Trezor Discloses TROPIC01 Chip Flaw in Safe 7 Wallet, Assuring User Funds Remain Secure

Trezor has disclosed a security vulnerability in the TROPIC01 secure element chip used in its Trezor Safe 7 hardware wallet, following independent testing by Ledger’s Donjon team and additional analysis by Tropic Square. The flaw involves lab-grade techniques that could extract certain chip secrets and bypass firmware signature checks, and Tropic Square later identified an additional exploitation path that might reveal another secret tied to PIN-related chip functions. Despite the chip-level weakness, Trezor says the Safe 7’s layered, multi-chip design prevents attackers from using a compromised TROPIC01 to access a user’s PIN, wallet, or funds, and it has not indicated any real-world exploitation. Because the vulnerability is hardware-based, Trezor and Tropic Square do not provide a conventional remote firmware fix and instead emphasize public, coordinated disclosure. The episode also illustrates the hardware-wallet industry’s growing practice of independent cross-company security research, with both rivals framing transparency as improving overall customer safety.
Trezor said the TROPIC01 secure element was designed to be “the first fully open and auditable” chip, with its “complete source code and documentation” publicly available on GitHub (including a RISC-V core and custom cryptographic coprocessor) to enable community verification rather than relying on NDAs for security research.
Ledger’s Donjon research reportedly involved a “laser fault injection attack under lab conditions,” which Trezor and Tropic Square said was able to extract “some chip secrets” and “bypass firmware signature checks.”
Trezor described the Safe 7 architecture as having “one of three independent security layers” affected by the TROPIC01 issue, with the overall design combining TROPIC01 with two other chips—“OPTIGA Trust M” and “STM32U5”—to protect PIN checks, device authenticity, and wallet creation.
Trezor told CoinDesk that exploiting the hardware flaw would require “physical possession of a device, expensive lab equipment and advanced technical expertise,” and that there was “no evidence the flaw has been exploited in the real world,” while still emphasizing coordinated disclosure as a safer industry model.
Publishers
13
Articles
7
Reach
20