• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Ledger Uncovers Critical Vulnerability in Tangem Crypto Cards, Exposing Weak Password Risks
Share
  • bitcoinBitcoin(BTC)$80,841.00
  • ethereumEthereum(ETH)$2,374.41
  • tetherTether(USDT)$1.00
  • rippleXRP(XRP)$1.40
  • binancecoinBNB(BNB)$626.58
  • usd-coinUSDC(USDC)$1.00
  • solanaSolana(SOL)$84.67
  • tronTRON(TRX)$0.339402
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03
  • dogecoinDogecoin(DOGE)$0.111522
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
Company

Ledger Uncovers Critical Vulnerability in Tangem Crypto Cards, Exposing Weak Password Risks

News Desk
Last updated: September 21, 2025 2:14 pm
News Desk
Published: September 21, 2025
Share
Ledger Discloses Vulnerability in Cryptocurrency Wallet

A significant vulnerability in the security of cryptocurrency wallets has been identified, specifically affecting Tangem cards. Ledger, a well-known player in the crypto security domain, has reported a flaw that allows attackers to exploit weak passwords through a brute-force attack, raising grave concerns about the safety of wallet users. Without a current patch to address this security issue, the onus is now on users to enhance their password safety.

The Ledger Donjon team first revealed this serious vulnerability following thorough testing of both the secure channel and password protection mechanisms employed by Tangem. The flaw takes advantage of a tearing attack, enabling adversaries to perform brute-force logins at an alarming rate. While Tangem’s system has a built-in delay counter designed to deter password retrieval attempts, recent findings show that attackers can now guess passwords at approximately 2.5 attempts per second—over 100 times quicker than the intended pace of one attempt every 45 seconds.

Tangem cards are equipped with a security feature that enforces a delay after failed password attempts. A failed attempt results in a postponement of up to 45 seconds, making extensive brute-force efforts impractical for more complex passwords. However, the tearing attack circumvents this mechanism by cutting the power supply to the card during critical operations, leading to an improperly updated failure counter. As a result, attackers can continuously attempt passwords without facing the expected delay.

In their research, Ledger uncovered that by manipulating the timing of power disconnections to a narrow window of about 6700 microseconds, they could negate the security delay. Additionally, attackers can analyze electromagnetic emissions from the card’s chip to discern whether their password guess is correct before the delay takes effect.

The encryption protocol utilized for the security channel within Tangem, which aims to secure data exchanges, is also flawed. The encryption key’s integrity hinges on the user’s password, which means that cracking this encryption is as challenging as deciphering the password itself. Ledger’s tests indicated that even relatively inexpensive equipment, costing less than $5,000, could facilitate these attacks, putting this vulnerability within reach of many individuals with physical access to the cards.

As it stands, there is no patch available for current Tangem card models to rectify this critical vulnerability. Users of these wallets are thus at risk, particularly those with weak or simplistic passwords. For instance, a 4-digit PIN could be compromised in under an hour under these new attack conditions, compared to a more secure estimated timeline of five days without the vulnerability.

Passwords that range from six to eight characters are likewise deemed to be considerably weaker, albeit safer than shorter options. Tangem has recommended that users implement passwords consisting of at least eight characters that include a mix of letters, numbers, and symbols to bolster their security. This is vital, as simple passwords can often be breached in mere days.

In a detailed report submitted to Tangem, Ledger urged the adoption of a stronger password policy, advocating that users upgrade their passwords to mitigate potential risks. Despite Tangem’s assertion that the threat level is minimal, Ledger’s technical analysis underscores a significant risk of real-life breaches, which could lead to damaging consequences for users who rely on weak passwords.

Where Could the Hedera (HBAR) Price be Headed This Week?
U.S. Defense Secretary’s Enthusiasm for Bitcoin Boosts Market Confidence
Coinbase Shares Slip as Analyst Warns of Softer Crypto Volumes
Dogecoin Enters Parabolic Phase Despite Recent Price Decline
Top Crypto Coins to Watch in 2026: Insights on XRP, Cardano, Hedera, and BlockDAG
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article a couple meeting with an advisor Is the S&P 500 Still the Best Bet for Risk-Averse Investors?
Next Article 82addf54101924cf94d586d844015a882f3314ba 1920x1080 Stablecoin Adoption Surge Among Corporates Driven by Regulatory Clarity and Cost Savings
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
European Investment Banks Struggle to Compete with Wall Street Rivals
BTCfullsize 109 457x457
Bitcoin Price Supported by $532.3 Million ETF Inflow Amid Regulatory Clarity
395116f65469a8e16423df258d8a6df1a3af4b95 3840x2160
Bitcoin Surges Past $81,000 in Major Market Move
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Company
  • Finance
  • Stocks
  • News
  • Bitcoin
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?