According to The Block, Ledger's Donjon security team discovered a firmware verification bypass vulnerability in the TROPIC01 chip used by Trezor Safe 7 through laser-based attacks in laboratory conditions. The attack, which requires physical device possession, could enable loading of unauthorized firmware. Chip manufacturer Tropic Square identified an additional attack path targeting the chip's MAC-and-Destroy PIN verification mechanism, with enhanced chip versions scheduled for release by end of 2026.
Trezor stated that PIN, recovery seeds, and private keys are not stored on a single chip, and users require no action. The company recommends disabling the chip's MAINTENANCE mode to reduce attack feasibility and has notified partners about the vulnerability.