$ONDO
Fading QuicklySnapshot Window: 2026-07-13 19:10 UTC ยท โ Back to Crypto Overview
Social Momentum Summary
Total Engagement - Comments: 1, Retweets: 2, Likes: 8, Impressions: 180
Verbatim Community Citations & Social Evidence 1 source posts analyzed
Tangem Wallet Laser Attack Explained: Competitor Ledger Found Vulnerability (What You Need to Know) FULL DISCLOSURE: Tangem is a sponsor of this channel and I promote their products. I made this video the same way I would if they were not a sponsor. Ledger โ a direct [Spoken audio]: Ledger, one of the biggest names in crypto hardware wallets, just published research showing that they were able to break into a Tandrum card using a laser. They reset the password and drain the wallet in a lab. So here's the deal. I use Tandrum wallets. I promote Tandrum wallets. Tandrum is a sponsor of the channel. Sure, there's a real conflict of interest. And when something bad comes out about a sponsor, I cover it the same way I would if they weren't. Hello, I'm Crypto Casey. And in this video, we're going to walk through exactly what Ledger found exactly how Tandrum responded so you can decide what this means for you. All right, Ledger has a security research team called Don John and their job is to basically try to break hardware, including competitors hardware. On July 9th, 2026, they published an attack on Tandrum cards and here's the plain English version. A Tandrum card has a secure chip inside. Normally to change the card's password, you either need the old password or you need to go through a recovery process using two linked cards somewhere in the card software there is a single yes or no check that asks is this card in recovery mode right now and what ledger did was point a very precise laser at the chip at the exact microsecond that check happens that laser pulse flips that check which tricks the card into thinking it's in recovery mode when it isn't once that happens they can set a brand new password without knowing the old one. And whoever controls the password controls the crypto. That's the attack. One flipped check and the card hands over the keys. Now let's go through a few details from Ledger's own write-up on the matter to understand the uncomfortable ones and the reassuring ones together. Alright, here are the uncomfortable facts. The attacker does not need your password. The attacker does not need your backup card. Turning off the recovery feature does not protect you despite what some people have been leaving comments on the matter. Ledger tested this. It does not close the hole. It affects every tangent card in circulation, and because these cards have no firmware update mechanism, it cannot be patched, which means there is no software fix coming for the card's yard yield. And once Ledger's team figured out the exact settings, they hit a 100% success rate across the cards they tested at about 2 hours per card. Yikes! Take a deep breath. Ooh, saw it. Alright, now for the reassuring facts that are just as real. The attack needs physical possession of your card. This is not remote. Nobody is doing this over the internet, over NFC across the room, none of that. It needs roughly $250,000 worth of specialized lab equipment. It needs a genuine expert in hardware security, the kind of person who works in a chip lab. And the process is destructive and visible. They physically cut the card open. So if something happened, we would know. There's no putting it back together and handing it to us like nothing happened. And Ledger themselves says in the article the only realistic risk here is a lost or stolen card. If your card remained in your possession or in a secure place only you have access to, this attack cannot affect your tangent wallet. Cool. Okay, now tangent put out a response the same day. They didn't go silent and hide and here are their arguments. This kind of attack doesn't scale. You can't mass produce it. Every target is a separate quarter million dollar weeks long lab project. cards carry no person's name or balance on them. So an attacker spending $250k to crack a card has no idea if it holds $50 or $50 million. That genuinely wrecks the math for a thief because you're essentially spending a fortune on a slot pool. And there has never been a single documented real-world loss from a laser fault injection attack on any crypto hardware wallet ever. Not Tangem or any other hardware provider. This type of attack lives in research labs, not in the wild. So far. makes a design argument worth understanding. Most Tandrum users go seedless, meaning there is no recovery phrase. So the upside is there is no seed phrase for a Fisher to steal. And seed phrase theft is one of the biggest actual causes of lost crypto. The trade-off is that the card can't just nuke its own keys the instant it senses an attack because a false alarm would lock us out of our money forever. So it's a deliberate choice, not an oversight. Alright, now the reality we all need to consider is neither Tandrum or ledger are neutral players on the matter. Ledger sells hardware wallets, Tangem sells hardware wallets. Ledger's research team just spent serious effort finding and publicizing a flaw in a competitor's product. The research itself looks legitimate and this is important to note. Ledger disclosed this information privately to Tangem back in February before going public, which is a pretty responsible way of going about this. So this isn't necessarily a hit piece. However, we should read it for what it is. A competitor's evaluation with a competitor's incentive to make the finding sound as alarming as the facts allow, and some of Tangem's talking points in their response are softer than the facts support. They leaned hard into the idea that every attempt risks breaking the card, and that one-off demo doesn't prove a repeatable process. However, Ledger reported reproducing the attack on a second and third card with a 100% success rate once they dialed in, so that it might break the card is true for the setup phase. However, it's not true once the method is known. Tangem's framing kind of blurs that. And another key thing in Tangem's response is they never addressed the word unpatchable. They don't dispute a single technical finding in Ledger's report. They're quiet on the fact that the cards you already own can't be fixed. They don't say whether future versions of the card will implement the specific hardening Ledger recommended. And if or when Tangem does commit to that publicly, we will cover that together. So be sure to subscribe to stay up to date on the latest news. So at the end of the day, ledger has a motive to scare us and tangent has a motive to soothe us. The truth is sitting calmly somewhere in between. And it's honestly not that scary for most of us. However, we all need to be informed in order to decide what is best for us and what we feel most comfortable doing going forward. So let's go over what this actually means for us. Let's make this practical because most of us aren't walking around with a $250,000 laser lab hunting our cards. Here's the one thing that genuinely changed with this research. The risk of a lost or stolen card is now higher than we thought. Before the assumption was that even if someone got our tangent card, they couldn't get in without our password. Now we know an extremely well resourced attacker could. So here are some practical takeaways. 1. If we lose our card or it's stolen, treat it as urgent. If you're holding meaningful money, move your funds to a new wallet promptly. Don't assume the password is enough anymore. 2. This does not change our day to day security picture if our card stays in our possession. The overwhelming majority of crypto losses doesn't come from lasers. It comes from phishing, fake apps, malicious smart contracts, and people typing their seed rays into a scam site. Those are the threats emptying crypto wallets every single day, so we need to keep our focus there. 3. If we hold a large amount on a single card, think about our physical security the same way you'd think about a safe or a deposit box. Physical possession is the whole ballgame for this attack. And four, don't buy or sell your hardware wallet based on one headline. Every hardware wallet on the market has a threat model, and every one of them has some sophisticated physical attack. It's vulnerable too. Lodgers on products included. There is no perfectly unbreakable wallet. Anyone who says otherwise is selling something. Great. So here's two things I'll be watching for, and we'll make follow-up videos accordingly. One, whether Tangem ships a hardened chip and future card revisions, These are the redundant checks and fault-resistant designs Ledger recommended, and that would tell us that Tandrum took the research seriously than just PR'ing it around it. And two, whether this attack ever escapes the lab, whether we see even one real-world case. So far, zero. If that changes, we'll cover it. Alright, to sum it up, Ledger found a real serious unpatchable flaw that also happens to require a stolen card, a fortune's worth of equipment, and a lab full of expertise, and it has never once hurt a real user in the wild. Both of these halves are true at the same time. Serious and not necessarily a reason to panic. Both ledgers and tangents articles are available using the links below to check them out for yourself. And if you'd like to learn more about how cryptocurrency wallets work, check out this video. If you'd like to learn about more ways to protect your crypto bank accounts and identity, check out this video. And to subscribe to the channel to stay up to date on all the latest things crypto, click on the link on the screen. As always, Crypto Fam, be safe out there.
![]()