Trezor Addresses TROPIC01 Security Flaw

Trezor says a flaw in the TROPIC01 chip does not put Safe 7 users' funds at risk.

Trezor Addresses TROPIC01 Security Flaw

Reports have emerged about a security vulnerability in the TROPIC01 chip used in Trezor Safe 7 hardware wallets. However, Trezor insists that the issue does not threaten users’ assets and that the wallet remains secure thanks to multiple independent layers of protection.

The vulnerability was discovered by Ledger Donjon, the security research team of hardware wallet manufacturer Ledger. The audit of the TROPIC01 chip was conducted on behalf of Tropic Square, the company responsible for developing the component.

According to the disclosed findings, researchers informed Tropic Square in January 2026 that they had successfully carried out a laser fault injection attack in a controlled laboratory environment. The attack enabled them to extract some data stored on the chip and bypass the firmware signature verification mechanism.

Despite the discovery, Trezor emphasizes that users do not need to take any action. The company states that compromising the TROPIC01 chip alone does not provide access to a user’s PIN, wallet, or stored funds.

Trezor CEO Matej Žák explained that the Safe 7 was designed with multiple independent security layers. As a result, a vulnerability affecting a single component is not enough to compromise customer assets.

Because the issue exists at the hardware level, it cannot be fixed through a standard software update. Nevertheless, Trezor and Tropic Square decided to publicly disclose the findings after carefully reviewing the research results.

The disclosure highlights the ongoing efforts of hardware wallet manufacturers to rigorously test and improve their products. Trezor also reminds users to buy devices only from official sources, keep firmware updated, store recovery phrases offline, and avoid using hardware that shows signs of tampering.

Share