From the archive. This story describes the announcement at its original publication date. Product availability, pricing and terms may have changed.
At a glance
- What changed
- Physical chip vulnerability disclosed.
- Who it affects
- Safe 7 context.
- When
- June 3 response.
Trezor partner offer and conditions ↓

Trezor responds to a vulnerability in one chip
Trezor acknowledged a physical attack affecting the TROPIC01 chip used in Safe 7. The company says compromising that component alone does not expose the wallet backup, PIN or funds because other device protections remain. It advises no user action. That is Trezor’s assessment of its complete product, distinct from the confirmed disclosure of a weakness in one component.
[1]What the chip manufacturer disclosed
Tropic Square’s advisory describes a laboratory laser-fault attack initially reported by Ledger Donjon, followed by further investigation of a hardware security boundary. It says exploitation requires physical possession and specialised preparation and equipment. The manufacturer assigns a CVSS 3.1 base score of 5.7 and reports no evidence of exploitation in the wild.
The advisory discusses firmware measures for existing silicon and a future hardware revision. These are component-level statements for customers integrating the chip. They should not be converted into an instruction for an ordinary Trezor owner to install arbitrary chip firmware. Nor does a planned future revision prove that a particular retail device already contains it. The chip maker’s disclosure and Trezor’s product response need to be read together while keeping their scopes clear.
[2]A simple example of layered protection
Consider a fictional secure cabinet protected by an outer lock and a separate inner compartment. Discovering a way through the outer lock is a real weakness. Whether it also exposes the contents depends on the inner barrier and on what is stored where. Saying “one lock failed” and saying “everything inside was taken” are different claims.
That analogy explains the question a layered design must answer; it is not a technical model of the Safe 7 or proof of Trezor’s conclusion. In a real device, the independence of the protections must be evaluated from the architecture and evidence. A second component is not automatically an effective second barrier merely because there are two chips on a board.
For readers, the useful habit is to ask exactly what the researchers obtained and which further steps would be needed to reach the asset being protected. This makes the report more informative than a binary argument over whether the entire device has or has not been “hacked.”
Separate the laboratory result from a personal incident
A research disclosure describes a demonstrated or analysed capability under stated conditions. A personal incident involves evidence about a particular device or account. The first can inform the response to the second, but it cannot supply missing facts about what happened to an individual owner.
For example, a reader who has never lost physical control of a device is asking a different question from an organisation evaluating hardware that passes through several custodians. A useful assessment begins by writing down that situation. Who can handle the equipment? What records exist? Which asset or secret is the concern? Those questions help identify which part of the disclosure applies.
This does not mean that a demanding attack is irrelevant. Research can expose a boundary worth improving even when exploitation is expensive today. It means that cost, access requirements and demonstrated impact should be described accurately, rather than compressed into either reassurance without evidence or a universal emergency claim.
What to watch for in a follow-up
A meaningful follow-up would identify a changed product instruction, a verified extension of the attack’s impact or a confirmed deployment of a mitigation. A new headline repeating the same component finding would not, by itself, establish any of those developments. Keep the date and author attached to each statement so that a manufacturer’s plan is not confused with a completed change.
Our reading is that transparency is useful when it makes these distinctions easier to inspect. The reader should be able to identify the affected component, the conditions of the reported attack, the product maker’s explanation and the action that maker actually recommends. We have not reproduced the laboratory work or independently verified the entire Safe 7 security architecture. The article therefore reports the disclosed weakness and the vendors’ stated response without promising that no other vulnerability could exist or inventing a reason for users to move their funds.
Understand the TROPIC01 disclosure
Choose the perspective relevant to your reading.
- Existing Safe 7 owner
Follow the stated response
Trezor says this finding does not require action.
- Evaluating the research
Read the component scope
The disclosed chip attack is distinct from recovering the wallet backup.
Based on the official announcement; availability may change. [1]
- Physical access required.
- Layered protection cited by Trezor.
- Vendor advises no action.
Official sources & further reading
Independently written from the primary sources below. Checked on 26 September 2026.
- Trezor response: TROPIC01 chip disclosure (no impact to your funds) ↗Announcement · 3 June 2026
- TROPIC01 security advisory ↗Documentation
Open-source hardware wallets
No public discount code is attached. Any store promotion has its own terms.
Permanent partner link. Campaign dates and benefits are separate.
We may earn a commission, at no extra cost to you. Account and country conditions apply.