Back to news

Laser Exploit Cracks Tangem Wallets; Felon-Run Startup Hawks Zero-Days

Two separate security stories expose hardware wallet vulnerabilities and a fraudulent offensive cybersecurity firm recruiting researchers to sell exploits.

Laser Exploit Cracks Tangem Wallets; Felon-Run Startup Hawks Zero-Days

What happened

Researchers from Ledger's Donjon security team demonstrated a hardware-level attack against Tangem crypto wallet cards in which a precisely aimed laser pulse disrupts the card's chip at just the right moment, allowing an attacker to overwrite the password with one of their own choosing — no prior credentials required. Because the vulnerability lives in the card's hardware rather than its firmware, no software patch can close the gap. Separately, Krebs on Security revealed that a newly launched cybersecurity startup advertising multimillion-dollar payouts for zero-day exploits is controlled by two convicted felons with documented histories of operating fake intelligence firms and AI-driven lobbying platforms under false identities. The founders are described as far-right conspiracy theorists who have repeatedly rebranded failed or fraudulent ventures.

Why it matters for your business

For organizations or treasury functions using hardware wallet cards to custody digital assets, the Tangem findings are a reminder that physical security assumptions can be broken by sophisticated lab-grade equipment — the attack requires close physical access and specialized hardware, limiting mass exploitation, but it raises the risk calculus for high-value holdings stored on unpatched cards. Companies evaluating cold-storage solutions should ask vendors for documented hardware security certifications and threat-model physical access scenarios alongside software risks. The fraudulent zero-day startup story carries a different warning: any security researcher or vendor approached by unknown brokers offering outsized payments for vulnerability research should conduct rigorous due-diligence on buyers, since routing exploits through bad actors can create legal exposure and geopolitical risk for sellers and their employers alike.

What to watch next

Tangem has not yet issued a public remediation roadmap; watch for whether the company offers card-replacement programs or enhanced physical tamper-resistance in future hardware revisions. On the zero-day broker front, regulators and law enforcement have been increasing scrutiny of the vulnerability-acquisition market, and this case may accelerate calls for mandatory disclosure of who is buying and brokering exploits. Both stories collectively signal a broader trend: threat actors are targeting the physical and commercial infrastructure of cybersecurity, not just its software layer.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp