The technique involves a nanosecond laser pulse that disrupts firmware verification during a password reset command. Ledger researchers successfully tested this on three cards, noting that the procedure allows an attacker to define a new password without knowing the original or possessing a backup card. Because current Tangem cards lack support for firmware updates, this vulnerability cannot be patched remotely.
Performing the attack is a destructive process. It requires cutting open the card, removing shielding, and rewiring the chip, leaving the device visibly damaged. Consequently, the card cannot be returned to its owner in a functional, original state after the breach. Tangem maintains that the threat to everyday users is virtually non-existent, emphasizing that the attack relies on high-level expertise and substantial physical infrastructure. The company also highlighted the competitive nature of the relationship, as Ledger stands as one of Tangem's primary market rivals.

Comments (0)
No comments yet. Be the first!