← Back to News

Tangem responds to hardware fault attack claims

2026-07-11 · tangem

Tangem has issued an official response to Ledger Donjon's latest write-up on laser fault injection against its wallet hardware. The company says the attack is real in a laboratory sense but requires invasive physical access, expensive specialized equipment, deep expertise, and extensive setup time. That matters for anyone thinking seriously about custody. The story is a reminder that self-custody security is not just about malware and phishing, but also about what happens when attackers can physically reach the device storing your keys.


What Happened

Tangem says Ledger Donjon's findings center on a firmware-handling scenario under laser fault injection against a secure element. According to Tangem's summary, the attack requires decapping, side-channel work, precise laser tuning, physical possession of the card, and a controlled lab environment, making it highly resource-intensive and non-scalable.

The Cost of Data Loss

If a wallet or recovery design fails under physical compromise, the consequence is total asset loss, not a temporary outage or reversible account incident. That is the harsh reality of self-custody: once keys are extracted or recovery paths are exposed, there is usually no help desk, chargeback, or reset button waiting on the other side.

How Cold Storage Prevents This

Cold storage is strongest when it is paired with strict physical separation, limited handling, and layered backup discipline so an attacker cannot easily obtain both the device and the recovery path. Offline storage, tamper-aware handling, and segregated backups force an attacker out of the convenient remote-threat model and into a slower, riskier physical attack path.

Read Original Post →