XKEYCHAINX LABS
Response & remediation

Disclosed.
Then what?

A patch belongs to a specific finding. Check the model, the affected component and whether an update addresses an existing exposure.

Read this as a dated research snapshot. Listed fix versions are historical thresholds, not a claim that they are today’s latest releases. “Unknown version” and hardware limitations remain visible; a seed exposure may require migration.

Manufacturer / findingAffected scopePublished remediationDetails
Ledger
Ledger Nano X: physical cellular implant
Nano X · Physical tamperingNo software-only fix establishedScope & sources ↗
Keystone
Black Hat 2026: USB SDK attack
Keystone 3 Pro before 2.4.02.4.0 released April 1, 2026.Scope & sources ↗
Ledger
Signing state could change during review
Affected apps built with vulnerable SDK through 26.6.0SDK 26.6.1 and rebuilt apps; Ethereum added a guard in 1.22.2.Scope & sources ↗
Ledger
Clear-signing array count truncation
Ethereum app 1.19.0–1.22.2Ethereum app 1.22.3.Scope & sources ↗
Ledger
Swap approval accepted as payment
Ethereum app 1.20.0–1.22.2Ethereum app 1.22.3.Scope & sources ↗
BitBox
Three security findings in Dixence disclosure
BitBox02 / Nova; scope differs by finding9.26.5 covers all three; consult current vendor upgrade instructions.Scope & sources ↗
Trezor
Authenticity proofs not bound to individual chips
Safe 7 authenticity verificationVendor reports binding each proof to its intended element.Scope & sources ↗
Coldcard
Coldcard: weak seed generation and migration
Multiple models · Seed generationFixed firmware + seed migrationScope & sources ↗
Tangem
Tangem: laser fault password reset
Tangem cards · Physical accessNo field firmware patch per researcherScope & sources ↗
Trezor
Pairing-code check bypass
Safe 7 THP pairingVendor reports rejecting the invalid exchange values.Scope & sources ↗
Ledger
Monero app secret-key exposure
Monero app before 2.1.4Monero app 2.1.4, released March 20.Scope & sources ↗
Trezor
TROPIC01 laser fault research
Standalone TROPIC01 chip, including bootloader 2.0.1See chip mitigations and Trezor’s layered-security response.Scope & sources ↗
Jade
Descriptor parsing memory corruption
Firmware 1.0.24–1.0.361.0.37 fixes parsing; 1.0.38 adds rollback protection.Scope & sources ↗
Coldcard
Delta PIN private-key recovery
Delta PIN signing; full affected matrix unspecifiedVendor lists 5.4.4 and 1.3.4Q.Scope & sources ↗
Tangem
Access-code retry-delay bypass
Tangem card authenticationNo field firmware update for existing cards per researcher.Scope & sources ↗
Tangem
Android genuine-check bypass
Android app before 5.18.3Android app 5.18.3, released November 28, 2024.Scope & sources ↗
Trezor
Donjon supply-chain evaluation
Safe 3 design evaluated in 2024Vendor lists resolved; exact release not given on this entry.Scope & sources ↗
Tangem
Tangem: private keys in support logs
Mobile app · Seed-based activationiOS 5.19.1 / Android 5.19.2Scope & sources ↗
Coldcard
Donjon full Mk3 extraction chain
Mk3 challenge walletsLater architecture changes do not retrofit Mk3.Scope & sources ↗
Passport
Pre-production boot and update audit
Original Passport pre-production hardware/softwareKeylabs says findings remediated and fixes sanity-checked.Scope & sources ↗
SafePal
Physical tamper and downgrade weaknesses
S1 evaluated by KrakenDowngrade issue fixed in 1.0.24.Scope & sources ↗
Coldcard
Multisig wallet substitution
Firmware through 3.1.9Firmware 3.2.1.Scope & sources ↗
Coldcard
Donjon laser PIN recovery
Mk2 / ATECC508AHardware-generation change; see vendor response.Scope & sources ↗
Trezor
Trezor One and Model T: physical seed extraction
Trezor One / Model T · Legacy modelsPassphrase mitigation; hardware limitScope & sources ↗
Coldcard
Coldcard: multisig change validation
Multisig transactions · HistoricalFixed in firmware 3.0.6Scope & sources ↗
KeepKey
Kraken physical seed extraction
Historical KeepKey designStrong external passphrase mitigates the associated wallet; hardware limitation.Scope & sources ↗
Trezor
Black Hat: MINimum Failure
Trezor One before firmware 1.8.0; USB descriptor handlingTrezor One 1.8.0 closed this attack path. Model T 2.1.0 received the same defensive measures although it was not directly affected.Scope & sources ↗
Ellipal
Ellipal EC01: physical and firmware weaknesses
Original EC01 · Not a Titan findingVendor cites firmware 2.0Scope & sources ↗