Edited By
Olivia Johnson

A fresh wave of revelations from Ledger's internal team, the Donjon, highlights ongoing efforts in 2025 to enhance the security of crypto hardware. This white-hat hacking initiative reflects escalating concerns around device vulnerabilities and the challenges in ensuring user trust amid industry controversies.
Donjon is Ledger's internal group of ethical hackers tasked with testing products before malicious actors can exploit weaknesses. The teamโs mantra is clear: "You canโt call a device 'unhackable' without trying to hack it first.โ This proactive approach to security sets them apart in a landscape often marred by marketing gimmicks rather than genuine safety.
In 2025, Donjon focused on several areas:
Smartphone Weaknesses: During tests on the Mediatek Dimensity 7300 chip, the team exploited electromagnetic pulses, successfully altering the boot process. This illustrates that while smartphones serve as essential tools, they fall short of being secure vaults for sensitive data.
Tangem Wallet Breaches: A recent examination of Tangem's card-style wallets revealed vulnerabilities, enabling a brute force attack on a 4-digit PIN, taking as little as an hour.
Collaborative Efforts: The team partnered with Trezor, identifying supply chain vulnerabilities within their Safe 3 microcontroller. This cooperation emphasizes a community-driven approach to bolstering security across the ecosystem.
Instead of publicizing exploits that could lead to further attacks, the Donjon team practices responsible disclosure. They provide a 90-day window for companies to address identified vulnerabilities. โWe would rather get a โthank youโ in a patch note than see someoneโs savings lost,โ a team member noted.
Many wonder, โDoes this matter if I donโt lose my device?โ The answer lies in the evolving nature of security. Each vulnerability discovered feeds back into firmware updates, underscoring the critical need for updatable devices. Without updates, wallets become ticking time bombs, susceptible to known threats over time.
While the work at the Donjon might seem methodical and slow, the costs of neglecting such proactive measures can be high. The lab, based in Paris, is equipped with advanced testing tools typically unseen by the public. Even as some challenges remain, the team also encourages external scrutiny through a public Bug Bounty program, fostering a culture of openness.
Comments about Ledger's practices reveal mixed feelings:
Call for Transparency: โRemove changelly and apologize to the victims first,โ urges one, reflecting broader discontent around trust issues.
Distrust: Another commenter wrote, โYou might have a great team but business practices suggest we should not trust you.โ
In a world where trust is vital, the handling of data leaks and previous controversies weighs heavily on user confidence.
๐ก๏ธ Donjon reinforces security through upfront testing.
๐ Responsible disclosure ensures threats are managed before they go public.
๐ Trust remains shaky among users post-controversy; fingers are pointed at past dealings.
Ledgerโs Donjon initiative paints a picture of an industry committed to evolving security, even as trust issues loom large. The question remains: will users embrace these measures amid lingering skepticism?
For more information about Ledger's commitment to security, visit Ledgerโs website.
As Ledgerโs Donjon continues pushing the envelope in security practices, thereโs a strong chance that other companies will follow suit. Experts estimate around a 70% likelihood that we will see broader industry collaboration aimed at fortifying crypto hardware over the next year. The continual rise of cyber threats may push companies to not only adopt strong security measures but also prioritize transparency. Additionally, this proactive culture could lead to a more robust Bug Bounty environment, encouraging more people from the ethical hacking community to engage in responsible security practices. Considering the growing demand for safe crypto solutions, consumers might increasingly gravitate toward brands showcasing such initiatives, leading to an emerging standard for security in the crypto space.
This situation recalls the establishment of safety standards in the automotive industry after the introduction of safety regulations in the 1960s. Just as manufacturers needed to adapt to rigorous testing for safety features, such as seat belts and airbags, so too do crypto hardware companies today face similar pressures. Once seen merely as optional enhancements, safety measures became essential for consumer trust and market competitiveness. Similarly, the necessity for crypto security may evolve from a niche requirement to a baseline expectation as people demand safety in a digital landscape fraught with risks.