14 Mar 2025

light mode

Ledger Gives Trezor a Security Boost

Ledger Gives Trezor a Security Boost

Ledger’s security team stepped in to help competitor Trezor fix a major vulnerability in the Safe 3 and Safe 5 models—raising questions about industry-wide security standards.

On this page

Trezor, known for its emphasis on security, introduced several improvements in its latest models, drawing scrutiny from cybersecurity analysts.

One major advancement was the inclusion of a Secure Element, a technology designed by Ledger to protect PINs and cryptographic keys. However, despite this integration, the devices remained susceptible to attacks, as certain cryptographic functions continued to rely on an unprotected microcontroller. 

Technical Analysis: The Strengths and Weaknesses

The Trezor Safe 3 and Safe 5 introduce a two-chip architecture, with a certified Optiga Trust M Secure Element working alongside a traditional microcontroller. Compared to earlier models—where security was primarily handled by a single chip—this is a clear improvement.

However, the microcontroller remains a vulnerable component. Unlike the Secure Element, it wasn’t built to withstand sophisticated hardware attacks, leaving room for potential exploitation.

Attackers with even temporary access to a Trezor device could reconfigure its firmware through the microcontroller, potentially altering its behavior. While Trezor’s integrity checks are designed to detect unauthorized changes, they failed to block certain types of modifications.

This loophole doesn’t directly expose private keys, but it does open up multiple attack pathways, making the device susceptible to more sophisticated threats.

Related: Trezor Safe 5 Review

According to security analysts who tested the flaw, Trezor’s developers reacted swiftly, releasing a fix for affected wallets well before the issue was publicly disclosed. Their quick response helped safeguard user funds.

This case underscores the importance of cooperation between leading security teams in protecting the broader crypto ecosystem.

At Ledger Donjon, our mission is to push the boundaries of security for the benefit of the whole crypto ecosystem. We will continue to research and collaborate to protect users under all relevant threat models. The collaboration with Trezor exemplifies this commitment.

— Charles Guillemet, CTO of Ledger.

Cybersecurity Lessons

Cyber threats remain an ever-present risk, even for security-focused companies like Ledger. In December 2023, hackers exploited a vulnerability in one of its software components, resulting in nearly $500,000 in stolen digital assets.

Additionally, the company experienced a customer data breach, with sensitive user information being exposed online. These incidents underscore the need for continuous innovation and industry-wide collaboration to protect users from evolving cyber threats.

Check this out: Introducing Ledger Flex: A “Cold Storage” Star Among Wallets

When it comes to securing digital assets, collaboration—not competition—is the key to staying ahead of threats. That’s why the partnership between Trezor and Ledger sends a powerful message to the crypto community.

By working together to identify and resolve vulnerabilities, these industry leaders not only respond faster to risks but also improve security for all wallet users. As Ledger’s CTO put it:

We appreciate Trezor’s responsiveness to this responsible security disclosure, and that Trezor addressed the vulnerabilities we found, showcasing the importance of continuous improvement and cooperation in the crypto space. We believe that making the ecosystem more secure helps everyone, and is critical as we push towards broader adoption of crypto and digital assets.

Developers are continuously strengthening firmware and hardware security, addressing known vulnerabilities and enhancing resilience. However, security professionals remind us that no wallet is entirely immune to threats.

To mitigate risks, users should follow best practices: purchase only from authorized sellers, install firmware updates promptly, and ensure their device remains physically secure.

Read on: Trezor Wallet: How Secure Is Your Crypto?

The content on The Coinomist is for informational purposes only and should not be interpreted as financial advice. While we strive to provide accurate and up-to-date information, we do not guarantee the accuracy, completeness, or reliability of any content. Neither we accept liability for any errors or omissions in the information provided or for any financial losses incurred as a result of relying on this information. Actions based on this content are at your own risk. Always do your own research and consult a professional. See our Terms, Privacy Policy, and Disclaimers for more details.

Articles by this author
Europeans Are Reluctant to Adopt the Digital Euro

Europeans Are Reluctant to Adopt the Digital Euro

The latest report from the ECB suggests that widespread adoption of the digital euro is far from reality, as most Europeans still prefer conventional payment methods.

Anton Kryshtal
Binance Scores Record-Breaking $2B Investment from Abu Dhabi’s MGX

Binance Scores Record-Breaking $2B Investment from Abu Dhabi’s MGX

The recent $2 billion Binance investment from Abu Dhabi’s MGX marks the single largest investment into a crypto company.

Anahit Avetisyan
Nebraska Enacts New Crypto ATM Regulations: What Will Change?

Nebraska Enacts New Crypto ATM Regulations: What Will Change?

Nebraska has tightened regulations on cryptocurrency ATMs. The new law mandates licensing, sets transaction limits, and requires operators to inform users about potential fraud risks.

Vlad Vovk
Ripple Enters the UAE Crypto Payments Market

Ripple Enters the UAE Crypto Payments Market

Ripple has obtained full regulatory approval from Dubai’s DFSA, making it the first licensed blockchain-based payment provider in the region.

Vlad Vovk
Pump.fun’s Meme Coin Frenzy: How It Became a $500M Crypto Powerhouse

Pump.fun’s Meme Coin Frenzy: How It Became a $500M Crypto Powerhouse

In the chaotic world of cryptocurrencies, no platform captures the spirit of financial anarchy better than Pump.fun. What began as an experiment on Solana in early 2024 soon turned into a meme coin explosion.

Ivan Dikalenko
Crypto Voices on Twitter/X: Jack Dorsey Suspended, Hayden Adams Talks DeFi

Crypto Voices on Twitter/X: Jack Dorsey Suspended, Hayden Adams Talks DeFi

A common topic on crypto Twitter (X) today is: ‘Why was Jack Dorsey suspended on the platform he created?’ This leads to another question about the decentralization and control of social media.

Anahit Avetisyan
Crypto Voices on Twitter/X: Michael Saylor’s Speech, BMT Token, and Stables

Crypto Voices on Twitter/X: Michael Saylor’s Speech, BMT Token, and Stables

Crypto moving forward despite market ups and downs. Michael Saylor’s speech on Bitcoin, the launch of Bubblemap’s BMT token, and the growth of stablecoins have been drawing a lot of attention.

Anahit Avetisyan
What Is a Bullish Market? How to Spot One Before It Happens

What Is a Bullish Market? How to Spot One Before It Happens

Learn what a bullish market is, its key characteristics, and how to identify early signs before a full bull market develops. Gain insights into market trends and strategies.

The Coinomist
What Is an MPC? How It Works and Why It Matters

What Is an MPC? How It Works and Why It Matters

Learn about Multi-Party Computation (MPC) in crypto, its mechanics, and benefits. Discover how MPC enhances security, privacy, and decentralized collaboration in digital transactions.

The Coinomist
How to Make Money in Crypto: Top Strategies for Beginners

How to Make Money in Crypto: Top Strategies for Beginners

Discover top strategies to profit in the crypto market—from HODLing and trading to staking, yield farming, NFTs, and crypto lending. Learn the risks and rewards for beginners.

The Coinomist
What Does ATH Mean for Your Crypto Portfolio?

What Does ATH Mean for Your Crypto Portfolio?

Learn what ATH (All-Time High) means for your crypto portfolio, its impact on investor sentiment, and how to strategize around market peaks to manage risk effectively.

The Coinomist
Crypto Heist 101: How Hackers Steal Millions in Crypto

Crypto Heist 101: How Hackers Steal Millions in Crypto

The crypto industry faces massive losses every year from cyberattacks, hacks, and social engineering scams. In 2024 alone, crypto heists resulted in over $2 billion worth of stolen digital assets.

Vlad Vovk
Network Congestion: Key Factors Affecting Your Connection

Network Congestion: Key Factors Affecting Your Connection

Explore the factors that lead to network congestion and learn how high traffic, outdated infrastructure, and interference impact your connection. Find solutions to improve performance.

The Coinomist
Trump’s “US Crypto Reserve” Plan: A Game Changer or Just Talk?

Trump’s “US Crypto Reserve” Plan: A Game Changer or Just Talk?

It takes just one post from Trump to stir the crypto market. Recently, he announced on Truth Social that the evaluation of a strategic crypto reserve is in progress as part of his broader Trump crypto policy.

Anahit Avetisyan
Trump’s Crypto Tax Plan: Smart Policy or Risky Gamble?

Trump’s Crypto Tax Plan: Smart Policy or Risky Gamble?

There’s been a lot of talk about possible changes to crypto tax policies in the U.S. One of the more controversial ideas floating around is “Trump no tax on crypto.” As Trump adopts a more crypto-friendly stance, major rumors have surfaced that he’s considering a 0% tax on crypto gains.

Anahit Avetisyan
MORE
From Lambo Dreams to Tax Nightmares: The Hidden Cost of Crypto Wealth

From Lambo Dreams to Tax Nightmares: The Hidden Cost of Crypto Wealth

Chasing crypto wealth? Don’t let tax obligations drain your profits. We reveal the best ways to lower your tax expenses and keep more of your earnings.

The Coinomist
A Day in the Life of a Web3 Startup Founder: Chaos and Opportunity

A Day in the Life of a Web3 Startup Founder: Chaos and Opportunity

What does a typical day look like for a Web3 founder? Pitching investors, managing internal crises, and trying to stay sane—this and much more in our deep dive.

The Coinomist
MORE