Ledger finds security flaws in Trezor Safe 3 and Safe 5 models

Source Cryptopolitan

Trezor’s latest hardware wallets, the Safe 3 and Safe 5, have some serious security issues, according to a report from Ledger that was released on March 12.

The report said that its security research team, Ledger Donjon, found that these devices had a ton of vulnerabilities in their microcontrollers that could allow hackers to gain remote access to user funds.

The flaws come despite Trezor’s upgrade to a two-chip design that includes an EAL6+ certified Secure Element. While the Secure Element protects PINs and private keys, Ledger’s report reveals that all cryptographic operations are still performed on the microcontroller, which is vulnerable to voltage glitching attacks.

If exploited, an attacker could extract cryptographic secrets, modify firmware, and bypass security checks, leaving user funds at risk.

Trezor’s new security design fails to protect critical operations

Trezor launched the Safe 3 in late 2023, followed by the Safe 5 in mid-2024, and both wallets introduced an upgraded two-chip design, in efforts to move away from the single-chip architecture used in older Trezor models.

The upgrade also added an Optiga Trust M Secure Element from Infineon, which will be a dedicated security chip to store PINs and cryptographic secrets.

According to Ledger’s findings, this Secure Element prevents access to sensitive data unless the correct PIN is entered. It also blocks hardware attacks like voltage glitching, which were previously used to extract seed phrases from models like Trezor One and Trezor T.

PCBs of two Trezor Safe 3, one running genuine software and the other running modified firmware | Source: Ledger

But despite these improvements, Ledger Donjon’s research shows that the main cryptographic functions—including transaction signing—still happen on the microcontroller, which remains a major security weakness.

The microcontroller used in the Safe 3 and Safe 5 is labeled TRZ32F429, which is actually a custom-packaged STM32F429 chip.

This chip has known vulnerabilities, specifically voltage glitching exploits that allow attackers to gain full read/write access to the flash memory.

Once an attacker modifies the firmware, they could manipulate entropy generation, which plays a key role in cryptographic security. This could lead to remote theft of private keys, giving hackers complete access to user funds.

Authentication system fails to verify microcontroller integrity

Trezor uses cryptographic authentication to verify its devices, but Ledger Donjon found that this system does not check the microcontroller’s firmware.

The Optiga Trust M Secure Element generates a public-private key pair during production, and Trezor signs the public key, embedding it into a certificate. When a user connects their wallet, Trezor Suite sends a random challenge that the device must sign using its private key. If the signature is valid, the device is considered authentic.

How the Optiga Trust M Secure Element works | Source: Ledger

But Ledger’s research shows that this process only verifies the Secure Element, not the microcontroller or its firmware.

Trezor attempted to link the Secure Element and microcontroller using a pre-shared secret, which is programmed into both chips during manufacturing. The Secure Element will only respond to signature requests if the microcontroller proves knowledge of this secret.

The problem? This pre-shared secret is stored in the microcontroller’s flash memory, which is vulnerable to voltage glitching attacks.

Ledger’s team was able to extract the secret, reprogram the chip, and bypass the authentication process entirely. This means an attacker could modify the firmware while still passing Trezor’s security checks.

Ledger’s report describes how they built a custom attack board, which allowed them to break out the TRZ32F429’s pads onto standard headers.

This setup lets them mount the microcontroller onto their attack system, extract the pre-shared secret, and reprogram the device without detection.

Once reprogrammed, the device would still appear legitimate when connected to Trezor Suite since the cryptographic attestation system remains unchanged.

This creates a dangerous situation, where compromised Trezor Safe 3 and Safe 5 wallets could be sold as genuine devices, while secretly running malicious firmware that steals user funds.

Firmware validation is bypassed, leaving users exposed

Trezor does include a firmware integrity check in Trezor Suite, but Ledger Donjon found a way to completely bypass this protection.

The firmware check works by sending a random challenge to the device, which then computes a cryptographic hash using both the challenge and its firmware. Trezor Suite verifies this hash against a database of genuine firmware versions.

At first glance, this method seems kind of effective—an attacker can’t just hardcode a fake hash because they wouldn’t know the random challenge in advance, so the device must compute the hash in real time, proving it’s running genuine firmware.

However, Ledger Donjon discovered a way to fully bypass this protection. Since the microcontroller handles this computation, an attacker can modify its firmware to fake a valid response.

Source: Ledger

By manipulating how the device calculates the hash, the attacker can make any firmware version appear authentic. This is a serious issue because it allows attackers to run modified software while still passing Trezor Suite’s verification checks.

As a result, a compromised Trezor Safe 3 or Safe 5 could still appear legitimate while secretly leaking private keys or altering transaction data.

Ledger’s report concludes that the only way to fully secure the Safe 3 and Safe 5 would be to replace the microcontroller with a more secure alternative. The Trezor Safe 5 does include a more modern microcontroller, the STM32U5, which has no publicly known fault injection attacks—at least for now.

But since it’s still a standard microcontroller, not a dedicated Secure Element, the risk remains that new attack methods could be discovered.

Trezor has already patched the vulnerabilities, but the underlying security concerns remain. Until the microcontroller itself is fully secured, users will have to trust Trezor’s software protections, which Ledger Donjon’s research has already proven can be bypassed.

Cryptopolitan Academy: Coming Soon - A New Way to Earn Passive Income with DeFi in 2025. Learn More

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Why a Quiet 2025 Signals a Massive 2026 Crypto Bull Run: Bitwise CIO ExplainsBitwise's Matt Hougan Predicts a Crypto Boom in 2026 Amid Current Market Struggles
Author  Mitrade
Nov 13, Thu
Bitwise's Matt Hougan Predicts a Crypto Boom in 2026 Amid Current Market Struggles
placeholder
Gold Price Forecast: XAU/USD recovers above $4,100, hawkish Fed might cap gainsGold price (XAU/USD) recovers some lost ground to near $4,105, snapping the two-day losing streak during the early European session on Friday. The precious metal edges higher on the softer US Dollar (USD).  Traders will take more cues from the Fedspeak later on Monday.
Author  FXStreet
Yesterday 01: 52
Gold price (XAU/USD) recovers some lost ground to near $4,105, snapping the two-day losing streak during the early European session on Friday. The precious metal edges higher on the softer US Dollar (USD).  Traders will take more cues from the Fedspeak later on Monday.
placeholder
Bitcoin slides deeper into red as bears lean on $96,600 wall and eye $90,000Bitcoin extends its decline after failing to reclaim $96,500, trading below $95,000, the 100-hour SMA and a bearish trend line near $96,600; unless bulls can force a decisive close back above $96,600–$97,200, the short-term path of least resistance stays lower, with $92,500, $90,000 and the main $88,500 support zone in focus.
Author  Mitrade
Yesterday 03: 35
Bitcoin extends its decline after failing to reclaim $96,500, trading below $95,000, the 100-hour SMA and a bearish trend line near $96,600; unless bulls can force a decisive close back above $96,600–$97,200, the short-term path of least resistance stays lower, with $92,500, $90,000 and the main $88,500 support zone in focus.
placeholder
Bitcoin briefly loses 2025 gains as crypto plunges over the weekend.Bitcoin experienced a sharp decline this weekend, briefly erasing its 2025 gains and dipping below its year-opening value of $93,507. The cryptocurrency fell to a low of $93,029 on Sunday, representing a 25% drop from its all-time high in October. Although it has rebounded slightly to around $94,209, the pressures on the market remain significant. The downturn occurred despite the reopening of the U.S. government on Thursday, which many had hoped would provide essential support for crypto markets. This year initially appeared promising for cryptocurrencies, particularly after the inauguration of President Donald Trump, who has established the most pro-crypto administration thus far. However, ongoing political tensions—including Trump's tariff strategies and the recent government shutdown, lasting a historic 43 days—have contributed to several rapid price pullbacks for Bitcoin throughout the year. Market dynamics are also being influenced by Bitcoin whales—investors holding large amounts of Bitcoin—who have been offloading portions of their assets, consequently stalling price rallies even as positive regulatory developments emerge. Despite these sell-offs, analysts from Glassnode argue that this behavior aligns with typical patterns seen among long-term investors during the concluding stages of bull markets, suggesting it is not indicative of a mass exodus. Notably, Bitcoin is not alone in its struggles, as Ethereum and Solana have also recorded declines of 7.95% and 28.3%, respectively, since the start of the year, while numerous altcoins have faced even steeper losses. Looking ahead, questions linger regarding the viability of the four-year cycle thesis, particularly given the increasing institutional support and regulatory frameworks now in place in the crypto landscape. Matt Hougan, chief investment officer at Bitwise, remains optimistic, suggesting a potential Bitcoin resurgence in 2026 driven by the “debasement trade” thesis and a broader trend toward increased adoption of stablecoins, tokenization, and decentralized finance. Hougan emphasized the soundness of the underlying fundamentals, pointing to a positive outlook for the sector in the longer term.
Author  Mitrade
Yesterday 03: 11
Bitcoin experienced a sharp decline this weekend, briefly erasing its 2025 gains and dipping below its year-opening value of $93,507. The cryptocurrency fell to a low of $93,029 on Sunday, representing a 25% drop from its all-time high in October. Although it has rebounded slightly to around $94,209, the pressures on the market remain significant. The downturn occurred despite the reopening of the U.S. government on Thursday, which many had hoped would provide essential support for crypto markets. This year initially appeared promising for cryptocurrencies, particularly after the inauguration of President Donald Trump, who has established the most pro-crypto administration thus far. However, ongoing political tensions—including Trump's tariff strategies and the recent government shutdown, lasting a historic 43 days—have contributed to several rapid price pullbacks for Bitcoin throughout the year. Market dynamics are also being influenced by Bitcoin whales—investors holding large amounts of Bitcoin—who have been offloading portions of their assets, consequently stalling price rallies even as positive regulatory developments emerge. Despite these sell-offs, analysts from Glassnode argue that this behavior aligns with typical patterns seen among long-term investors during the concluding stages of bull markets, suggesting it is not indicative of a mass exodus. Notably, Bitcoin is not alone in its struggles, as Ethereum and Solana have also recorded declines of 7.95% and 28.3%, respectively, since the start of the year, while numerous altcoins have faced even steeper losses. Looking ahead, questions linger regarding the viability of the four-year cycle thesis, particularly given the increasing institutional support and regulatory frameworks now in place in the crypto landscape. Matt Hougan, chief investment officer at Bitwise, remains optimistic, suggesting a potential Bitcoin resurgence in 2026 driven by the “debasement trade” thesis and a broader trend toward increased adoption of stablecoins, tokenization, and decentralized finance. Hougan emphasized the soundness of the underlying fundamentals, pointing to a positive outlook for the sector in the longer term.
placeholder
Gold Price Forecast: XAU/USD declines below $4,050 on USD strength and hawkish Fed comments Gold price (XAU/USD) extends the decline to around $4,030 during the early Asian session on Tuesday. The precious metal edges lower as traders dialed back expectations of a US interest rate cut next month.
Author  FXStreet
7 hours ago
Gold price (XAU/USD) extends the decline to around $4,030 during the early Asian session on Tuesday. The precious metal edges lower as traders dialed back expectations of a US interest rate cut next month.
goTop
quote