Atlas21
  • ‎
No Result
View All Result
Atlas21
No Result
View All Result
Atlas21
Home Bitcoin

Vulnerability discovered in Trezor Safe devices by Ledger team

Newsroom by Newsroom
March 17, 2025
in Bitcoin
Scoperta vulnerabilitĂ  nei dispositivi Trezor Safe grazie al team di Ledger
Share on FacebookShare on TwitterShare on Linkedin

The Ledger open-source research team has discovered and reported a vulnerability in Trezor’s Safe 3 and Safe 5 devices.

According to a post published on X on March 12, the Ledger open-source research team, known as Ledger Donjon, identified a flaw in the microcontrollers of Trezor’s Safe 3 and Safe 5 models. Despite Trezor’s recent security improvements, Ledger found that cryptographic operations can still be performed on the microcontroller, potentially exposing the devices to more “advanced attacks”.

At @Ledger, you might know that we have the @DonjonLedger, our dedicated team constantly conducting open security research.

We recently worked with Trezor, revealing that their Trezor Safe 3 was susceptible to physical supply chain attacks. Here's a thread on our findings:đź§µ pic.twitter.com/CORDOQWRYg

— Charles Guillemet (@P3b7_) March 12, 2025

Charles Guillemet, Chief Technology Officer at Ledger, stated:

“We believe that making the ecosystem more secure helps everyone, and is critical as we push towards broader adoption of crypto and digital assets.”

Trezor had already implemented Secure Elements (SE)—chips designed to protect users’ PIN codes and cryptographic secrets—since earlier Trezor devices could be compromised by modifying the running software, potentially allowing attackers to steal users’ funds. According to Ledger, this implementation “effectively hinders any low-cost hardware attack, particularly voltage glitching,” ensuring users’ funds remain protected even if the device is lost or stolen.

However, Ledger identified another potential attack vector originating from the microcontroller, the other main component of Trezor’s dual-chip design in the Safe 3 and 5 models. Trezor implemented firmware integrity checks to detect modified software, but Ledger demonstrated that an attacker can still bypass this security measure.

Source: Ledger

Trezor confirmed on X that users’ funds remain safe and no action is required. However, when asked whether the issue could be fixed via a firmware update, the hardware wallet provider responded:

Hi, unfortunately not. In cybersecurity, the golden rule is simple: nothing is fully unbreakable. That’s why we have already implemented a multi-layer defense against supply chain attacks and always advise our users to purchase from official sources.

— Trezor (@Trezor) March 12, 2025
Previous Post

The strategic Bitcoin reserve is for businesses, not for states

Next Post

Russia: the Central Bank opens crypto trading to qualified investors

Latest News

tether
Crypto

Tether: first full financial audit with KPMG

by Newsroom
March 27, 2026
0

The USDT issuer has engaged Big Four firm KPMG for its first complete independent financial audit, alongside PwC for internal...

Read moreDetails
gamestop
Bitcoin

GameStop: the 4,709 BTC were not sold, they were held as collateral at Coinbase

by Newsroom
March 27, 2026
0

The 10-K filing submitted to the SEC clarifies that GameStop pledged its bitcoin as collateral as part of a covered-call...

Read moreDetails
brasile digital asset
Crypto

Brazil: seized digital assets to fund public security

by Newsroom
March 27, 2026
0

President Lula signed Law No. 15.358, directing digital assets confiscated from criminal organizations toward law enforcement funding.

Read moreDetails
mutui
Crypto

Fannie Mae: crypto-backed mortgages green-lit with Better and Coinbase

by Newsroom
March 26, 2026
0

For the first time in the history of the American real estate system, Fannie Mae will accept digital assets as...

Read moreDetails
uk
Crypto

UK: temporary ban on political donations in digital assets

by Newsroom
March 27, 2026
0

The British government has announced a moratorium on political donations in digital assets, with retroactive effect from March 25.

Read moreDetails
Atlas21

© 2026 Atlas21

Navigate Site

  • Editorial Policy
  • Cookie Policy
  • Privacy Policy
  • Team

Follow Us

No Result
View All Result
  • Bitcoin 101
    • What Is Bitcoin? A Complete Guide
    • Bitcoin Security: A Complete Guide
    • Bitcoin Privacy: A Complete Guide
    • Lightning Network: A Complete Guide
    • Bitcoin Mining: A Complete Guide
    • Advanced Bitcoin: A Technical Guide
  • Learn
  • Latest News
  • Interviews
  • Opinion
  • Feature
  • B2B Services
  • About Us
  • Contacts

© 2026 Atlas21

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site, we will assume that you are happy with it.