We built TROPIC01 to find its limits.
Today we're publishing a Security Advisory on a hardware vulnerability discovered during an independent audit by the Ledger Donjon team - alongside the deeper findings our engineers made as a result.
What was found:
👉️ During their audit, Ledger Donjon successfully executed a Laser Fault Injection attack bypassing firmware boot signature under lab conditions - but essential hardware security withstood it.
👉️ Building on that discovery, our team found that more complex combined attack paths can potentially breach the hardware boundary and expose all confidential data.
Worth knowing:
👉️ This is not a remote exploit and there is no evidence of real-world exploitation.
👉️ Mitigation measures for this attack vector are available for deployment.
True hardware security is built on transparency and auditability. So we don't just tolerate scrutiny, we invite it. This disclosure is that principle in practice.
A huge thanks to
@DonjonLedger team for their exceptional technical expertise, professionalism and dedication to coordinated disclosure.
📄 Read our full announcement:
bit.ly/4vGfgEH
🔬 Link to technical deep-dive:
bit.ly/49Cj8Ol