Key Highlights
Ledger's Donjon security team used a 1064 nm laser to bypass firmware signature verification on the TROPIC01 chip in Trezor's Safe 7 wallet, a method first executed in January 2026 and disclosed publicly in June.
The attack requires physical possession of the device, chip decapsulation, a specialized laser rig, and advanced technical expertise, placing it firmly in laboratory territory with no evidence of real-world exploitation.
Trezor confirmed that user funds, private keys, and wallet backups remain fully secure because the Safe 7 relies on multiple independent security layers rather than a single chip.
Trezor disclosed a vulnerability in the TROPIC01 chip used in its Safe 7 hardware wallet after Ledger's Donjon security lab identified and responsibly reported the flaw. The company confirmed that no user funds are at risk and that no action is required by Safe 7 owners.
The vulnerability centers on a Laser Fault Injection attack carried out in January 2026. Ledger's Donjon researchers decapsulated the TROPIC01 chip using a 1064 nm laser and directed it at the chip's boot path to defeat firmware signature verification. The hardware had to be physically removed from the device, desoldered, and prepared with a custom connection board before the attack could proceed. Security researchers detailed the full technical scope of the method, confirming its laboratory-only character.
Trezor and Tropic Square credited Ledger for the responsible disclosure. The two companies compete directly in the hardware wallet market, but both framed the collaboration as the right model for industry-wide security. Trezor CEO Matej Žák said the open process by which the flaw was found, examined, and disclosed is the standard the industry should hold itself to.
The practical threat to users is minimal. An attacker would need to physically seize the device, source specialized laser equipment, and possess advanced chip-level expertise. As the security research community confirmed following the disclosure, there is no evidence this vulnerability has ever been exploited in real-world conditions. Trezor's multi-layer architecture ensures that even a compromised TROPIC01 chip does not expose the private key material needed to access a wallet. Firmware updates are being evaluated in coordination with Tropic Square.