25 Mar 2025

light mode

Ledger Gives Trezor a Security Boost

Ledger Gives Trezor a Security Boost

Ledger’s security team stepped in to help competitor Trezor fix a major vulnerability in the Safe 3 and Safe 5 models—raising questions about industry-wide security standards.

On this page

Trezor, known for its emphasis on security, introduced several improvements in its latest models, drawing scrutiny from cybersecurity analysts.

One major advancement was the inclusion of a Secure Element, a technology designed by Ledger to protect PINs and cryptographic keys. However, despite this integration, the devices remained susceptible to attacks, as certain cryptographic functions continued to rely on an unprotected microcontroller. 

Technical Analysis: The Strengths and Weaknesses

The Trezor Safe 3 and Safe 5 introduce a two-chip architecture, with a certified Optiga Trust M Secure Element working alongside a traditional microcontroller. Compared to earlier models—where security was primarily handled by a single chip—this is a clear improvement.

However, the microcontroller remains a vulnerable component. Unlike the Secure Element, it wasn’t built to withstand sophisticated hardware attacks, leaving room for potential exploitation.

Attackers with even temporary access to a Trezor device could reconfigure its firmware through the microcontroller, potentially altering its behavior. While Trezor’s integrity checks are designed to detect unauthorized changes, they failed to block certain types of modifications.

This loophole doesn’t directly expose private keys, but it does open up multiple attack pathways, making the device susceptible to more sophisticated threats.

Related: Trezor Safe 5 Review

According to security analysts who tested the flaw, Trezor’s developers reacted swiftly, releasing a fix for affected wallets well before the issue was publicly disclosed. Their quick response helped safeguard user funds.

This case underscores the importance of cooperation between leading security teams in protecting the broader crypto ecosystem.

At Ledger Donjon, our mission is to push the boundaries of security for the benefit of the whole crypto ecosystem. We will continue to research and collaborate to protect users under all relevant threat models. The collaboration with Trezor exemplifies this commitment.

— Charles Guillemet, CTO of Ledger.

Cybersecurity Lessons

Cyber threats remain an ever-present risk, even for security-focused companies like Ledger. In December 2023, hackers exploited a vulnerability in one of its software components, resulting in nearly $500,000 in stolen digital assets.

Additionally, the company experienced a customer data breach, with sensitive user information being exposed online. These incidents underscore the need for continuous innovation and industry-wide collaboration to protect users from evolving cyber threats.

Check this out: Introducing Ledger Flex: A “Cold Storage” Star Among Wallets

When it comes to securing digital assets, collaboration—not competition—is the key to staying ahead of threats. That’s why the partnership between Trezor and Ledger sends a powerful message to the crypto community.

By working together to identify and resolve vulnerabilities, these industry leaders not only respond faster to risks but also improve security for all wallet users. As Ledger’s CTO put it:

We appreciate Trezor’s responsiveness to this responsible security disclosure, and that Trezor addressed the vulnerabilities we found, showcasing the importance of continuous improvement and cooperation in the crypto space. We believe that making the ecosystem more secure helps everyone, and is critical as we push towards broader adoption of crypto and digital assets.

Developers are continuously strengthening firmware and hardware security, addressing known vulnerabilities and enhancing resilience. However, security professionals remind us that no wallet is entirely immune to threats.

To mitigate risks, users should follow best practices: purchase only from authorized sellers, install firmware updates promptly, and ensure their device remains physically secure.

Read on: Trezor Wallet: How Secure Is Your Crypto?

The content on The Coinomist is for informational purposes only and should not be interpreted as financial advice. While we strive to provide accurate and up-to-date information, we do not guarantee the accuracy, completeness, or reliability of any content. Neither we accept liability for any errors or omissions in the information provided or for any financial losses incurred as a result of relying on this information. Actions based on this content are at your own risk. Always do your own research and consult a professional. See our Terms, Privacy Policy, and Disclaimers for more details.

Articles by this author
Trump Pumps TRUMP Memecoin by 10% with Truth Social Post

Trump Pumps TRUMP Memecoin by 10% with Truth Social Post

Donald Trump stirred the crypto community with a post on Truth Social, once again expressing his enthusiasm for his TRUMP memecoin. As a result, both TRUMP trading volume and price skyrocketed.

Dmytro Psevdonimenko
Fidelity Integrates Ethereum Blockchain into Treasury Fund Management

Fidelity Integrates Ethereum Blockchain into Treasury Fund Management

Fidelity Investments has announced the launch of a new share class called OnChain, which will be tracked on the Ethereum blockchain.

Dmytro Psevdonimenko
Bitcoin Breaks Above $87,000: What’s Driving the Surge?

Bitcoin Breaks Above $87,000: What’s Driving the Surge?

Bitcoin has once again surged past $87,000, driven by renewed interest from major traders and growing optimism around a potential easing of trade tariffs.

Anton Kryshtal
Metaplanet Buys 150 Bitcoin, Bringing Total Holdings to 3,350

Metaplanet Buys 150 Bitcoin, Bringing Total Holdings to 3,350

Metaplanet, a Tokyo-based Bitcoin treasury firm, added 150 BTC at $84K per coin on March 24. Following the latest Metaplanet Bitcoin buy, its holdings total 3,350 BTC, worth over ÂĄ42B ($281M).

Anahit Avetisyan
Justin Sun’s Playbook: How He Built TRON and Disrupted Crypto

Justin Sun’s Playbook: How He Built TRON and Disrupted Crypto

Justin Sun remains one of the most polarizing figures in the crypto industry. Is he a visionary who transformed TRON into a blockchain powerhouse—or a master of manipulation and self-promotion?

Ivan Dikalenko
NFTs & Film Financing: Turning Creativity into Digital Gold

NFTs & Film Financing: Turning Creativity into Digital Gold

Filmmaker Markus MĂĽller-Hahnefeld shows how NFTs are revolutionizing film financing by turning creative ideas into unique digital assets that fund projects and build engaged communities.

Sebastian Scheplitz
Jesse Powell’s Wild Ride: The Untold Story of Kraken’s Rise

Jesse Powell’s Wild Ride: The Untold Story of Kraken’s Rise

The crypto world has always been a battlefield between innovation and regulation. But amid the chaos, one figure refused to play by the system’s rules—and instead declared war on it. Meet Kraken founder Jesse Powell.

Ivan Dikalenko
What is a Hash Function and Why It’s Essential?

What is a Hash Function and Why It’s Essential?

Learn what a hash function is, how it works, and why it’s vital for data integrity, security, and performance in modern computing and blockchain technology.

The Coinomist
How Many Confirmations for Bitcoin Transactions and Why It Matters

How Many Confirmations for Bitcoin Transactions and Why It Matters

Learn what Bitcoin confirmations are, how many are required for different transactions, and why they matter for security and fraud prevention in the blockchain.

The Coinomist
What is a Check Digit? A Full Explanation

What is a Check Digit? A Full Explanation

Discover what a check digit is, how it’s calculated, and why it matters for data verification. Learn how algorithms like Luhn ensure data integrity across various industries.

The Coinomist
When Was Ethereum Created and How It Transformed Blockchain?

When Was Ethereum Created and How It Transformed Blockchain?

Explore Ethereum’s origins and evolution. Learn how Vitalik Buterin’s vision reshaped blockchain technology, sparking innovations like smart contracts, DeFi, and NFTs.

The Coinomist
How Many Sats in a Bitcoin? Everything You Need to Know

How Many Sats in a Bitcoin? Everything You Need to Know

Learn how many satoshis (sats) make up one Bitcoin and why this divisibility matters. Understand the role of sats in facilitating microtransactions and enhancing Bitcoin’s usability.

The Coinomist
OnyxCoin (XCN): Why This Layer-3 Blockchain Is Gaining Investor Attention

OnyxCoin (XCN): Why This Layer-3 Blockchain Is Gaining Investor Attention

OnyxCoin isn’t just a crypto project—it’s an infrastructure built for the digital age, offering scalable, secure, and low-cost transactions for a globalized economy.

Vlad Vovk
Trump’s “US Crypto Reserve” Plan: A Game Changer or Just Talk?

Trump’s “US Crypto Reserve” Plan: A Game Changer or Just Talk?

It takes just one post from Trump to stir the crypto market. Recently, he announced on Truth Social that the evaluation of a strategic crypto reserve is in progress as part of his broader Trump crypto policy.

Anahit Avetisyan
Trump’s Crypto Tax Plan: Smart Policy or Risky Gamble?

Trump’s Crypto Tax Plan: Smart Policy or Risky Gamble?

There’s been a lot of talk about possible changes to crypto tax policies in the U.S. One of the more controversial ideas floating around is “Trump no tax on crypto.” As Trump adopts a more crypto-friendly stance, major rumors have surfaced that he’s considering a 0% tax on crypto gains.

Anahit Avetisyan
MORE
Living on Crypto in the U.S.: Is It Even Possible?

Living on Crypto in the U.S.: Is It Even Possible?

Crypto is often pitched as the key to financial freedom. But how feasible is living on crypto in the real-world American economy?

Iaroslava Kramarenko
Life Inside a Bitcoin Mining Farm: The Daily Grind of Miners

Life Inside a Bitcoin Mining Farm: The Daily Grind of Miners

Imagine waking up to the hum of thousands of mining rigs. Welcome to a Bitcoin mining farm, where time is money, and every second counts.

Iaroslava Kramarenko
MORE