Ledger Donjon Security Research Team Discloses that the TROPIC01 chip used in Trezor Safe 7 has a hardware vulnerability that can bypass the firmware verification system through precise laser attacks in a laboratory environment. Trezor states that user funds, wallet backups, and private keys are not stored on the chip, and user funds are unaffected. Tropic Square claims that all deployed production TROPIC01 chips are affected and has discovered another potential attack vector that could impact the MAC-and-Destroy security mechanism; the reinforced version of the chip is expected to be released by the end of 2026, with full technical details expected to be disclosed in spring 2027. (The Block)

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 7
  • 3
  • Share
Comment
Add a comment
Add a comment
GateUser-1859b7cd
· 57m ago
Has MAC-and-Destroy been compromised as well? Was fault injection testing not performed during the chip design phase?
View OriginalReply0
MoonlightReef
· 6h ago
Firmware verification can all be bypassed, and supply chain security has once again become a focus.
View OriginalReply0
TokenomicsMechanic
· 6h ago
Wallet manufacturers will now be required to include Faraday cages and bulletproof glass as standard features.
View OriginalReply0
ButterStop-LossLine
· 6h ago
Laser attack costs are not low, so ordinary users should still be safe.
View OriginalReply0
GateUser-f78f1f3e
· 6h ago
This vulnerability is named quite vacation-vibe, TROPIC01, but it turns out to be a dud.
View OriginalReply0
Cross-SectionOfSucculent
· 6h ago
Trezor's response was quite quick, but rebuilding trust is harder than fixing the code.
View OriginalReply0
ReflectionsOnTheStreetCorner
· 6h ago
By the end of 2026... whether my hardware wallet will still be functional by then is a question in itself.
View OriginalReply0
  • Pinned