Opinion
Hardware Wallet Security 21.07.2026: The Laser Test Lesson
An explanatory and analytical article on the physical security of hardware wallets in the context of Baltic and Nordic self-custody – what the Ledger Donjon laser attack on Tangem cards truly means, and how to compare the security architectures of Ledger, Trezor, BitBox, Coldcard, and Tangem.
Over the past 24 hours, there has been no specific primary news in the Baltic and Nordic crypto exchange segment, so this is an honestly labelled explanation, not a news report. We examine an ongoing topic from our hardware wallet category: to what extent physical attacks (e.g., the Ledger Donjon laser test on Tangem cards) threaten self-custody, how to compare the security architectures of Ledger, Trezor, BitBox, Coldcard, and Tangem, and what this risk means for a real user in the region.
Over the past 24 hours (20-21 July), there has been no specific primary news in the Baltic and Nordic crypto exchange and CASP segment. The previous ESMA MiCA register update (16 July, total 294 CASPs) was covered in the 20 July weekly review, with the next weekly update expected around 23 July. Therefore, this is an honestly labelled explanatory and analytical article, not a news summary. We are looking at an ongoing topic that directly affects the second category of our segment – hardware wallets – and is becoming increasingly important for users in the region: to what extent physical attacks threaten self-custody, and how to properly assess this risk.
Why this topic now
Following the end of the MiCA transition period on 1 July, the number of licensed exchanges in the Baltics and Nordics has decreased, and some users are increasingly turning to self-custody. This means that keys are stored not on an exchange, but in the user's own hardware wallet. Therefore, the question of how resilient these wallets are to physical attacks is no longer academic. The brands we monitor in this category are Ledger, Trezor, BitBox, Coldcard, and Tangem.
The current discussion was triggered by a study published by Ledger's security laboratory, Donjon, on a laser fault injection (LFI) attack on Tangem cards, as well as the subsequent public polemic between Ledger and Tangem. We covered this event in detail in our 13 July news article; here, we use it as context to explain the broader issue of hardware wallet security architecture, rather than as fresh news.
What the study actually showed (context, not fresh news)
According to material published by Ledger Donjon, the vulnerability in Tangem was disclosed on 10 February 2026. The attack uses a nanosecond laser pulse, aimed at the Samsung S3D232A secure element (EAL6+ certification), to bypass the password reset state check and set an attacker-chosen access password without knowing the previous one. The attacker can then sign transactions.
The prerequisites for the attack are crucial. It requires physical possession of the specific card, laboratory equipment worth approximately 250,000 US dollars, in-depth knowledge of both software and hardware security, and about two hours of preparation per card after initial characterisation. The attack is invasive and leaves visible damage on the card. Tangem's response on 9 July emphasised that LFI is a laboratory-scale technique that does not scale, does not work remotely, and applies to secure elements in general, not just Tangem. Ledger, in turn, states that Tangem cards do not have a firmware update mechanism, so cards in circulation cannot be patched. Both positions are partially correct and not mutually exclusive.
Comparison of security architectures
Hardware wallet security is based on several independent principles that are worth distinguishing.
A secure element is a certified tamper-resistant microchip that stores keys and performs signing in isolation. Ledger, Trezor's latest Safe series, BitBox02, Coldcard, and Tangem – all use a secure element. Historically, older Trezor models did not use a secure element; Safe 3, Safe 5, and Safe 7 now include it.
Open-source refers to whether the firmware can be independently verified. Trezor, BitBox02, and Coldcard firmware are open-source. Ledger's secure element software is not open-source, as it is covered by manufacturer agreements. Tangem's application code is available, but the card is designed to be closed without updates.
Seedless approach. Tangem deliberately does not use the traditional seed phrase backup – keys are generated on the card and do not leave it. This prevents the most common real cause of loss (a neglected or stolen seed phrase), but in exchange, the user does not have a classic backup and becomes dependent on the physical card's durability. Ledger, Trezor, BitBox, and Coldcard use a seed phrase, which means a different risk profile: backup is possible, but the seed phrase becomes the main weak point.
This comparison shows that there is no single "safest" wallet – there are different risk trade-offs. A physical durability test, such as LFI, highlights one axis (resistance to invasive attacks with card possession), but says nothing about others, such as resistance to malicious applications or social engineering.
What a physical attack means for a real user
The threat model is crucial. An LFI-type attack requires the adversary to physically obtain your specific card, have a laboratory, and be motivated to spend a six-figure sum against a wallet whose balance is not known in advance. For most private users, this scenario is unlikely. In practice, most real losses in self-custody result from seed phrase disclosure, fake applications, and misleading transaction confirmations, not from laboratory attacks – to date, there are no known real-world cases of LFI being used against any hardware wallet.
This does not mean that physical durability is not important. For high-value holders, businesses, and people in elevated risk situations (border crossings, theft risk, targeted attention), physical resistance and the ability to update firmware are real considerations. Here, manufacturer differences become significant.
Watchlist and next checkpoints
Several things are worth following in the segment. Firstly, the next weekly update of the ESMA MiCA register, expected around 23 July – whether new CASPs will appear in the region (LV, LT, EE, FI, SE, NO, DK). Secondly, whether Tangem and other manufacturers of non-updatable formats will come up with a hardware-level solution for new cards, given that cards in circulation cannot be patched. Thirdly, whether independent security laboratories will publish equivalent tests for other monitored brands – for objectivity, comparable methodology is essential, not just one manufacturer's study on a competitor.
Summary for users and traders
Firstly, assess your real threat model: for most private users, seed phrase hygiene and protection against fake applications are more important than laboratory-scale physical attacks. Secondly, if you choose a seedless wallet, be aware that security relies on the physical card's durability and that there are no update options – this is a deliberate trade-off, not a flaw in itself. Thirdly, for high-value holders, consider wallets with a secure element, updatable firmware, and the ability to split holdings (multisig). Fourthly, evaluate security claims critically: a manufacturer's published study on a competitor is valuable information, but not a neutral judgment – look for independent confirmation. Fifthly, regardless of your wallet choice, store your seed phrase offline and never enter it into internet-connected devices.
Sources
- ESMA - Markets in Crypto-Assets Regulation (MiCA) and CASP register
- Ledger Donjon - Bypassing Tangem Card Security with a Laser Attack
- Tangem - Our Comment on Ledger Donjon's Latest Article (9 July)
- The Hacker News - Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched
- Incrypted - Ledger and Tangem Publicly Argued Over a Wallet Hack via a Laser Attack (10 July)
- BitBox - Hardware wallet comparison: Ledger, Trezor, BitBox