Ledger logo by Wikimedia contributor, CC BY-SA 4.0
A laser fault-injection vulnerability found in Trezor's hardware led to an unusual display of competitor cooperation, with both firms warning that AI is accelerating the exploit arms race.
Two of the biggest names in crypto hardware wallets just demonstrated something vanishingly rare in the tech industry: competitors working together to make each other’s products safer. Ledger’s security research arm, Donjon, discovered a vulnerability in a chip used by Trezor’s Safe 7 wallet, disclosed it responsibly, and both companies are now using the moment to push for industry-wide standards on how security flaws get reported.
The backdrop makes their plea more urgent. Both firms are warning that advances in artificial intelligence are compressing the timeline between vulnerability discovery and real-world exploitation, turning what used to be theoretical attacks into practical ones far more quickly.
What Ledger actually found #
In late January 2026, Ledger Donjon identified a laser fault-injection attack on the TROPIC01 chip, a secure element manufactured by Tropic Square and integrated into the Trezor Safe 7 wallet. The technique involves firing precisely targeted laser pulses at the chip to disrupt its operations, a method that sounds like science fiction but is well-established in hardware security research.
The vulnerability was publicly disclosed around June 3, 2026, after Ledger coordinated with Tropic Square directly. During that process, the chip’s manufacturer uncovered an additional attack path affecting PIN-related functions, meaning the collaboration produced more security insight than either party would have found alone.
Before anyone starts frantically moving funds: the attack requires physical possession of the device and access to specialized laboratory equipment. There is no remote or supply-chain risk associated with the flaw.
Trezor moved quickly to reassure users that their funds and backups remain safe. The reason ties back to the Safe 7’s design architecture. The TROPIC01 chip is just one of three independent security layers protecting user assets. Even if an attacker successfully exploited this single chip, the other two layers would still stand between them and a user’s crypto.
Why AI changes the calculus #
AI tools can accelerate brute-force attacks against weak entropy, which is the randomness that underpins cryptographic security. When the randomness in key generation or PIN systems isn’t robust enough, AI can chew through possibilities faster than traditional computing methods ever could.
Ledger referenced a roughly $116 million incident related to Coldcard wallets in July 2026 as a cautionary example of what happens when entropy weaknesses meet increasingly powerful attack tools.
A history of competitive cooperation #
This isn’t the first time Ledger and Trezor have disclosed vulnerabilities in each other’s products. The two companies have a history of responsible disclosure stretching back to 2018-2019, when early-generation hardware wallet flaws were identified through cross-company research. More recently, a voltage-glitch vulnerability was disclosed in 2025, following similar coordinated protocols.
Trezor CEO Matej Žák framed the latest exchange as a model for the industry.
“This is the model the industry should hold itself to.”
The statement carries weight because Trezor’s approach is rooted in open-source principles. The TROPIC01 chip itself comes from Tropic Square, a company aligned with transparent hardware design, where security through obscurity is explicitly rejected in favor of public scrutiny. Ledger, by contrast, uses proprietary secure elements in its own devices. What’s notable here is that both companies are setting aside that debate to advocate for a shared framework around disclosure practices.
What this means for the hardware wallet market #
For users, the immediate takeaway is reassuring: the vulnerability was found, reported, and mitigated through layered security before it could be exploited in the wild. The $116 million Coldcard-related incident Ledger cited serves as a concrete reminder that theoretical vulnerabilities eventually become real losses.
For consumers weighing self-custody options, the episode reinforces a practical point. The Trezor Safe 7’s three-layer architecture is what prevented a real vulnerability from becoming a real problem. When evaluating hardware wallets, the question isn’t whether vulnerabilities exist. The question is whether the architecture is designed to contain them when they surface. Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our