Trezor says Safe 7 funds remain secure after Ledger Donjon found a TROPIC01 chip flaw during lab testing with physical access.Trezor says Safe 7 funds remain secure after Ledger Donjon found a TROPIC01 chip flaw during lab testing with physical access.

Trezor says Safe 7 funds are safe after Ledger finds chip flaw

2026/06/03 18:31
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Trezor and Tropic Square have disclosed a TROPIC01 chip flaw found by Ledger Donjon, but said the Trezor Safe 7 wallet and user funds remain secure.

Summary
  • Trezor says Safe 7 user funds remain safe because three hardware layers protect wallet access.
  • Ledger Donjon found the TROPIC01 flaw during lab tests using laser fault injection techniques.
  • Tropic Square disclosed the flaw publicly and said the chip issue needs physical lab access.

The vulnerability was found during an independent audit of the TROPIC01 Secure Element chip. Ledger Donjon, the white-hat research team at rival hardware wallet maker Ledger, carried out the review.

Tropic Square gave the chip to Ledger Donjon for testing. Trezor said the flaw affects one of three independent security layers inside the Safe 7 wallet.

According to the disclosure, Ledger Donjon told Tropic Square in January 2026 that it had carried out a laser fault injection attack under lab conditions. The attack allowed researchers to extract some chip secrets and bypass firmware signature checks.

Tropic Square later found another way to use the same weakness. That method could expose another secret tied to PIN-related chip functions.

Trezor says funds remain protected

Trezor said users do not need to take action. The company said a compromise of TROPIC01 alone does not give access to a user’s PIN, wallet or funds.

“Because the Trezor Safe 7 was built with multiple independent security layers, a vulnerability in TROPIC01 does not put user funds at risk,” Trezor CEO Matej Žák said.

The issue sits at the hardware level, so it cannot be fixed through a normal remote firmware update. Trezor and Tropic Square still chose public disclosure after reviewing Ledger Donjon’s findings.

The Safe 7 uses TROPIC01 with two other chips. Its design combines TROPIC01, OPTIGA Trust M and STM32U5 to protect PIN checks, device authenticity and wallet creation.

Hardware wallet audits remain in focus

The disclosure gives a rare public view of rival security testing in the hardware wallet market. Ledger Donjon has previously reviewed Trezor devices and published research on physical attack routes.

As previously reported by crypto.news, Ledger Donjon earlier said Trezor Safe devices still faced physical attack risks linked to microcontroller use. Trezor said at the time that user funds remained safe when devices came from official sources.

Separate crypto.news coverage also warned that some hardware wallets using ESP32 chips faced private key theft risks. That report showed that chip-level flaws remain a key security concern for crypto custody devices.

Open security model faces real tests

Tropic Square markets TROPIC01 as an open and auditable secure element. The company says the chip lets researchers inspect and test hardware that would often remain closed under non-disclosure terms.

The new flaw shows that open testing can reveal weaknesses before attackers do. It also shows that hardware wallet security depends on full device design, not only one chip.

For users, the main guidance remains simple. They should buy devices from official channels, keep firmware updated, protect recovery phrases offline and avoid using any wallet that shows signs of tampering.

Market Opportunity
USD.AI Logo
USD.AI Price(CHIP)
$0.04065
$0.04065$0.04065
-0.24%
USD
USD.AI (CHIP) Live Price Chart

SPACEX(PRE) Launchpad

SPACEX(PRE) LaunchpadSPACEX(PRE) Launchpad

Register for a chance to win a free lucky draw

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

RealStocks Now Live

RealStocks Now LiveRealStocks Now Live

Trade real U.S. stock via regulated brokerage