By
Mia Chen
Edited By
Carlos Ramirez

Security isnβt a static checkbox; itβs a constant fight. Ledger reveals how their internal team of white-hat hackers, known as the Donjon, evaluates their hardware and the broader ecosystem to identify vulnerabilities before they can be exploited by bad actors.
In 2025, the Donjon team focused on physical security, asking pertinent questions about device security. They specifically examined:
Smartphone Vulnerabilities: The team targeted the Mediatek Dimensity 7300 chip, widely used in Android phones. They demonstrated how electromagnetic pulses could disrupt the boot process, granting full control over devices.
Brute-Forcing Wallets: Their research on Tangem's card-style wallets revealed a method to bypass PIN delays. This allowed them to crack a 4-digit PIN in roughly one hour by interrupting power at critical moments.
Supply Chain Risks: Collaborating with Trezor, they identified potential supply-chain bypass vulnerabilities in the Safe 3 microcontroller, which could leave users exposed.
When the Donjon uncovers a vulnerability, they donβt broadcast it publicly. Instead, the team practices responsible disclosure, notifying the affected companies privately with a 90-day window to fix the issue. As one insider noted, "Weβd rather have a 'thank you' in a patch note than a viral exploit that costs people their savings."
Users should question the assumption of safety if they think losing a device isn't an issue. Each finding from the Donjon goes directly to firmware teams, enhancing device security. An 'un-updatable' device is now seen as a "ticking clock" waiting for an inevitable exploit.
"Security that doesnβt evolve is just an old lock on a new door," a Donjon member emphasized.
Comments from the community reflect skepticism about Ledger's practices. Users voiced concerns, with one stating, "Nobody cares. You might have a great team, but trust is the primary factor."
Several themes emerged:
Criticism of Ledgerβs Business Practices: Users are wary due to past controversies.
Trust Issues: Trust remains crucial in financial and security sectors.
Desire for Transparency: There's a call for clear communication and accountability.
Feedback is mostly negative, with community members questioning Ledger's reliability and practices, especially surrounding data security.
π The Donjon's physical security work reveals critical vulnerabilities.
π "Responsibility in disclosure protects not only companies but users as well."
π° Ongoing criticism raises questions about trust within Ledger's business practices.
In the crypto world, trust is paramount. As security threats evolve, Ledger's proactive approach may be refreshing but is met with scrutiny as users demand better reliability and transparency.
Experts estimate that Ledger will need to enhance its communication strategy and practices to regain user trust. With ongoing scrutiny, thereβs a strong chance the company will introduce more transparent security disclosures within the next six months. If the Donjon Lab continues to identify critical vulnerabilities and provide timely updates, user confidence could see a notable rebound, with expectations of a 20% improvement in community sentiment. Conversely, if skepticism persists without visible change, Ledger might face a decline in user engagement over the coming year, leading to further market challenges.
Looking back, a curious parallel can be drawn between Ledger's current situation and the case of vault manufacturers in the early 2000s. As the digital age began to displace traditional security measures, vault producers faced similar trust issues after a series of high-profile breaches. Just as vaults were deemed unreliable, despite high-grade materials, people ultimately turned to smart technology for security solutions. The lesson echoes: trust is built not just through innovation but through consistent, reliable performance over time, reminding us that a reputation can hinge on the smallest details.