Ledger Discloses TROPIC01 Chip Vulnerability in Trezor Safe 7, Trezor Says User Funds Remain Secure

According to The Block, Ledger's Donjon security team discovered a firmware verification bypass vulnerability in the TROPIC01 chip used by Trezor Safe 7 through laser-based attacks in laboratory conditions. The attack, which requires physical device possession, could enable loading of unauthorized firmware. Chip manufacturer Tropic Square identified an additional attack path targeting the chip's MAC-and-Destroy PIN verification mechanism, with enhanced chip versions scheduled for release by end of 2026.

Trezor stated that PIN, recovery seeds, and private keys are not stored on a single chip, and users require no action. The company recommends disabling the chip's MAINTENANCE mode to reduce attack feasibility and has notified partners about the vulnerability.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments