Ledger Helps Trezor Fix Security Vulnerability
Ledger reported a vulnerability in the Safe 3 and 5 models to Trezor. Trezor has already released a patch to resolve the security issue.

Get the latest news, learn from experts, discover new tools, and find inspiration right in your inbox.
No spam. Unsubscribe anytime.
A powerful documentary on how Bitcoin and blockchain are reshaping money, power, and geopolitics—from El Salvador’s Bitcoin experiment and Europe’s regulatory revolution to the rise of decentralized finance and the new global financial order.
Hardware wallet vendor Ledger has demonstrated to Trezor that it can bypass security controls on the Trezor Safe 3 and 5 models, prompting Trezor to fix the vulnerability.
Hardware wallet vendor Trezor has fixed a security vulnerability in two of its latest models after Ledger's open-source research unit discovered a flaw in its microcontrollers.
Ledger Donjon acknowledged that Trezor has made several security improvements recently, but noted that cryptographic operations can still be performed on the microcontroller in the Trezor Safe 3 and 5 models, making them 'vulnerable to more sophisticated attacks'.
Unfortunately, Trezor has already patched the discovered vulnerabilities, Ledger CTO Charles Guillemet said in a 12 March post.
X
Trezor has already implemented 'Secure Elements' chips designed to protect user PIN and cryptographic secrets, as some Trezor devices could be hacked by modifying the software they run on, potentially allowing attackers to steal users' funds.
The Secure Elements feature "effectively prevents any low-cost hardware attacks, particularly power failures," Ledger said in a 12 March announcement.
Trezor Resolves Firmware Integrity & Check Vulnerability
Trezor implemented a firmware integrity check to detect tampered software, but Ledger was able to demonstrate that an attacker could still bypass this security check.
Since then, Trezor has fixed the problem, although neither Ledger nor Trezor has explained how.
Trezor confirmed on X that users' funds remain safe, and that no action is needed.
X
However, when asked if Trezor had been able to correct the problem with a firmware update, the hardware wallet vendor replied: "Unfortunately not.
In December 2023, a hacker compromised Ledger's connector library and stole cryptocurrencies worth $484,000.
Another attacker, who hacked Ledger's systems, published the email addresses of approximately 270,000 Ledger customers in June 2020.
Although Trezor has patched the latest security vulnerabilities identified by Ledger, concerns remain over potential attack vectors through the microcontroller.
Both companies emphasise the importance of continuous security improvements and multi-layered protection to protect users' funds. Despite past breaches that have affected the cryptocurrency hardware wallet industry, Trezor reassures users that their funds remain safe, with no immediate action required.
Read Next
YouTube integrates PayPal's PYUSD to pay US creators
YouTube introduces PayPal's PYUSD as an optional payment method for eligible creators in the US, opening up stablecoins in mainstream monetisation streams.
Bitcoin disengages from equities: historical correlation broken
Bitcoin breaks historic correlation with equities: markets rally as BTC falls for the first time since 2014.
Garantex: Russian Exchange Under Sanctions Moving Millions Under Track
The Russian exchange Garantex is back in operation despite sanctions and seizures, moving millions through mixing, cross-chain and state stablecoin.
Light Penalty for the 40 Billion Collapse: Why Do Kwon took Less than SBF
The US federal judiciary has issued conflicting sentences in the most egregious crypto cases. Prosecutorial conduct has weighed more heavily than economic loss in the disparity of punishment between Do Kwon and SBF.