• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Security Flaw Discovered in Tangem Cold Wallet Cards Allowing Easier PIN Code Brute Force Attacks
Share
  • bitcoinBitcoin(BTC)$76,728.00
  • ethereumEthereum(ETH)$2,117.22
  • tetherTether(USDT)$1.00
  • binancecoinBNB(BNB)$657.98
  • rippleXRP(XRP)$1.35
  • usd-coinUSDC(USDC)$1.00
  • solanaSolana(SOL)$86.64
  • tronTRON(TRX)$0.360835
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03
  • dogecoinDogecoin(DOGE)$0.105585
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
Company

Security Flaw Discovered in Tangem Cold Wallet Cards Allowing Easier PIN Code Brute Force Attacks

News Desk
Last updated: September 21, 2025 3:03 pm
News Desk
Published: September 21, 2025
Share
Protos Artwork Tangem SIMG

A significant security vulnerability has been uncovered in Tangem’s cold wallet cards, allowing potential hackers to brute force the PIN codes through a method known as the “tearing attack.” This discovery was made public by Ledger’s white hat hacker team, Donjon. Charles Guillemet, the Chief Technology Officer at Ledger, shared information about the exploit via a post on X, stating that it had been communicated to Tangem, the competing hardware wallet company.

The crux of the vulnerability lies in how the Tangem cards handle power loss during the authentication process. Donjon’s analysis revealed that disconnecting a Tangem card’s power source before it registers a password attempt could prevent it from counting failed attempts. This flaw offers hackers the unique ability to test multiple password combinations without triggering any security measures.

In a clever twist, Donjon devised a method to monitor the electromagnetic emissions released by the card with each password input. By analyzing these emissions, hackers can identify a distinct pattern indicating a correct guess, drastically lowering the effort required to crack the code.

This “tearing attack” significantly accelerates the brute-force attack timeframe. For example, while it would typically take around five days to crack a four-digit PIN under normal security protections, the new method reduces that duration to approximately one hour. Similarly, cracking an eight-digit code could go from about 148 years to around 460 days, allowing hackers to attempt more than two passwords every second.

The estimated cost to execute this attack is about $5,000. However, Donjon acknowledged that although this cost puts the method within reach of various attackers, physical access to the target card is still required for success.

Unfortunately for Tangem card users, there is no feasible patch to rectify this exploit on existing cards. In light of these findings, Donjon advised users to adopt longer, more complex passwords, including alphanumeric characters and symbols, to enhance security against such attacks.

Tangem’s response to the findings appeared dismissive. According to Donjon, representatives from Tangem did not regard the disclosed vulnerabilities as significant, stating that the described scenario posed minimal risk. They further noted that, despite the responsible disclosure process followed by Donjon, no bounty was awarded for their findings. Tangem emphasized that they prioritize vulnerabilities with practical implications over what they consider theoretical attacks requiring considerable resources.

In its defense, Tangem argued that the method proposed by Donjon would likely result in the physical destruction of the card’s chip long before any access code could be successfully guessed. They claimed that, even if the chip survived, brute-forcing a four-digit code would take months, and a five-digit code would require over 64 years.

Donjon, on the other hand, expressed disappointment with Tangem’s rebuttal, asserting that the process does not inherently destroy the card and insisting that their exploit would indeed expedite brute-force attempts by a factor of one hundred, particularly against weak passwords. They also contended that the attack is not overly sophisticated, emphasizing its accessibility and the need for basic certification standards, such as the EAL 3 grade.

While Ledger’s focus remains on strengthening the security of its ecosystem and supporting broader security initiatives, it has faced its share of vulnerabilities. Past incidents include a supply chain attack in 2023 that compromised user wallets via a breach of a former employee’s account, as well as a data breach in July 2020 that exposed customer information, leading to significant ramifications for those affected.

Cathie Wood Predicts US Government Could Begin Purchasing Bitcoin to Build Strategic Reserve
Caliber Announces Initial Purchase of Chainlink Tokens as Part of Digital Asset Treasury Strategy
HBAR Price Predictions Through 2031 Show Significant Growth Potential
DeepSeek AI Predicts Explosive Gains for Ethereum, XRP, and Cardano Amid Market Volatility
Bitget Sees Surge in Institutional Participation, Accounting for 80% of Total Volume
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article TCB 001 2024 12 13T104026583 How XRP Could Make You $1M by 2040
Next Article 2235873725 94bafa Major European Airports Recover from Cyberattack Disrupting Check-In Systems
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
8747762748650c0e78470ca04cfdd030
Coinbase Global Says New Crypto Rules Could Unleash Its ‘Everything Exchange’
108309149 1779205692146 gettyimages 2232601959 ar 5515 jkhvzp8i
Stocks Gain Momentum as Workday, Deckers, and Estee Lauder Post Strong Earnings
108310518 17793718312025 12 03t220222z 1230587347 rc299iaywlsr rtrmadp 0 usa trump
Stellantis CEO Highlights Opportunities for Partnerships and Production Expansion in North America
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Company
  • Finance
  • Stocks
  • Bitcoin
  • News
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?