With the @Ledger Wallet CLI you can put your agent to work with the peace of mind that no funds move unless you sign on your Ledger signer.
Let your agent play with Ledger Wallet CLI v2, out now.
v1: Give your agent balances, history, send, receive, swap via CEX providers.
v2? 🧵👇
💥One Check, One Laser, Every Card: The Tangem Immutability Trap.
The @DonjonLedger just published research worth stating plainly.
With a single laser pulse the Ledger Donjon team faults one conditional check in the firmware of a Tangem card and resets the password to a value of its choosing. No existing password, backup card, or recovery feature needed. Once reset, the attacker is able to sign anything and can potentially drain the user’s wallet.
To be precise about the threat model: this attack requires physical possession of the card, invasive chip opening, lab-grade fault-injection equipment, our own setup costs roughly $250,000, and genuine technical expertise. That puts it well beyond the reach of an opportunistic thief, but comfortably within the capabilities of a serious lab. Both things can be true at the same time.
Why one pulse is enough: the recovery path depends on a single yes/no check, “is this card in recovery state?”, and a pulse is simply a precisely timed electrical disturbance designed to make the chip misread that decision at the critical moment. Because there is no redundant check and no penalty for repeated SetPin attempts, one successful disturbance is enough. The chip’s countermeasures are formidable, but they cannot protect the one bit the firmware chose to trust.
The uncomfortable part: it cannot be patched. Tangem cards have no firmware update mechanism. The vulnerability was disclosed on February 10th, 2026. There is no fix coming, because there is no channel to deliver one.
Tangem presents immutable firmware as a security feature. Call it what it is: a trade-off. "We cannot change the firmware" is a strong story right up until the firmware is wrong. Then the same property that protected you guarantees you can never be protected again. This research did not create that reality. It made it visible.
What a user can do, since there is no patch: this attack requires physical possession of the card and invasive lab work, so it cannot be done covertly. The practical risk is a lost or stolen card in the hands of a capable attacker. If the card stays in your possession, there is no reason to assume compromise. If you have doubt, or if your threat model requires a higher level of assurance, treat the funds as compromised and move them to a new secure set up.
This was published in line with Ledger Donjon’s responsible disclosure process. When a vulnerability cannot be patched, the next responsibility is to inform users clearly and widely, so they can make their own informed decisions, especially here where the vulnerability can not be exploited remotely.
The bigger lesson is not about one product. Security is never static, and systems should be designed with human error and future failure in mind. You should not have to blindly trust that yesterday’s assumptions still hold. You should be able to verify, adapt, and recover when they do not. Design for the day you are wrong, because eventually, you will be.
Full write-up from Baptistin Boilot, Ledger Donjon.
Stay safe. Stay honest about your trust assumptions.
https://t.co/1FMn0fjGJd
🚨“Bitcoin cracked in 9 minutes”. Headlines are going viral today.
The truth is: Google just showed that the math is advancing faster than most expected. That’s serious progress. But no one has the quantum hardware to touch your keys. Not even close.
At @Ledger, we’ve been building for this exact scenario for years. Our hardware is already stress-testing post-quantum signatures.
Your assets are secure, today and in the future.
To the whole industry: stop waiting.
The time for post-quantum migration is now.
We’re not just talking, we’re shipping.
Ledger is ready.
Are you?
Full technical breakdown from our CTO @P3b7_ here 👇
#PostQuantum #CryptoSecurity
This is a must-read blog from @Ledger's CXO @iancr.
Soon, the primary actors in our financial and digital systems won’t be humans clicking buttons; it will be autonomous AI agents. These agents will research, negotiate, and transact in milliseconds, 24/7, on our behalf.
The rise of AI agents only reinforces this reality:
- If agents act on your behalf, you must control your keys.
- If identities can be faked, trust must be rooted in secure hardware.
- If decisions are automated, consent must remain human-verifiable.
Ledger’s strategy from securing crypto to securing agents is natural. Crypto is an incredible first use case. Agents are the next one. The companies that understand this shift will define the next decade of digital ownership.
#RevengeOfTheAtoms #AgenticEconomy
https://t.co/Gw88Wqd54J
La population de Gaza a besoin de nourriture et d'eau maintenant ! Il est temps de #SuspendreL'accord au risque d'être complice de famine. @gouvernementfr@KajaKallas@vonderleyen Le monde vous regarde.
@JohnKerry the world needs you! And can’t afford the #cop28 climate talks to fail. Please support the fossil fuel phase-out NOW to limit global warming to 1.5C! 🙏
Avec @Atekka_Ins ➡️ Une #assurance gel sans passage d’expert
[La flexibilité dans le choix des parcelles, des taux de franchises et des aléas à couvrir en sont les principaux atouts]
✅ https://t.co/3pRspDryXA
5️⃣% : c’est le maximum du temps consacré au climat depuis le début de la présidentielle ! 📣 @LeaSalame@laurentguimier : jeudi 31 mars, on compte sur vous poser les questions essentielles pour le climat durant @Elysee2022 ! #PasDeClimatPasDeMandat
« Depuis quelques années, on est confronté à des aléas climatiques » Thierry Sureau
💫Chez @OcealiaGroupe , Atekka & @UnderstoryWx lancent une offre d’assurance innovante pour les viticulteurs de #Cognac : de nouvelles solutions complémentaires à l’assurance traditionnelle
Les viticulteurs seront indemnisés sous trois semaines par @Atekka_Ins d'un montant fixé à l'avance en fonction de données récoltées par des capteurs @UnderstoryWx installés dans leurs parcelles.
https://t.co/c3eIJ3U1S4
La #coopérative@OcealiaGroupe et @Atekka_Ins s'associent à Understory pour créer une solution d'assurance paramétrique contre la grêle et le #gel auprès des viticulteurs 🍇 de #Cognac.
https://t.co/hzE9ZM4ljc
@Atekka_Ins , @UnderstoryWx et Océalia s'associent pour créer une solution unique d'#assurance paramétrique contre la #grêle et le #gel pour les vignobles.
👉https://t.co/53OboMspHa