We collect cookies to analyze our website traffic and performance; we never collect any personal data.Cookies Policy
Accept
Michigan Post
Search
  • Home
  • Trending
  • Michigan
  • World
  • Politics
  • Top Story
  • Business
    • Business
    • Economics
    • Real Estate
    • Startups
    • Autos
    • Crypto & Web 3
  • Tech
  • Lifestyle
    • Lifestyle
    • Food
    • Beauty
    • Art & Books
  • Health
  • Sports
  • Entertainment
  • Education
Reading: Tangem pockets brute power vulnerability revealed by rival Ledger
Share
Font ResizerAa
Michigan PostMichigan Post
Search
  • Home
  • Trending
  • Michigan
  • World
  • Politics
  • Top Story
  • Business
    • Business
    • Economics
    • Real Estate
    • Startups
    • Autos
    • Crypto & Web 3
  • Tech
  • Lifestyle
    • Lifestyle
    • Food
    • Beauty
    • Art & Books
  • Health
  • Sports
  • Entertainment
  • Education
© 2024 | The Michigan Post | All Rights Reserved.
Michigan Post > Blog > Crypto & Web 3 > Tangem pockets brute power vulnerability revealed by rival Ledger
Crypto & Web 3

Tangem pockets brute power vulnerability revealed by rival Ledger

By Editorial Board Published September 18, 2025 6 Min Read
Share
Tangem pockets brute power vulnerability revealed by rival Ledger

A safety flaw permitting hackers to brute power the PIN code of Tangem’s chilly pockets playing cards by reducing off their supply of energy was revealed yesterday by Ledger’s white hat hacker group, Donjon.

Ledger CTO, Charles Guillemet, introduced the “tearing attack” on X after disclosing the exploit with the rival {hardware} pockets agency. Sadly for Tangem, Donjon famous that it will possibly’t be patched on already current Tangem playing cards. 

With a view to carry out the assault, Donjon found that reducing a Tangem card’s supply of energy earlier than it acknowledges a password try stops it from registering a failed password. 

A hacker would then want to find out in the event that they’ve discovered the proper password.

Donjon found that by analyzing the electromagnetic emissions the cardboard emits with every try, they’ll see a sample of peaked electromagnetic emissions indicating that the right mixture was discovered.

By doing this, hackers can try as many passwords as they like with out concern of activating any safety protocols. 

Tangem pockets brute power vulnerability revealed by rival LedgerThe makeshift antenna Donjon created to concentrate on the chip’s electromagnetic emissions

Donjon says it could usually take 5 days to brute power a four-digit code with Tangem’s safety protections, and roughly 148 years to brute power an eight-digit code. 

Nonetheless, the “tearing attack” reduces this time to ~1 hour for a four-digit code, and ~460 days for an eight-digit code, because it permits for 2 and a half password makes an attempt each second.  

It estimates that the fee to hold all this out would come to $5,000, including that, “While the setup cost is relatively low, making it accessible to a wider range of attackers, the need for physical proximity to the target card remains a prerequisite.”

Regardless, there’s not a lot that may be achieved to repair the exploit for the present Tangem playing cards on the market, because it’s not a patchable repair. As such, Donjon’s recommendation for at-risk customers is to make use of an eight-character or extra password with a combination of letters, numbers, and symbols. 

Tangem isn’t fazed about card findings

In keeping with Donjon, Tangem wasn’t fazed by Donjon’s findings and concluded it isn’t a vulnerability. “In their opinion, the proposed attack scenario does not pose a significant risk,” Donjon claimed. 

Due to this, a Donjon consultant instructed Protos that Tangem didn’t award them a bounty, regardless of Donjon “following the responsible disclosure process.”

Certainly, Tangem instructed Protos that it rewards “practical, real-world vulnerabilities,” and never “a theoretical lab attack that is self-defeating by design and requires immense resources.”

In keeping with Tanjem, Donjon’s technique would basically “physically destroy the card’s chip long before an access code could be guessed.”

It mentioned that even when it survived, cracking a four-digit code would take months, and over 64 years if it was 5 digits. 

“The analysis oddly centered on four-digit PINs, whereas our playing cards help a lot stronger alphanumeric entry codes with symbols, making the real-world problem exponentially tougher.

“For these reasons, the scenario remains purely academic. While the research is technically interesting, it does not represent a practical vulnerability or risk to our users,” Tangem concluded. 

Donjon, nevertheless, discovered Tanjem’s response to its findings “disappointing,” and referred to as its arguments “inaccurate.”

Donjon claims the playing cards it examined by no means died, and that “the tearing process means there’s no writing done to the flash memory to wear it out.”

It insists that the exploit would velocity up the brute power assault by “100x,” particularly for weak passwords, which Tangem rejects.

Donjon additionally says it wasn’t a “sophisticated attack” due to the low value, and the truth that this safety take a look at is required for a Fundamental degree certification, akin to an “EAL 3 grade.”

Ledger isn’t good both

Donjon Ledger is a safety analysis group posted on the crypto {hardware} pockets agency Ledger. Past serving to Ledger, it says, “From time to time, the team also works on improving the security of the ecosystem.”

There have been cases, nevertheless, the place Ledger exploits have led to penalties felt by its customers.

One provide chain assault in 2023 allowed hackers to empty the wallets of customers who use Ledger’s Join Package when a former worker’s account was breached.

In July 2020, Ledger revealed its e-commerce and advertising database had been breached, exposing the non-public particulars of a lot of its prospects.

By December, this information was leaked, and a collection of scammers started sending faux Ledger wallets to uncovered prospects.

TAGGED:bruteforceLedgerrevealedrivalTangemvulnerabilitywallet
Share This Article
Facebook Twitter Email Copy Link Print

HOT NEWS

Ioannis Antypas on Helping Businesses Expand Into Saudi Arabia and the Middle East

Ioannis Antypas on Helping Businesses Expand Into Saudi Arabia and the Middle East

BusinessTrending
January 3, 2026
Vintage Rare USA: A Curated Archive of Iconic American Style

Vintage Rare USA: A Curated Archive of Iconic American Style

True vintage is not about trends—it’s about authenticity, heritage, and character. Vintage Rare USA has…

December 25, 2025
Omri Raiter: AI and Fusion Are Becoming Core Tools Against the Next Generation of Crime

Omri Raiter: AI and Fusion Are Becoming Core Tools Against the Next Generation of Crime

By Omri Raiter, Founder and CEO of RAKIA Group The next generation of organized crime…

December 24, 2025
Ocado chair joins Visma board forward of €20bn London float

Ocado chair joins Visma board forward of €20bn London float

The chairman of Ocado Group has been recruited to the board of Visma, the European…

December 18, 2025
Unique: Minnie Driver Proves 55 Is the New Fabulous – Beauty

Unique: Minnie Driver Proves 55 Is the New Fabulous – Beauty

Minnie Driver is in a second of full-flight momentum, getting into a vivid, confident period…

December 18, 2025

YOU MAY ALSO LIKE

The Block Mine Emerges as a Global Mining Powerhouse—Ushering in a New Era of Digital Asset Infrastructure with Nexa

The global blockchain economy is entering its next great phase—and The Block Mine is standing at the center of it.…

Crypto & Web 3Trending
December 18, 2025

Cathie Wooden falls for AI slop regardless of heavy OpenAI, Tempus bets

Cathie Wooden, the Ark Make investments CEO who heralded AI as “the most transformative technology in history” whereas investing tens…

Crypto & Web 3
December 18, 2025

Aave Labs v DAO: Who controls the cash — and the model?

The talk between Aave DAO and Aave Labs continues to escalate. In what started as a spat over the “private…

Crypto & Web 3
December 17, 2025

Ex-Alameda CEO Caroline Ellison leaves federal jail after 11 months

Caroline Ellison, the previous co-CEO of Alameda Analysis, is not behind bars after being moved to a midway home lower…

Crypto & Web 3
December 17, 2025

Welcome to Michigan Post, an esteemed publication of the Enspirers News Group. As a beacon of excellence in journalism, Michigan Post is committed to delivering unfiltered and comprehensive news coverage on World News, Politics, Business, Tech, and beyond.

Company

  • About Us
  • Newsroom Policies & Standards
  • Diversity & Inclusion
  • Careers
  • Media & Community Relations
  • Accessibility Statement

Contact Us

  • Contact Us
  • Contact Customer Care
  • Advertise
  • Licensing & Syndication
  • Request a Correction
  • Contact the Newsroom
  • Send a News Tip
  • Report a Vulnerability

Term of Use

  • Digital Products Terms of Sale
  • Terms of Service
  • Privacy Policy
  • Cookie Settings
  • Submissions & Discussion Policy
  • RSS Terms of Service
  • Ad Choices

© 2024 | The Michigan Post | All Rights Reserved

Welcome Back!

Sign in to your account

Lost your password?