Trezor Safe 7 TROPIC01 Flaw Found by Ledger Donjon, Funds Remain Safe

Share

Trezor and Tropic Square jointly disclosed a hardware vulnerability affecting the TROPIC01 chip of the Trezor Safe 7 wallet, identified by the Ledger Donjon team during an independent audit. Despite the flaw, the wallet’s three-layer independent security architecture preserves the integrity of user funds, both companies stated on June 2, 2026.

🔑 Key Takeaways

  • Ledger Donjon discovered a laser fault injection flaw on the TROPIC01 chip.
  • The attack requires physical access to the wallet and specialized lab equipment.
  • The Trezor Safe 7 relies on three independent components: TROPIC01, OPTIGA Trust M, and STM32U5.
  • No user action required; no real-world exploitation has been observed.
  • Tropic Square is preparing a hardware and software fix for the next chip revision.

Origin of the disclosure: an independent audit

The audit was commissioned by Tropic Square itself, the semiconductor company affiliated with Trezor that developed the TROPIC01 component. Launched in early 2025 and integrated into the Trezor Safe 7 wallet released in October 2025, the chip was voluntarily handed over to Ledger Donjon — the security research team of competitor Ledger — for independent testing, illustrating a proactive transparency initiative.

In January 2026, Donjon researchers informed Tropic Square that they had successfully executed a laser fault injection attack (a technique that deliberately disrupts a chip’s operation using targeted light pulses) on the component under controlled laboratory conditions. This attack allowed them to extract certain secrets stored in the chip and bypass firmware signature verifications.

After analysis, Tropic Square engineers themselves identified a second exploitation method that could expose another secret tied to PIN protection functions. Both companies then notified their partners, including Trezor, and opted for a joint public disclosure on June 2, 2026.

Technical conditions of the attack

The attack targets two specific moments in the component’s lifecycle: the verification of a new firmware installation and the re-verification of firmware at device startup. Once this barrier is bypassed, an attacker can load and execute custom firmware. However, this exploitation requires a complex sequence of operations:

  • physical possession of the Trezor Safe 7 wallet;
  • complete disassembly of the device;
  • desoldering of certain components;
  • back-side decapsulation (removal of the chip’s protective casing);
  • access to specialized laboratory equipment;
  • deep technical expertise.

Furthermore, the attack must be re-executed at every power-on, which prevents the creation of tampered devices with persistent malicious firmware. No supply-chain threat has been identified, and the random number generation during initial wallet setup — combining sources from the STM32U5, Optiga, TROPIC01, and the host computer — remains out of reach of the attack.

A multi-layer security architecture

The Trezor Safe 7 was designed around a « three independent barriers » architecture in which no component trusts any other. The table below summarizes the role of each element:

ComponentSecurity functionOrigin
TROPIC01Firmware authentication and storage of part of the PIN secretTropic Square / Trezor
OPTIGA Trust MIndependent Secure Element, wipe after 10 wrong PIN attemptsInfineon
STM32U5Main microcontroller and complementary entropy sourceSTMicroelectronics

The attack technically reduces the number of physical barriers from three to two, as it allows extraction of one of the three secrets protecting the PIN code and the device attestation material. To access the wallet backup, an attacker would still need to compromise the OPTIGA and STM32U5 components, then brute-force the user’s PIN code.

A Trezor spokesperson told Cointelegraph that no Ledger Donjon research identified a vulnerability in OPTIGA, and that the STM32U5 used in the Safe 7 is a newer microcontroller against which no fault injection attack has been demonstrated to date. The company also emphasized that OPTIGA and STM32U5 come from different manufacturers and are produced in different countries, further diversifying security.

« Thanks to the multiple independent security layers of the Trezor Safe 7, a vulnerability in the TROPIC01 component does not put user funds at risk. This open process of discovery, review, and disclosure is the model the industry should adopt. »

Matej Žák, CEO of Trezor

Official position and corrective measures

Trezor publicly confirmed that users need to take no action: since the vulnerability is hardware-based, it cannot be fixed through a remote firmware update. No evidence of real-world exploitation has been found and the Trezor Safe 7 has never been hacked, according to the company. The Tropic Square team is working on hardware and software improvements to mitigate the flaw in the next revision of the component.

This incident is not the first of its kind. In 2024, Ledger Donjon had already published research on the Trezor Safe 3 demonstrating a physical supply-chain interception attack — desoldering and modifying the device before delivery to the user. Trezor responded publicly and strengthened its defenses, while stating that it had no knowledge of compromised funds during such incidents.


Conclusion: a transparency model for the industry

This disclosure illustrates an unusual cooperation between two major — and competing — players in the hardware wallet market. Trezor credited the Ledger Donjon team for identifying this weakness, arguing that independent research and open disclosure strengthen the entire crypto ecosystem. The incident also validates Tropic Square’s positioning, which markets TROPIC01 as the world’s only fully auditable security element — without non-disclosure agreements. The lesson is clear: the security of a hardware wallet depends on the overall design of the device, not on any single component, however robust.

Sources

This article is published for informational and educational purposes only. It does not constitute investment advice. Do your own research (DYOR) before making any decisions.

Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Lire la Suite

Articles