Atlas21
  • ‎
No Result
View All Result
Atlas21
No Result
View All Result
Atlas21
Home Bitcoin

Trezor: hardware vulnerability in the TROPIC01 secure element of the Safe 7, funds remain safe

Newsroom by Newsroom
June 3, 2026
in Bitcoin
Trezor: vulnerabilità hardware nel secure element TROPIC01 del Safe 7, fondi al sicuro
Share on FacebookShare on TwitterShare on Linkedin

An audit by the Ledger Donjon team identified a flaw in the Secure Element chip of the Trezor Safe 7 wallet: exploiting it requires physical access and specialized equipment.

Trezor has publicly disclosed the existence of a vulnerability in its flagship hardware wallet, the Safe 7, clarifying that users’ funds “remain protected” due to the nature of the exploit. The flaw was discovered during an independent security audit conducted by the Ledger Donjon team, which reported a “laser fault injection” attack against the TROPIC01 Secure Element chip.

The attack allows a malicious actor to extract one of the three “secrets” that protect the user’s PIN, effectively reducing the three physical layers of protection to two. As Trezor’s official blog states: “The vulnerability only affects the TROPIC01 Secure Element chip, one of three independent physical security layers. Compromising TROPIC01 alone is not sufficient to access the PIN, which is the final layer of protection for funds”. Trezor also adds that the flaw “cannot result in Trezor Safe 7 devices being tampered with persistent malicious firmware”.

To exploit the vulnerability, according to Trezor, an attacker must physically possess the wallet, disassemble it, and use specialized laboratory equipment. For this reason, the company still defines the TROPIC01 chip as an “effective barrier” of protection that “requires significant time and effort to exploit”. Blockchain security firm Cyvers confirmed Trezor’s assessment, stating that the attack appears “highly impractical”.

A critical aspect of the situation is that, as a hardware-level vulnerability, it cannot be fixed through a firmware update. Users’ private keys, however, are not stored in the TROPIC01 chip, which further limits the concrete risk to funds.

Deddy Lavid, CEO of Cyvers, offered a broader perspective on the topic of hardware wallet security, telling Decrypt: “The security of a hardware wallet should not be evaluated solely on whether a chip can be attacked in a lab. For most users, the far greater risk is still phishing, seed phrase theft, malicious dApps, and blind-signed transactions they don’t fully understand”.

Previous Post

USA: Treasury sanctions Nobitex, Iran’s largest crypto exchange

Next Post

Bitcoin: over $600 million in longs liquidated as BTC heads toward $60,000

Latest News

Coldcard bug, weak seeds generated since 2021: “Funds are at risk, move them now”
Bitcoin

Coldcard bug, weak seeds generated since 2021: “Funds are at risk, move them now”

by Federico Rivi
July 31, 2026
0

Less than 24 hours after the 594 BTC theft, Coinkite publishes a security advisory and technical review: seed generation on...

Read moreDetails
594 bitcoin svuotati in quindici minuti: cosa sappiamo finora
Bitcoin

594 bitcoin drained in fifteen minutes: what we know so far

by Federico Rivi
July 30, 2026
0

In the early hours of 30 July an automated operation swept 500 single-sig addresses across four consecutive blocks. Evidence points...

Read moreDetails
The dark side of Telegram founder’s arrest
Feature

Pavel Durov and the price of non-compliant communication

by Federico Rivi
July 30, 2026
0

The FSB charges Durov with terrorism: when a platform escapes surveillance, the state turns the refusal to cooperate into a...

Read moreDetails
Industry

IMF calls on Brazil to impose controls on digital asset flows

by Newsroom
July 29, 2026
0

An International Monetary Fund paper finds that digital asset transfers in Brazil exceed traditional channel volumes and calls for stronger...

Read moreDetails
Chat private di Claude indicizzate da Google e Bing
Industry

Claude private chats indexed by Google and Bing

by Newsroom
July 29, 2026
0

Anthropic enabled public sharing of conversations without warning users that search engine crawlers would make them retrievable by anyone.

Read moreDetails
Atlas21

© 2026 Atlas21

Navigate Site

  • Editorial Policy
  • Cookie Policy
  • Privacy Policy
  • Team

Follow Us

Italiano
No Result
View All Result
  • Bitcoin 101
    • What Is Bitcoin? A Complete Guide
    • Bitcoin Security: A Complete Guide
    • Bitcoin Privacy: A Complete Guide
    • Lightning Network: A Complete Guide
    • Bitcoin Mining: A Complete Guide
    • Advanced Bitcoin: A Technical Guide
  • Learn
  • Latest News
  • Interviews
  • Opinion
  • Feature
  • B2B Services
  • About Us
  • Contacts

© 2026 Atlas21

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site, we will assume that you are happy with it.