TLDR: Ledger Donjon researchers revealed Tangem cards allow unlimited PIN guesses using a tearing attack technique. The flaw bypasses security delays, enabling 2.5 password attempts per second instead of days of waiting. Tangem responded, saying the attack is impractical due to chip endurance limits and required lab equipment. Security experts urged users to set long, [...] The post Ledger Says Tangem Cards Can Be Brute-Forced Faster, Wallet Maker Disagrees appeared first on Blockonomi.TLDR: Ledger Donjon researchers revealed Tangem cards allow unlimited PIN guesses using a tearing attack technique. The flaw bypasses security delays, enabling 2.5 password attempts per second instead of days of waiting. Tangem responded, saying the attack is impractical due to chip endurance limits and required lab equipment. Security experts urged users to set long, [...] The post Ledger Says Tangem Cards Can Be Brute-Forced Faster, Wallet Maker Disagrees appeared first on Blockonomi.

Ledger Says Tangem Cards Can Be Brute-Forced Faster, Wallet Maker Disagrees

2025/09/18 16:52

TLDR:

  • Ledger Donjon researchers revealed Tangem cards allow unlimited PIN guesses using a tearing attack technique.
  • The flaw bypasses security delays, enabling 2.5 password attempts per second instead of days of waiting.
  • Tangem responded, saying the attack is impractical due to chip endurance limits and required lab equipment.
  • Security experts urged users to set long, complex passwords to reduce risk from brute-force attacks

A new wallet security issue has sparked a heated debate among crypto holders. Ledger’s security researchers have disclosed a flaw in Tangem hardware wallets. The weakness could let attackers bypass security delays and guess passwords much faster.

Tangem pushed back, saying the risk is minimal in real-world conditions. The clash highlights how hardware wallet security remains a constant arms race.

Ledger Researchers Reveal Tearing Attack

Ledger’s Charles Guillemet shared that its Donjon team discovered a “tearing attack” on Tangem cards. This attack works by cutting power before a failed password attempt is logged. 

Without logging the failure, the card never activates its security delay. That allows attackers to try unlimited passwords without being locked out.

Researchers said this method increases password guessing speed up to 100 times. At 2.5 attempts per second, a 4-digit PIN could be cracked in about one hour. They warned that simple or short passwords are especially vulnerable to this technique. 

Guillemet urged users to set long passwords with letters, numbers, and symbols.

Ledger stressed that its disclosure followed responsible security research protocols. They notified Tangem privately before going public. The team stated that the vulnerability shows why upgradable security features are important.

Tangem Pushes Back on Risk Level

Tangem responded, saying the research was a sophisticated hardware exercise but impractical for real attackers. The company said disabling the delay does not speed up brute-force attacks enough to make them feasible.

They explained that a 4-character password would still take about 245 days to break at four attempts per second. Using five or more characters increases the time to decades. Tangem also said the chip would likely fail under such repeated attempts.

The wallet maker pointed out that physical possession of the card is required for the attack. Specialized lab equipment is needed, raising the difficulty further. They emphasized that Tangem’s app encourages users to create robust access codes with numbers and characters.

This back-and-forth underscores the tension between wallet makers and security researchers. Both agree that password complexity is a critical defense. For now, Tangem users may want to review their access codes to ensure they meet strong security standards

The post Ledger Says Tangem Cards Can Be Brute-Forced Faster, Wallet Maker Disagrees appeared first on Blockonomi.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Aave V4 roadmap signals end of multichain sprawl

Aave V4 roadmap signals end of multichain sprawl

The post Aave V4 roadmap signals end of multichain sprawl appeared on BitcoinEthereumNews.com. Aave Labs has released its official launch roadmap for V4, laying out the final steps ahead of the major upgrade’s Q4 mainnet launch.  Alongside new architectural and security improvements, the roadmap introduces a fundamental shift in how user balances are tracked and highlights a strategic pullback from economically underperforming deployments across layer-2 and alternative layer-1 networks. The V4 release moves away from aTokens’ rebasing-style mechanics toward ERC-4626-style share accounting, a change that promises cleaner integrations, easier tax treatment, and better compatibility with downstream DeFi infrastructure.  In a recent technical development update, Aave Labs confirmed that “tokenization is to remain optional and built using ERC 4626 vaults,” and that internal accounting will eliminate the use of exchange rates or scaled balances. The goal is to “further improve the overall reliability of the protocol.” ERC-4626 is a widely adopted Ethereum standard that expresses user deposits as shares of a vault rather than balances that grow over time. In Aave V3, aTokens accrue interest by increasing a user’s balance directly — behavior that resembles rebasing tokens and often confuses integrations and portfolio accounting tools.  By contrast, ERC-4626 tracks yield through a rising price-per-share metric, leaving token balances unchanged. The result is more predictable behavior for integrators, auditors and tax software, as well as a clearer cost basis for users. The roadmap also outlines a series of release milestones, including a formal codebase publication, a public testnet launch with a redesigned interface, and the completion of a multi-layered security review involving formal verification and manual audits. Aave Labs said the roadmap reflects the protocol’s “final stages of review, testing, and deployment,” and that additional documentation and launch preparation materials will be released in the coming weeks. But the most pointed strategic shift comes not from the codebase, but from Aave’s own governance forums. “Aave…
Share
BitcoinEthereumNews2025/09/18 07:40