• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Security Flaw Discovered in Tangem Cold Wallet Cards Allowing Easier PIN Code Brute Force Attacks
Share
  • bitcoinBitcoin(BTC)$92,596.00
  • ethereumEthereum(ETH)$3,200.19
  • tetherTether(USDT)$1.00
  • binancecoinBNB(BNB)$924.49
  • rippleXRP(XRP)$1.96
  • usd-coinUSDC(USDC)$1.00
  • solanaSolana(SOL)$133.31
  • tronTRON(TRX)$0.317667
  • staked-etherLido Staked Ether(STETH)$3,195.73
  • dogecoinDogecoin(DOGE)$0.127109
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
Company

Security Flaw Discovered in Tangem Cold Wallet Cards Allowing Easier PIN Code Brute Force Attacks

News Desk
Last updated: September 21, 2025 3:03 pm
News Desk
Published: September 21, 2025
Share
Protos Artwork Tangem SIMG

A significant security vulnerability has been uncovered in Tangem’s cold wallet cards, allowing potential hackers to brute force the PIN codes through a method known as the “tearing attack.” This discovery was made public by Ledger’s white hat hacker team, Donjon. Charles Guillemet, the Chief Technology Officer at Ledger, shared information about the exploit via a post on X, stating that it had been communicated to Tangem, the competing hardware wallet company.

The crux of the vulnerability lies in how the Tangem cards handle power loss during the authentication process. Donjon’s analysis revealed that disconnecting a Tangem card’s power source before it registers a password attempt could prevent it from counting failed attempts. This flaw offers hackers the unique ability to test multiple password combinations without triggering any security measures.

In a clever twist, Donjon devised a method to monitor the electromagnetic emissions released by the card with each password input. By analyzing these emissions, hackers can identify a distinct pattern indicating a correct guess, drastically lowering the effort required to crack the code.

This “tearing attack” significantly accelerates the brute-force attack timeframe. For example, while it would typically take around five days to crack a four-digit PIN under normal security protections, the new method reduces that duration to approximately one hour. Similarly, cracking an eight-digit code could go from about 148 years to around 460 days, allowing hackers to attempt more than two passwords every second.

The estimated cost to execute this attack is about $5,000. However, Donjon acknowledged that although this cost puts the method within reach of various attackers, physical access to the target card is still required for success.

Unfortunately for Tangem card users, there is no feasible patch to rectify this exploit on existing cards. In light of these findings, Donjon advised users to adopt longer, more complex passwords, including alphanumeric characters and symbols, to enhance security against such attacks.

Tangem’s response to the findings appeared dismissive. According to Donjon, representatives from Tangem did not regard the disclosed vulnerabilities as significant, stating that the described scenario posed minimal risk. They further noted that, despite the responsible disclosure process followed by Donjon, no bounty was awarded for their findings. Tangem emphasized that they prioritize vulnerabilities with practical implications over what they consider theoretical attacks requiring considerable resources.

In its defense, Tangem argued that the method proposed by Donjon would likely result in the physical destruction of the card’s chip long before any access code could be successfully guessed. They claimed that, even if the chip survived, brute-forcing a four-digit code would take months, and a five-digit code would require over 64 years.

Donjon, on the other hand, expressed disappointment with Tangem’s rebuttal, asserting that the process does not inherently destroy the card and insisting that their exploit would indeed expedite brute-force attempts by a factor of one hundred, particularly against weak passwords. They also contended that the attack is not overly sophisticated, emphasizing its accessibility and the need for basic certification standards, such as the EAL 3 grade.

While Ledger’s focus remains on strengthening the security of its ecosystem and supporting broader security initiatives, it has faced its share of vulnerabilities. Past incidents include a supply chain attack in 2023 that compromised user wallets via a breach of a former employee’s account, as well as a data breach in July 2020 that exposed customer information, leading to significant ramifications for those affected.

Executive Interview with Andres Jimenez from Swiset at iFX EXPO International 2025
OKX to List PAX Gold (PAXG) on October 15th
Bitget Launches PORTALSUSDT for Futures Trading with 20x Leverage
BlockDAG Leads October’s Crypto Spotlight with Strong Performance and Global Partnership
OpenSea Prepares for SEA Token Launch Amid NFT Market Decline
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article TCB 001 2024 12 13T104026583 How XRP Could Make You $1M by 2040
Next Article 2235873725 94bafa Major European Airports Recover from Cyberattack Disrupting Check-In Systems
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
108247124 17672001632025 12 31t162352z 2034036607 rc2sria2w6nj rtrmadp 0 new year china
Investors React to Trump-Greenland Tensions as Asia-Pacific Markets Slide
f220a7d2018949b26a657641abbc87921768796658844
Whale 0x10ea’s $14.56M DOGE Position Wiped Out
a32031b8bd05707d56c215aae3c87594
Jefferies Financial Group Exits Bitcoin Allocation, Shifts to Gold Amid Security Concerns
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • News
  • Finance
  • Company
  • Stocks
  • Bitcoin
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?