Ledger found a flaw in Trezor’s Safe 7 chip: what it does and doesn’t mean for your crypto

banner-image

Ledger’s security research team found a way to defeat one of three independent hardware layers inside Trezor’s Safe 7 wallet, using laboratory equipment a normal attacker would not have and physical possession of the device, according to Trezor’s own disclosure as reported by CoinDesk, CryptoSlate and crypto.news. That does not mean a user’s crypto is at risk: Trezor says the flaw alone does not expose a user’s PIN, private keys or funds, but that assurance comes from Trezor and its sister company, not from an outside auditor.

What Ledger actually found

The flaw sits in TROPIC01, a secure element chip that Trezor’s sister company Tropic Square designed to be openly auditable, according to CryptoSlate’s review of the device. Ledger’s white-hat research unit, known as Donjon, told Tropic Square in January 2026 it had run a laser-based fault-injection test in a lab setting, per CryptoSlate and crypto.news. That test let the researchers bypass the chip’s firmware-signature verification and extract some of the secrets stored on it, according to CryptoSlate and crypto.news; CoinDesk’s account is less specific, describing only that Donjon “used specialized laboratory equipment to bypass some of the chip’s protections.” Tropic Square later found a second, related way to use the same weakness, which crypto.news describes as potentially exposing another secret tied to the chip’s PIN-related functions; none of the other outlets characterize this second issue in the same detail, so that description should be treated as single-sourced.

Trezor and Tropic Square disclosed the finding publicly on 3 June 2026, crediting Ledger Donjon’s research, according to CoinDesk, CryptoSlate and crypto.news. On the company’s X account, Trezor posted that its Safe 7 had not been hacked and that funds remained safe, per the tweet reproduced in crypto.news’s article.

Why a broken chip is not the same as a broken wallet

The Safe 7’s design is built around the idea that no single chip should be able to leak a user’s funds on its own. According to CryptoSlate’s review, the device combines three separate components to protect the seed: a TROPIC01 chip, a second secure element from Infineon carrying an EAL6+ certification, and a microcontroller, the STM32U5, that provides a third layer of checks. CryptoSlate describes the Optiga chip as the certified anchor of the design, while crypto.news reports the Safe 7 combines TROPIC01, an OPTIGA Trust M chip and the STM32U5 to protect PIN checks, device authenticity and wallet creation collectively, without specifying which layer handles which function on its own. Trezor’s argument, as CoinDesk and crypto.news both report, is that compromising TROPIC01 alone does not hand an attacker the PIN, the wallet, or the funds, because the other two layers still have to be defeated separately.

Trezor CEO Matej Žák framed the disclosure itself as proof the model works. In comments carried by CoinDesk, he said: “I believe the open process by which this vulnerability was found, examined, and disclosed is the model the industry should hold itself to.” In a separately worded statement carried by crypto.news, Žák said: “Because the Trezor Safe 7 was built with multiple independent security layers, a vulnerability in TROPIC01 does not put user funds at risk.” Both quotes make the same underlying case — that an auditable chip is supposed to get attacked by researchers and fixed in public, rather than sit undiscovered in a closed design — but both come from the company whose product is being defended.

What it would actually take to exploit this

CoinDesk reports that the attack requires physical possession of the device, specialized laboratory equipment and advanced technical expertise — not something achievable remotely or at scale. CryptoSlate’s account states the attack requires physical possession of the device plus specialized laboratory equipment, and adds that it defeated only one of the three security layers and has never been seen in the wild; CryptoSlate does not separately describe an expertise requirement, so that detail should be read as CoinDesk’s alone. Both accounts agree that no user funds were at risk under lab conditions and that there is no evidence of real-world exploitation, which is consistent with CoinDesk’s reporting that Trezor found no compromised devices. None of the sources in this evidence set, however, are an independent security lab confirming that conclusion; the claim traces back to Trezor and Tropic Square’s own disclosure in every outlet that reported it.

The mitigation claim that only one outlet makes

The Block’s coverage, of which only a summary is available in this evidence set, states that an immediate firmware-based mitigation exists by disabling the chip’s MAINTENANCE mode. That specific claim does not appear in the full-text accounts from CoinDesk, CryptoSlate or crypto.news. Because only a partial summary of The Block’s article is available here, this page cannot confirm whether that mitigation claim is accurate, what it covers, or whether Trezor has actually shipped it.

The Safe 7 itself, and how it handles recovery

For context on what is being discussed: the Safe 7 is Trezor’s current flagship hardware wallet, sold by SatoshiLabs, the Prague-based company behind Trezor, according to CryptoSlate’s review. CryptoSlate reports it has shipped since November 23, 2025, sells for $249, and was the first Trezor device to add Bluetooth connectivity and Qi2 wireless charging alongside the TROPIC01 chip. That review is a commercial page carrying “Buy” and “Visit Website” links, a promotional format worth keeping in mind when weighing its favorable framing of the disclosure as evidence that Trezor’s open-audit approach worked as intended.

The chip flaw described above concerns onboard security, not the recovery phrase a user writes down and stores separately. On that point, CryptoSlate’s review reports that new Safe 7 wallets default to a 20-word single-share backup, with 12- and 24-word options available, and that Trezor’s SLIP39 multi-share format lets a user split a backup across several physical shares rather than rely on one piece of paper; standard BIP39 seeds remain supported for compatibility. This evidence set contains no equivalent detail on how Ledger devices handle recovery. That absence is the reason this page does not attempt a Ledger-versus-Trezor comparison on recovery, even though that comparison was the original brief: the evidence supports a description of the Safe 7’s own backup options, and nothing has been gathered on Ledger’s side to compare it against.

What this page does not tell you

This page cannot confirm The Block’s claim that disabling MAINTENANCE mode mitigates the flaw, because only a summary of that article was available, not the full text. Every safety assurance in this disclosure — that funds remain safe, that the flaw has not been exploited in the real world — originates from Trezor and Tropic Square themselves; no independent auditor’s confirmation appears anywhere in the evidence gathered for this page. The precise technical content of the second vulnerability Tropic Square identified is described only in general terms by crypto.news, and no other outlet corroborates that specific detail. CryptoSlate’s account of the Safe 7’s design, specifications and recovery options comes from a review page that also promotes the device for sale — nothing in the evidence confirms whether that review is paid or sponsored, only that it carries purchase links — which does not make its facts wrong but is a relevant disclosure. Finally, this evidence describes only the Safe 7’s own backup options, not Ledger’s; it does not support any comparison between how the two companies handle recovery, and none is attempted here beyond what CryptoSlate reports about Trezor alone.

Sources

Every fact above is attributed to one of these reports. Where they disagree, the article says so.