Tangem wallet brute force vulnerability revealed by rival Ledger
A security flaw allowing hackers to brute force the PIN code of Tangem’s cold wallet cards by cutting off their source of power was revealed yesterday by Ledger’s white hat hacker team, Donjon. Ledger CTO, Charles Guillemet, announced the “tearing attack” on X after disclosing the exploit with the rival hardware wallet firm. Unfortunately for Tangem, Donjon noted that it can’t be patched on already existing Tangem cards. In order to perform the attack, Donjon discovered that cutting a Tangem card’s source of power before it acknowledges a password attempt stops it from registering a failed password . A hacker would then need to determine if they’ve found the right password. Donjon discovered that by analyzing the electromagnetic emissions the card emits with each attempt, they can see a pattern of peaked electromagnetic emissions indicating that the correct combination was found. By doing this, hackers can attempt as many passwords as they like w...