Overview
- Ledger Donjon published a technical report on Friday, July 10, 2026 that shows a precisely timed laser pulse can flip a firmware check on the Samsung S3D232A chip and allow an attacker to set a new password without the original PIN.
- The attack is a form of laser fault injection that targets the card’s recovery-state check so the chip accepts a password reset as if a legitimate recovery had occurred.
- Researchers say the technique requires physical possession, cutting the card open to expose the chip, custom rewiring, power analysis and a high-end lab rig with setup costs estimated at about $250,000.
- Tangem has acknowledged the lab demonstration but says the method is specialised and impractical for ordinary users; researchers and multiple outlets note the exploit is most relevant to high-value or targeted thefts because it is invasive and leaves obvious damage.
- Because Tangem cards cannot receive firmware updates, the vulnerability affects every affected card in the field for its lifetime and highlights limits of secure-element certification and the trade-offs in Tangem’s seedless, non-updatable design.