📈 Get daily crypto insights that make you smarter about your money

Trezor Safe 3 and Safe 5 Hardware Wallet Vulnerability: Why Supply Chain Security Cannot Be an Afterthought

Hardware wallets have long been considered the gold standard of cryptocurrency self-custody, offering an air-gapped environment for private key management that software wallets simply cannot match. But a disclosure from Ledger’s open-source research division, Ledger Donjon, has shaken that assumption by revealing a significant vulnerability in Trezor’s Safe 3 and Safe 5 hardware wallet models. The discovery, patched by Trezor after responsible disclosure, raises urgent questions about supply chain integrity and the assumptions users make when trusting hardware devices with their digital assets.

The Threat Landscape

The cryptocurrency market in March 2025 reflected a period of heightened activity, with Bitcoin trading at approximately $82,862 and Ethereum around $1,920. As asset values climbed, so did the incentive for sophisticated attacks targeting custody solutions. The Trezor vulnerability emerged not from a software bug in the traditional sense, but from a hardware-level weakness in the microcontroller architecture that underpins the entire security model of these devices.

Ledger Donjon discovered that cryptographic operations could still be performed on the microcontroller of the Trezor Safe 3 model, potentially making it vulnerable to advanced physical attacks. The microcontroller used in Trezor Safe devices, labeled TRZ32F429, a customized STM32F429 chip, was found to be susceptible to voltage glitching attacks, a technique that involves applying precise voltage fluctuations to disrupt normal processor behavior and reveal protected memory contents.

Core Principles

Understanding this vulnerability requires grasping several fundamental security principles that govern hardware wallet design. The first is the separation between the Secure Element and the general-purpose microcontroller. A Secure Element is a dedicated chip designed specifically to resist physical and logical attacks, storing sensitive cryptographic material in a hardened environment. The microcontroller, by contrast, handles the broader operational logic of the device, including user interface interactions and communication with host computers.

The core issue is that Trezor’s design relies on a pre-shared secret between the Secure Element and the microcontroller for authenticity verification. Ledger Donjon demonstrated that an attacker with physical access could potentially extract this secret through voltage glitching, then reprogram the device to appear genuine while running malicious firmware. This breaks the trust chain that users depend on when they verify their device is authentic.

Another potential attack vector stemmed from the firmware integrity check that Trezor implemented to detect modified software. Ledger showed that this security check could be bypassed, undermining a critical safeguard that was supposed to prevent tampered devices from operating.

Tooling and Setup

The demonstrated attack involved desoldering the microcontroller from the Trezor device and applying precise voltage changes to reveal the flash memory contents. This is a highly technical procedure requiring specialized equipment, including a soldering station, voltage glitching hardware, and expertise in embedded systems security. It is not an attack that can be performed remotely or by a casual adversary.

However, the supply chain attack scenario is far more concerning. A sophisticated operation could intercept devices during manufacturing or distribution, implant malicious firmware, and deliver compromised wallets to unsuspecting users. Such an attack could lead to the remote theft of user funds without any visible indication of tampering. The barrier to entry for this type of attack is high but not impossibly so, particularly for well-funded state-sponsored groups known to target cryptocurrency infrastructure.

Trezor responded by patching the vulnerability after Ledger’s disclosure, though notably, when asked whether the fix was delivered through a firmware update, Trezor responded that it was not. This leaves some ambiguity about how exactly the issue was addressed and whether all devices in circulation have been protected.

Ongoing Vigilance

For users, the incident reinforces several essential security practices. First, always purchase hardware wallets directly from the manufacturer’s official website or authorized resellers. Never buy second-hand devices or accept hardware wallets from unverified sources. Second, verify the tamper-evident packaging upon receipt and immediately check the firmware version using the official Trezor Suite application. Third, enable the passphrase feature, which adds an additional layer of protection by requiring a secondary password that is never stored on the device itself.

The Trezor Safe 5 model uses an upgraded microcontroller that is reportedly resistant to voltage glitching, representing a hardware-level improvement over its predecessor. Users with Safe 3 devices should be particularly vigilant and consider upgrading if they are managing significant holdings.

Final Takeaway

The Ledger Donjon disclosure is not an indictment of Trezor’s commitment to security, but rather a reminder that hardware wallet security is a continuous arms race. Every design decision involves trade-offs between security, usability, and cost. The discovery and responsible disclosure of this vulnerability ultimately strengthens the ecosystem, but only if users act on the lessons it teaches. Supply chain security is not a feature that can be added after the fact. It must be embedded in every stage of the device lifecycle, from chip fabrication through final delivery to the end user.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before making financial decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “Trezor Safe 3 and Safe 5 Hardware Wallet Vulnerability: Why Supply Chain Security Cannot Be an Afterthought”

  1. the supply chain angle is the part nobody takes seriously enough. you can verify firmware all day but if the secure element was compromised between prague and your mailbox no software patch saves you

  2. ledger auditing trezor while dealing with their own recover feature backlash was convenient timing. doesnt make the finding wrong but the optics are terrible

  3. supply_chain_watcher

    microcontroller side channel attacks are scary because you cant patch hardware. firmware update helps but the physical attack surface stays

  4. voltage glitching on STM32 chips has been a known attack vector since 2018. took 7 years for hardware wallet makers to take it seriously

  5. ColdStorageKing

    Ledger Donjon finding a flaw in Trezor hardware is peak corporate espionage energy. respect the responsible disclosure though

  6. supply chain attacks are the one threat model nobody takes seriously until its too late. your seed phrase doesnt help if the chip was compromised before you unboxed it

    1. BTC at 82k when this dropped and nobody talks about the microcontroller issue. its always about price until your wallet is empty

    2. chip_whisperer

      this is why i buy hardware wallets direct from the manufacturer, never amazon. one intercepted package and your seed is already known to someone else

      1. chip_whisperer buying direct helps but the real threat is a man-in-the-middle between factory and your door. tamper evident bags can be resealed

  7. Ledger finding flaws in Trezor hardware is like Ford crash testing Honda vehicles and publishing the dents. useful but the motives arent pure

    1. Tomasz B. competitive research is still research. the voltage glitching attack on TRZ32F429 is real regardless of who found it

  8. Ledger auditing Trezor is like Coca-Cola auditing Pepsi. convenient that they found a flaw in the competitors hardware right when Ledger was getting hammered for their own recover feature backlash

  9. supply_chain_paranoia

    the real issue is you cant verify your device wasnt tampered between factory and your mailbox. patched firmware doesnt help if the hardware was modified before you even opened the box

    1. ledger donjon finding a flaw in trezor hardware right after the recover feature backlash was convenient timing. competitive audit or not the disclosure was legitimate, the microcontroller weakness was real

  10. BTC at 82K and ETH at 1920 when this dropped. the price gap itself shows why hardware wallet security matters more than ever. bigger prices = bigger targets

    1. Niko P. btc at 82k means a single compromised seed is life changing money. the trezor patch came fast but how many users actually updated their firmware. probably under 30 percent

  11. ledger auditing trezor hardware is like coke taste testing pepsi and publishing the results. convenient timing for the competition

    1. Nadia V. competitive audit isnt espionage, its how hardware security improves. the concern is whether Trezor would have disclosed it without Ledger forcing their hand

      1. Minna L. fair point on competitive audits but Ledger has their own DCLeaks history. both companies have incentives here, trust neither blindly

  12. the pre-shared secret extraction via voltage glitching on the TRZ32F429 chip is the real concern here. the attack itself requires desoldering and specialized equipment which limits it to nation-state level actors, but the supply chain scenario where devices get intercepted and reflashed before reaching users is what keeps me up at night. buy direct from trezor or do not buy at all

  13. tamper_evidence_

    trezor saying the fix was not a firmware update is the most alarming part of this entire disclosure. if the vulnerability is in the microcontroller hardware itself and you cannot patch it remotely, every Safe 3 device in the wild before the fix date should be treated as potentially compromised. the Safe 5 upgrade path is essentially mandatory for anyone holding serious amounts

    1. voltage_glitch_

      tamper_evidence_ the hardware patch means existing Safe 3 units are permanently vulnerable. you cant flash your way out of a microcontroller flaw. thats a recall not an update

  14. supply_chain_paranoia

    ledger donjon doing responsible disclosure on a competitor product is good for the ecosystem but the bypassed firmware integrity check means users had zero way to detect a tampered device before this research was published. enabling the passphrase feature on trezor is the minimum viable defense here since the passphrase is never stored on the device and would survive even a reflashed MCU

    1. glitch_budget_

      Ledger Donjon finding vulnerabilities in Trezor hardware is like Coke publishing a study on Pepsi health risks. convenient but the findings are legit

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$65,195.00+0.3%ETH$1,923.27+0.1%SOL$77.20+1.2%BNB$607.88+0.5%XRP$1.04-0.3%ADA$0.1977-1.2%DOGE$0.0706-0.6%DOT$0.8106-0.8%AVAX$6.54-0.1%LINK$8.34+0.1%UNI$4.04+1.3%ATOM$1.39-0.1%LTC$46.27+1.0%ARB$0.0785-1.5%NEAR$1.63+0.0%FIL$0.7109-1.0%SUI$0.7022+0.6%BTC$65,195.00+0.3%ETH$1,923.27+0.1%SOL$77.20+1.2%BNB$607.88+0.5%XRP$1.04-0.3%ADA$0.1977-1.2%DOGE$0.0706-0.6%DOT$0.8106-0.8%AVAX$6.54-0.1%LINK$8.34+0.1%UNI$4.04+1.3%ATOM$1.39-0.1%LTC$46.27+1.0%ARB$0.0785-1.5%NEAR$1.63+0.0%FIL$0.7109-1.0%SUI$0.7022+0.6%
Scroll to Top