Glass Ledger

Ledger Found a Flaw in a Rival Wallet's Chip. Now What?

Ledger's security team found a lab-only flaw in the chip inside Trezor's Safe 7 wallet. Here is what it actually means for anyone holding Bitcoin.

Trezor Safe 7 TROPIC01 chip flaw, lab-only attack path versus everyday use, zero real-world attacks

Wait, Ledger Found a Flaw in a Competitor's Wallet? Why Would They Do That?

In January 2026, Ledger's in-house security research team, known as Donjon, told Tropic Square, the company behind the secure chip used in Trezor's Safe 7 hardware wallet, that it had found a real Trezor Safe 7 chip vulnerability: a laser fault injection attack that succeeded against that chip under laboratory conditions. Tropic Square's own engineers, after being told, found a second exploitation path affecting a PIN-related function. The two companies coordinated a public disclosure on June 3, 2026. It reads strangely at first, one hardware wallet company finding a flaw in a direct competitor's product and telling them about it rather than staying quiet, but responsible disclosure between security researchers, even ones who compete commercially, is a long-standing norm in the industry precisely because the alternative, a flaw sitting undisclosed until an attacker finds it independently, is worse for everyone holding a device from either company.

Does This Trezor Safe 7 Chip Vulnerability Put My Coins at Risk Right Now?

For the overwhelming majority of Safe 7 owners, no, not today. Trezor and Tropic Square were direct about the limits of what was found: compromising the TROPIC01 chip alone is not enough to reach a wallet's PIN or funds, because the chip is one layer inside a larger security design, not the entire lock. There is no evidence of the technique being used against a real device outside a lab. That is meaningfully different from a flaw that is already being exploited in the wild.

What's the Actual Difference Between a Lab Attack and a Real One?

This is the question worth sitting with, because "vulnerability disclosed" headlines rarely explain it. Ledger Donjon's laser fault injection attack required physical possession of the specific device, specialized laboratory equipment capable of precisely timed laser pulses, and the kind of hardware security research expertise that takes years to build. An attacker who is not standing in a lab with your Safe 7 in hand, with that equipment, cannot use this particular technique against you remotely, over the internet, or through a phishing link. That is a genuinely different threat model than, for instance, a firmware bug that lets an attacker who never touches your device reconstruct your private key purely from something the device itself broadcasts or generates incorrectly. Both are real hardware wallet vulnerabilities. They are not the same kind of danger to an ordinary owner.

Should This Change Which Hardware Wallet I Trust?

Probably not in the direction of picking a winner, and that is worth saying plainly. The more interesting takeaway is not "Ledger beats Trezor" or the reverse; it is that a flaw requiring physical possession, lab equipment, and specialist skill still got found, disclosed, and patched before any reported real-world use, through the kind of adversarial testing that only happens when researchers actually go looking. A hardware wallet company that has never had a research team publicly probe its chips is not necessarily safer. It may simply mean nobody with that level of resources has tried yet. Trezor's own published response walked through the mitigation and made clear ordinary users did not need to take emergency action, which is the kind of disclosure that should build more confidence in a process, not less.

What Should I Actually Check on My Own Device?

If you own a Safe 7 or any other hardware wallet, the useful response to a disclosure like this one is not panic, it is a short list of habits. Confirm the device is running its current firmware, since patches for issues like this ship through normal firmware updates rather than requiring a new device. Keep physical possession of the wallet itself under the same care you already give a seed phrase, since this specific attack class depends entirely on someone else getting their hands on the hardware. And treat any unsolicited message asking you to "verify" your wallet by entering a seed phrase online as unrelated to this disclosure entirely, since no legitimate patch for a chip-level flaw ever requires typing a recovery phrase into a website. Those three habits cover the realistic response to this specific vulnerability, and they are also just good practice regardless of which wallet a person owns.

Does Any of This Apply to How a Mining Payout Gets Stored?

Directly, yes. Whatever address a solo miner points a pool at is only as safe as the wallet controlling it, hardware or software. A non-custodial mining pool solves one specific problem: it pays the full block reward straight to that address in the coinbase transaction, with nothing held on the pool's own books in between. It does not, and cannot, solve a separate problem, the security of the wallet holding that address's private key. Both matter, and they are not substitutes for each other. NexusPool's own non-custodial design and its signed Glass Ledger receipts, described on the pool's technology overview, address the payout side specifically; checking that a pool's infrastructure is actually behaving as described, rather than assuming it, is something its status page is there for. Before a block is even found, the Payout Preflight tool reconstructs and checks the coinbase transaction that would pay that address, which is a different kind of verification than anything a hardware wallet chip can offer, and neither replaces the other.

None of this is a claim that any hardware wallet, chip, or mining pool makes anyone's coins completely safe, and nothing here is investment advice. A solo miner's odds of finding a block are set by hashrate divided by network difficulty alone, identical for every miner on a chain regardless of which wallet controls the payout address, and no chip disclosure changes that arithmetic either way.

The single biggest question this raises, in one line: if you own a Trezor Safe 7, you do not need to do anything urgent today, but you should still confirm your device's firmware is current and treat the physical device itself, not just your seed phrase, as something worth protecting from anyone who could get their hands on it in a lab-grade way.

Trust nothing. Verify what a disclosed vulnerability actually requires before deciding whether it applies to you.

External source: CoinDesk's reporting on the TROPIC01 chip disclosure and Trezor's response.