Particle.news
Download on the App Store

Laser Fault Injection Lets Attackers Reset Tangem Card Passwords, Researchers Say

The method exploits a flaw in a Samsung secure element and cannot be patched on cards already in circulation.

Overview

  • Ledger Donjon published a technical report on Friday, July 10, 2026 that shows a precisely timed laser pulse can flip a firmware check on the Samsung S3D232A chip and allow an attacker to set a new password without the original PIN.
  • The attack is a form of laser fault injection that targets the card’s recovery-state check so the chip accepts a password reset as if a legitimate recovery had occurred.
  • Researchers say the technique requires physical possession, cutting the card open to expose the chip, custom rewiring, power analysis and a high-end lab rig with setup costs estimated at about $250,000.
  • Tangem has acknowledged the lab demonstration but says the method is specialised and impractical for ordinary users; researchers and multiple outlets note the exploit is most relevant to high-value or targeted thefts because it is invasive and leaves obvious damage.
  • Because Tangem cards cannot receive firmware updates, the vulnerability affects every affected card in the field for its lifetime and highlights limits of secure-element certification and the trade-offs in Tangem’s seedless, non-updatable design.