Atlas21
  • ‎
No Result
View All Result
Atlas21
No Result
View All Result
Atlas21
Home Bitcoin

Vulnerability discovered in Trezor Safe devices by Ledger team

Newsroom by Newsroom
March 17, 2025
in Bitcoin
Scoperta vulnerabilitĂ  nei dispositivi Trezor Safe grazie al team di Ledger
Share on FacebookShare on TwitterShare on Linkedin

The Ledger open-source research team has discovered and reported a vulnerability in Trezor’s Safe 3 and Safe 5 devices.

According to a post published on X on March 12, the Ledger open-source research team, known as Ledger Donjon, identified a flaw in the microcontrollers of Trezor’s Safe 3 and Safe 5 models. Despite Trezor’s recent security improvements, Ledger found that cryptographic operations can still be performed on the microcontroller, potentially exposing the devices to more “advanced attacks”.

At @Ledger, you might know that we have the @DonjonLedger, our dedicated team constantly conducting open security research.

We recently worked with Trezor, revealing that their Trezor Safe 3 was susceptible to physical supply chain attacks. Here's a thread on our findings:đź§µ pic.twitter.com/CORDOQWRYg

— Charles Guillemet (@P3b7_) March 12, 2025

Charles Guillemet, Chief Technology Officer at Ledger, stated:

“We believe that making the ecosystem more secure helps everyone, and is critical as we push towards broader adoption of crypto and digital assets.”

Trezor had already implemented Secure Elements (SE)—chips designed to protect users’ PIN codes and cryptographic secrets—since earlier Trezor devices could be compromised by modifying the running software, potentially allowing attackers to steal users’ funds. According to Ledger, this implementation “effectively hinders any low-cost hardware attack, particularly voltage glitching,” ensuring users’ funds remain protected even if the device is lost or stolen.

However, Ledger identified another potential attack vector originating from the microcontroller, the other main component of Trezor’s dual-chip design in the Safe 3 and 5 models. Trezor implemented firmware integrity checks to detect modified software, but Ledger demonstrated that an attacker can still bypass this security measure.

Source: Ledger

Trezor confirmed on X that users’ funds remain safe and no action is required. However, when asked whether the issue could be fixed via a firmware update, the hardware wallet provider responded:

Hi, unfortunately not. In cybersecurity, the golden rule is simple: nothing is fully unbreakable. That’s why we have already implemented a multi-layer defense against supply chain attacks and always advise our users to purchase from official sources.

— Trezor (@Trezor) March 12, 2025
Previous Post

The strategic Bitcoin reserve is for businesses, not for states

Next Post

Russia: the Central Bank opens crypto trading to qualified investors

Latest News

Il 94% dei titoli “tokenizzati” sul mercato è centralizzato
Industry

94% of “tokenized” stocks on the market are centralized

by Newsroom
July 27, 2026
0

A single California broker holds more than $1.5 billion in shares underlying stock tokens, while the SEC warns that third-party...

Read moreDetails
el salvador
Bitcoin

Five years of Bitcoin Law: bitcoin remittances in El Salvador remain at 0.7%

by Newsroom
July 27, 2026
0

Data from the Central Bank of El Salvador for the first half of 2026 show that of more than $5...

Read moreDetails
BancaStato lancia il trading Bitcoin tramite Sygnum e Avaloq
Bitcoin

BancaStato launches Bitcoin trading via Sygnum and Avaloq

by Newsroom
July 24, 2026
0

The Ticino cantonal bank integrates Bitcoin into its digital channels, relying on Sygnum's infrastructure and the Avaloq core banking platform

Read moreDetails
Report BIS: la Banca dei Regolamenti Internazionali boccia le stablecoin
Feature

When the BIS discovers its own irrelevance

by Federico Rivi
July 24, 2026
0

The central bank of central banks warns that dollar stablecoins bypass capital controls, fearing the erosion of its own relevance...

Read moreDetails
ledger bug
Industry

Flaw in Zilliqa’s Ledger app exposes users’ private keys

by Newsroom
July 23, 2026
0

Zilliqa reports that the vulnerability generates predictable ephemeral nonces, allowing an attacker to reconstruct a user's private key from publicly...

Read moreDetails
Atlas21

© 2026 Atlas21

Navigate Site

  • Editorial Policy
  • Cookie Policy
  • Privacy Policy
  • Team

Follow Us

Italiano
No Result
View All Result
  • Bitcoin 101
    • What Is Bitcoin? A Complete Guide
    • Bitcoin Security: A Complete Guide
    • Bitcoin Privacy: A Complete Guide
    • Lightning Network: A Complete Guide
    • Bitcoin Mining: A Complete Guide
    • Advanced Bitcoin: A Technical Guide
  • Learn
  • Latest News
  • Interviews
  • Opinion
  • Feature
  • B2B Services
  • About Us
  • Contacts

© 2026 Atlas21

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site, we will assume that you are happy with it.