The flagship hardware wallet Trezor Safe 7 is affected by a hardware-level vulnerability in its internal TROPIC01 security chip. The flaw was discovered by Ledger's Donjon research team in a laboratory setting, where researchers used a precise laser attack to bypass the firmware verification system of the TROPIC01 chip. This discovery highlights the challenges of securing embedded hardware against advanced physical attacks.
Attack Paths and Scope
After Ledger's initial demonstration, chip manufacturer Tropic Square conducted further analysis and uncovered a second attack path targeting the chip's "MAC-and-Destroy" security mechanism. This mechanism is designed to trigger data destruction upon detecting unauthorized access. Tropic Square confirmed that the hardware vulnerability affects all TROPIC01 chips currently in production, covering every unit shipped to date. As a result, all Trezor Safe 7 devices in circulation incorporate the affected chip. In a responsible disclosure move, Tropic Square has delayed the release of full technical details until late 2026, when a hardened silicon revision of TROPIC01 is expected to be introduced. A comprehensive public disclosure, including vulnerability principles and attack chain, is planned for spring 2027.
User Fund Safety and Mitigations
Trezor emphasized in a statement that the TROPIC01 chip is just one of three independent security layers within the Trezor Safe 7. User cryptocurrency assets, wallet backups, and private keys are never stored on this chip. During Ledger's extraction attempt targeting the chip's hardware encryption storage, the protection mechanism successfully withstood all attacks in initial tests, with no sensitive information accessed. Trezor CEO Matej Zak reiterated that the user's PIN, wallet backup, and private keys corresponding to funds have never been placed on any single chip, an architectural design that avoids single points of failure.
To address the immediate threat, Trezor has released a firmware-level mitigation that disables the MAINTENANCE mode of the TROPIC01 chip. Users can apply this update to block the known attack paths. Neither Trezor nor Tropic Square has received any reports of actual user fund losses stemming from this vulnerability. The incident underscores the importance of adversarial resilience in hardware wallet design and the value of responsible security research in the cryptocurrency space.

