Start now →

Trezor Reveals Hardware Wallet Vulnerability, But Funds 'Safe'

By Ryan Gladwin · Published June 3, 2026 · 3 min read · Source: Decrypt
RegulationSecurity
Trezor Reveals Hardware Wallet Vulnerability, But Funds 'Safe'
NewsTechnology

Trezor Reveals Hardware Wallet Vulnerability, But Funds 'Safe'

The vulnerability in Trezor's TROPIC01 Secure Element chip was uncovered by an audit carried out by the Ledger Donjon team.

Ryan S. GladwinBy Ryan S. GladwinEdited by Stephen GravesJun 3, 2026Jun 3, 20263 min read
Trezor Safe 7. Image: Decrypt/Trezor
Trezor Safe 7. Image: Decrypt/Trezor
Create an account to save your articles.Add on GoogleAdd Decrypt as your preferred source to see more of our stories on Google.

In brief

Trezor has revealed a vulnerability in its flagship Safe 7 hardware wallet, but affirms that user funds "remain protected" due to the nature of the exploit.

The vulnerability was uncovered during an independent security audit by the Ledger Donjon team, which reported a successful "laser fault injection attack" against the TROPIC01 Secure Element chip. It enables an attacker to extract one of three "secrets" that protect a user's PIN, effectively reducing three layers of protection to two.

Tropic Square disclosed a vulnerability in the TROPIC01 Secure Element chip used in Trezor Safe 7. It has been identified based on findings from the Ledger Donjon team's independent audit.

Important: Your funds remain safe and secure. Trezor Safe 7 has not been hacked, and you…

— Trezor (@Trezor) June 3, 2026

"The vulnerability concerns only the TROPIC01 Secure Element chip, one of three physical, independent security layers. Compromising TROPIC01 alone is not enough to give access to the PIN, which is the final layer of protection for your funds," the Trezor blog states. "It also cannot result in tampered Trezor Safe 7 devices with persistent malicious firmware."

It's worth noting that Trezor says that such an attack requires physical possession of the hardware wallet, for the attacker to disassemble it, and for specialized lab equipment to be used. As such, Trezor still calls the TROPIC01 chip an "effective barrier" of protection which "requires significant time and effort to exploit," adding that "users’ funds remain safe."

Blockchain security firm Cyvers echoed Trezor’s assessment that user funds are "safe," telling Decrypt that the attack appears "highly impractical."

Hardware wallets, otherwise known as "cold" wallets, store private keys offline on a physical device. This is in contrast to hot wallets, like MetaMask, which store the user's keys on locally installed software or on cloud-based servers. In the case of the Trezor Safe 7 wallet, the blog post says that the user's keys are fortunately not stored in the TROPIC01 chip.

Unfortunately, due to the vulnerability being hardware-based, the exploit cannot be patched with a firmware update. Trezor did not immediately respond to Decrypt's request for comment on whether it will accept refund requests from customers.

"Hardware wallet security should not be evaluated only by whether a chip can eventually be attacked in a lab," Deddy Lavid, CEO of Cyvers, told Decrypt. "For most users, the much larger risk is still phishing, seed phrase theft, malicious dApps, and blind-signing transactions they do not fully understand."

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.
This article was originally published on Decrypt and is republished here under RSS syndication for informational purposes. All rights and intellectual property remain with the original author. If you are the author and wish to have this article removed, please contact us at [email protected].

NexaPay — Accept Card Payments, Receive Crypto

No KYC · Instant Settlement · Visa, Mastercard, Apple Pay, Google Pay

Get Started →