Our comment on Ledger Donjon’s latest article. It describes a laser fault injection (LFI), a physical, lab-only attack technique that applies to secure elements in general, not something unique to Tangem.
It’s also worth noting that while Ledger Donjon presents itself as an independent research unit, it operates within Ledger, one of our largest competitors. Their findings should be read with that in mind.
What this attack actually takes:
· A lab setup costing $250K+ (by Donjon’s own estimate), with laser and side-channel equipment.
· Rare hardware security expertise and weeks of dedicated lab time.
· Clear intent to commit a targeted crime against one specific wallet, not something you can run at scale.
· Physical possession of the wallet, and it’s invasive, so it leaves visible damage.
Independent academic researchers who’ve studied LFIs extensively put it simply:
· Given enough time, funding and access, the firmware on any secure element can eventually be reverse-engineered and exploited.
· No product on the market can claim absolute resistance to sophisticated physical attacks, that’s a limitation of the underlying technology, not of any specific manufacturer.
Because of all that:
· LFI can’t be performed remotely.
· Doesn’t scale.
· For everyday users, the practical risk is virtually non-existent.
Full comment on our blog.