Was the Tangem Wallet Hacked?
Share
Short answer: sort of. Ledger's security research team published a vulnerability report on Tangem in July 2026, and it is a real vulnerability. But the details matter a lot here.
What Ledger actually did
Ledger Donjon disclosed this to Tangem back in February 2026, several months before going public. The target is the Samsung EAL6+ secure element inside every Tangem card currently in circulation.
The attack: physically open the card, expose the chip die, do side-channel timing analysis to find the right spot, then fire a single nanosecond laser pulse at one precise location. That flips one bit in a recovery-state check inside the SetPin command. With that check bypassed, you can set a new PIN without knowing the old one, sign transactions, and move the funds.
Once they had the parameters dialed in, it worked on every subsequent card tested. Each took around two hours. The lab setup cost around $250,000, and they had to destroy several cards just to characterize the right parameters.
Why this is not the threat it sounds like
- Physical access to the card is required
- The process destroys the card. The chip is physically exposed, the damage is obvious, and the card cannot be returned intact.
- Cannot be done remotely
- Nation-state-level resources and expertise required
Ledger themselves said: "This is not something an individual attacker can pull off."
No patch is coming either. Tangem uses immutable firmware by design, so there is no update mechanism, and the flaw stays on all cards currently in circulation. Tangem has acknowledged the findings and noted that laser fault injection is a general technique that applies to many secure elements, not just theirs.
What actually gets people hacked
Phishing, malware, seed phrase exposure, social engineering. That is what accounts for the vast majority of real crypto losses. Tangem's design is built to protect against most of those, especially seed phrase risk since there is no seed phrase to expose.
The only scenario where this attack matters in practice is if your card was lost or stolen, and the person who found it had $250,000 in equipment, the expertise to use it, and two hours specifically for your card. That is a very narrow threat model.
My take
Real vulnerability, yes. Something to worry about as a regular user, no. Focus on the threats that actually get people hacked.
If you want a full breakdown of how the Tangem wallet holds up overall, check out my Tangem wallet review. And if you just picked one up, here is a quick setup guide.
What do you think about this? Let me know in the comments.
If you decide to pick up a Tangem wallet, use the Tangem wallet discount codes NORDIC and NYEXTRA26 at checkout for up to 30% off. This link applies both codes automatically.