A Sophisticated Cyber Attack Exploits Unpatchable Wallet Cards, Resetting User Passwords
In a concerning incident that highlights the vulnerabilities of even the most secure systems, hackers have successfully exploited unpatchable wallet cards issued by Tangem, a Swiss-based company known for its high-security digital wallets. The attackers used a technique called a “laser attack” to reset user passwords on these cards, effectively giving them full control over the victims’ funds.
The affected users are those who hold Tangem’s proprietary cards, which store their cryptocurrency and other sensitive data in a tamper-evident manner. These cards are marketed as being virtually unhackable due to their unique design and secure manufacturing process. However, it appears that this security comes with a significant caveat: the cards cannot be patched or updated once they leave the factory.
The laser attack itself involves using a high-powered laser beam to alter the card’s internal components, essentially rewriting the password stored on the device. This is made possible by the fact that the cards are designed to respond to specific wavelengths of light, allowing hackers to bypass traditional security measures and directly access the sensitive data. The attackers can then use this information to reset the user’s password, effectively taking control of their account.
The implications of this attack are far-reaching, with experts warning that similar vulnerabilities may exist in other secure devices and systems. As AI-powered hacking tools become increasingly sophisticated, the need for robust security measures has never been more pressing. Cybersecurity professionals are urging organizations to take a proactive approach to protecting themselves against such attacks, including implementing robust incident response plans and conducting regular vulnerability assessments.
While Tangem has issued a statement assuring users that they are working to address the issue, it remains unclear how widespread the attack may be or what measures will be taken to prevent similar incidents in the future. For now, affected users are advised to take immediate action to secure their accounts, including changing passwords and monitoring their activity closely.
As this incident demonstrates, even the most advanced security measures can have significant weaknesses when exploited by determined attackers. To mitigate such risks, individuals and organizations must prioritize robust security protocols, including regular software updates and thorough vulnerability assessments. By staying informed about emerging threats and taking proactive steps to protect themselves, we can reduce the likelihood of falling victim to these types of attacks.
Source: The Hacker News — 2026-07-10