakes are high for BTC price seasonality, as historical patterns demand the next bull market peak and other risk assets set repeated new all-time highs. While both gold and the S&P 500 are in price discovery, BTC/USD has coiled throughout September after setting new highs of its own the month prior. Even at “just” 8%, however, this September’s performance is currently enough to make it Bitcoin’s strongest in 13 years. The only time that the ninth month of the year was more profitable for Bitcoin bulls was in 2012, when BTC/USD gained about 19.8%. Last year, upside topped out at 7.3%. BTC/USD monthly returns. Source: BiTBO BTC price volatility vanishes The figures underscore a highly unusual bull market peak year for Bitcoin. Related: BTC ‘pricing in’ what’s coming: 5 things to know in Bitcoin this week Unlike previous bull markets, BTC price volatility has died off in 2025, against the expectations of longtime market participants based on prior performance. CoinGlass data shows volatility dropping to levels not seen in over a decade, with a particularly sharp drop from April onward. Bitcoin historical volatility (screenshot). Source: CoinGlass Onchain analytics firm Glassnode, meanwhile, highlights the…
Share
BitcoinEthereumNews2025/09/18 11:09
The 8th Hainan International Health Industry Expo opens in Sanya

The 8th Hainan International Health Industry Expo opens in Sanya

HAIKOU, China, Dec. 21, 2025 /PRNewswire/ — A report from Hainan International Media Center: On December 20, 2025, the 8th Hainan International Health Industry
Share
AI Journal2025/12/22 11:45