A security researcher testing a hardware wallet may encounter a practical problem: the device claims to resist power analysis attacks, but what does that claim actually mean at the silicon level? Power analysis is not a theoretical vulnerability confined to academic papers. Attackers have extracted cryptographic keys from payment terminals, ATMs, and poorly designed hardware wallets by measuring the electrical current drawn during private key operations. The defense requires more than a secure element chip sealed inside a card. It requires the chip’s manufacturer to understand the physics of information leakage and implement countermeasures that survive real-world testing.
Tangem’s architecture presents a useful case study because it combines offline key storage with a compact form factor that must still resist electromagnetic observation, power consumption variation, and timing-based inference. The absence of a traditional screen, battery, or USB connection changes what an attacker can measure, but it does not eliminate the fundamental problem: when a cryptographic operation runs, it consumes power, emits radiation, and takes measurable time. Those physical signatures can reveal information about the keys and data being processed if the implementation is not carefully hardened.
Power analysis fundamentals and key extraction
Power analysis exploits the correlation between the electrical power consumed by a processor and the data it is processing. When a chip executes an instruction, current flows through transistors. The magnitude of that current depends on how many transistors are switching at a given moment. If a cryptographic operation uses conditional branches or lookup tables that depend on secret data, the power signature of processing a 0 bit will differ measurably from processing a 1 bit. Collecting many power traces during key operations and performing statistical analysis can recover the key one bit at a time.
Simple Power Analysis, or SPA, examines the power trace visually or through simple statistical comparison. A square-and-multiply modular exponentiation algorithm that conditionally executes multiplication based on the bits of the exponent will show different power patterns depending on whether the bit is 0 or 1. An attacker with access to high-resolution power measurements and knowledge of the algorithm can sometimes read the key directly from the pattern without sophisticated mathematics. Differential Power Analysis, or DPA, is more subtle. It requires many traces but no knowledge of the algorithm. The attacker acquires power traces for many cryptographic operations with different inputs, hypothesizes what the secret might be, and compares the measured power against the predicted power. The hypothesis that produces the best statistical correlation is correct.
A chip that is not hardened against DPA can leak key material during operations as brief as a few milliseconds. The attack does not require modifying the device, breaking its casing, or even touching it. A current probe placed near a power line or an electromagnetic sensor positioned at a distance can record the emissions. If the attacker controls the input data or can observe the outputs, DPA becomes practical with modest equipment: an oscilloscope, a probe, a computer with signal processing software, and time.
For hardware-based cryptography on a secure element chip, the goal is to ensure that the power signature is independent of the data being processed. This is harder than it sounds because CPUs are fundamentally designed to be efficient, and efficiency often correlates with how much work is being done on the current instruction. Resisting power analysis requires intentional inefficiency: adding dummy operations, randomizing instruction timing, masking data so that the intermediate values reveal nothing, and constantly drawing current regardless of whether useful work is happening.
Masking, blinding, and randomization strategies
Cryptographic masking is the primary defense against DPA. The idea is to ensure that intermediate values are never processed unmasked. Before an operation begins, the data is combined with a random value. The computation proceeds on the masked data, and at the end, the mask is removed. An attacker capturing a power trace sees the operation on masked data, which is independent of the actual secret. To recover the key, the attacker would need to know or guess the mask, which is random and different for each operation. For algorithms like AES, masking can be applied at various levels: the entire state can be masked, individual bytes can be masked, or multiple shares can be used in Boolean or arithmetic masking schemes.
Boolean masking splits the state into two or more random shares such that the XOR of all shares equals the original value. The processor operates on the shares independently, ensuring that no unmasked intermediate value ever appears in power consumption. Arithmetic masking uses modular addition instead, which can be more efficient on some hardware. The trade-off is complexity: a masked AES implementation requires more instructions and memory to achieve the same result as an unmasked version. That overhead increases code size, instruction cache pressure, and execution time. For a card-based wallet, execution time is less critical because the transaction is signed on-demand and users expect a brief delay. Increasing the work from a few thousand cycles to tens of thousands is acceptable if it hardens the implementation.
Blinding is orthogonal to masking and is particularly important for modular exponentiation algorithms used in RSA and Elliptic Curve operations. Before computing the exponentiation, the input is multiplied by a random blinding factor. After exponentiation, the blinding is removed. The exponentiation process now depends on the blinded input rather than the secret directly, which breaks the correlation between the power and the actual key. Randomizing the order of operations is another layer: an implementation might process AES SubBytes in a shuffled order rather than the standard row-major sequence. The final result is the same, but the power trace shows a different pattern each time, eliminating the ability to average traces and extract information through statistical correlation.
A proper implementation uses multiple defenses in combination. A transaction signature on Tangem hardware does not simply mask the key, randomize the operation order, and sign once. It may additionally randomize the order in which operations are processed, add dummy operations that do not affect the result, vary the power consumption by inserting random delays, and process the data through multiple masked shares simultaneously. Each layer makes extraction exponentially harder because an attacker must break through all of them, not just find the one weakness.
Electromagnetic emission hardening and shielding
Power analysis through the power supply is one attack surface. Electromagnetic analysis, or EMA, exploits the same underlying physical principle through the radiation emitted by the chip itself. When current changes direction and magnitude rapidly, it creates time-varying magnetic and electric fields. An antenna or probe positioned near the chip can detect these emissions, which encode information about the operations being performed. EMA can sometimes reveal information with finer spatial resolution than power analysis because different parts of the chip may have distinct electromagnetic signatures. An attacker with a probe near the ALU might see different patterns than one measuring the instruction decoder.
Tangem’s card form factor presents both advantages and constraints. The card is physically compact and has no exposed connector pins in the traditional sense. The only contact point is the NFC antenna embedded in the substrate. This reduces the number of locations where an attacker can attach a probe. The entire computation happens within a shielded die, which is mounted inside a secure element package designed to resist tamper detection. Standard secure element packages include Faraday cages, which are conductive meshes that attenuate external electromagnetic fields. They also include detectors that trigger a zeroization event if the die is subjected to excessive mechanical, thermal, or electromagnetic stress.
However, shielding is not perfect isolation. Electromagnetic waves can penetrate gaps, and high-frequency emissions can couple through multiple paths. An attacker with specialized equipment can position probes in multiple locations around the card and correlate the signals to extract information about chip operations. The defense requires hardening at the algorithmic level. Even if an attacker successfully captures electromagnetic emissions, the emissions should reflect only the masked or randomized data, not the key itself. This is why masking and blinding are so critical: they make the electromagnetic signature independent of the secret regardless of how well the physical shields work.
Tangem’s implementation likely includes both passive shielding through the secure element package and active hardening through the cryptographic software. The documentation available through sites.google.com/cryptowalletextensionus.com/tangem-wallet/ does not disclose specific masking parameters or implementation details, which is appropriate because publishing exact countermeasures can make reverse-engineering attacks easier. Security through obscurity is weak alone, but it is a reasonable supplementary defense when the primary defenses are mathematically sound.
Timing attacks and constant-time implementation
Power and electromagnetic analysis are not the only physical side-channels. Timing attacks measure how long a cryptographic operation takes. If a key-dependent operation runs faster when the key has certain properties, an attacker who can time the operation repeatedly can narrow the possibilities. For example, a naive RSA implementation that multiplies only when the exponent bit is 1 will be faster when processing an exponent with many 0 bits. An ECC implementation that terminates a loop early when certain conditions are met will leak information about the secret through execution time.
Defending against timing attacks requires constant-time implementation: every code path through a cryptographic operation must take the same number of clock cycles. This is harder than it sounds because modern processors have instruction caches, branch predictors, and memory hierarchies that naturally create timing variation. A load from cache is faster than a load from RAM. A predictable branch is resolved faster than a mispredicted one. Even if the programmer writes code that appears constant-time, the processor might optimize it in ways that reintroduce timing differences.
Secure element chips designed for cryptography often include specialized instructions that are guaranteed constant-time and side-channel hardened. These instructions perform operations like modular multiplication, AES encryption, or elliptic curve operations in a fixed number of cycles regardless of the input data. Using these specialized instructions instead of general-purpose arithmetic is a key part of implementing timing-resistant cryptography on Tangem hardware. The chip’s manufacturer has tested the instruction set to verify that the cycle count does not vary with data, and that power and electromagnetic emissions are independent of the input.
Timing can also be exploited indirectly through cache behavior or branch prediction. When a processor accesses memory at different addresses based on the secret key, the pattern of cache hits and misses creates timing variation that can be measured remotely. Defense requires array indexing that is independent of the secret, often implemented by accessing a lookup table at multiple addresses regardless of which value is actually needed, or by using instruction sequences that do not trigger branch prediction.
Fault injection resistance and tamper detection
Side-channel attacks measure physical phenomena during normal operation. Fault injection attacks deliberately introduce errors and observe the results. By applying a precisely timed electromagnetic pulse, a glitch of excessive heat, or a brief power spike, an attacker can force a bit to flip or a memory access to fail. If the fault occurs at the right moment during a cryptographic operation, the output will be incorrect in a way that reveals information about the key. Some fault attacks can even extract the key directly if the attacker can trigger a conditional branch to execute the wrong way and observe the output.
Tangem hardware includes tamper detection and response mechanisms. If the chip detects unusual electromagnetic pulses, temperature excursions, voltage fluctuations, or physical manipulation, it zeroizes the stored keys and generates a tamper event that cannot be reversed. The card is designed so that opening the casing or attempting to probe the die is detected and triggers immediate key destruction. This raises the cost of fault injection attacks because the attacker cannot simply inject faults, observe the results, and inject again. After the first successful injection, the device becomes inert.
At the software level, fault attack resistance involves redundancy and checks. Critical operations may be performed multiple times and the results compared. Loop counters may be checked after each iteration. Cryptographic outputs may be verified before returning to the calling application. If a fault has occurred, the result will not match the expected value, and the operation fails safely. This is distinct from power and electromagnetic hardening because fault injection is a discrete event, not a continuous physical phenomenon. The countermeasures are therefore detection and response rather than masking and randomization.
Practical limitations and attack surface reality
Tangem’s form factor creates asymmetric attack and defense properties. Because the card has no battery, no persistent connection, and no screen, attackers cannot conduct extended side-channel measurements in real-world usage. A payment at a merchant’s terminal or a transaction signed during a brief tap does not allow time for sophisticated statistical attacks that require thousands of traces. An attacker would need physical access to the card, specialized equipment, and controlled conditions. The card itself never connects directly to the internet; all communication is through the user’s phone. This eliminates entire attack vectors present in tethered hardware wallets where a USB connection might leak information or permit a firmware modification.
However, the absence of public security certifications or published penetration testing results is worth noting. Unlike some hardware wallets that have undergone FIPS certification or third-party audits, Tangem’s security documentation is not independently verified through standard processes. This does not mean the implementation is weak, but it means security researchers and users must evaluate the design based on the architectural choices disclosed rather than a formal certification. The card-based design, the use of a certified secure element, the requirement for physical confirmation, and the absence of a USB attack surface are all positive indicators. But security is only as strong as the weakest link, and the weakest link is often not the chip itself but the integration, the firmware, the update mechanism, and the user’s operational security.
A key practical reality is that side-channel hardening is a moving target. As researchers develop new attacks, manufacturers must respond with new countermeasures. An implementation that is secure against DPA and electromagnetic analysis today might be vulnerable to a newly published attack in five years. This is why examining the design choices—the masking strategy, the use of constant-time operations, the tamper detection mechanisms—is more informative than asking whether the device “passes” a side-channel test. The right question is whether the manufacturer has designed the system with side-channel defense as a core requirement and whether they are positioned to respond to new findings.
Evaluation criteria for side-channel resistance
When evaluating Tangem or any non-custodial hardware wallet for cryptocurrency security at the side-channel level, several criteria deserve attention. First, determine whether the device uses a certified secure element chip from a reputable manufacturer such as NXP, STMicroelectronics, or Infineon. These chips are designed for payment systems and have undergone extensive evaluation. The manufacturer’s datasheet should describe the masking and blinding algorithms used. If the documentation is vague or unavailable, ask why.
Second, examine the cryptographic algorithm choices. Does the wallet use AES for symmetric operations and well-vetted curves like secp256k1 or Ed25519 for asymmetric cryptography? Are the algorithms implemented using constant-time code and specialized chip instructions? Do the operations use appropriate key sizes? A 256-bit key is sufficient for elliptic curve cryptography for the foreseeable future; anything smaller is a red flag.
Third, assess the operational model. Can the device be updated remotely, or must updates be performed locally with physical access? Can firmware be audited and verified? Is there a secure boot process that prevents unsigned code from running? These questions address the integrity of the implementation over time.
Fourth, consider the practical threat model. Who might realistically attack the device, with what resources and constraints? A targeted attack by a nation-state intelligence agency is a different proposition from an opportunistic thief at an airport. The threat model should inform whether side-channel hardening is the most critical concern. For a user storing substantial Bitcoin holdings, side-channel resistance is important. For a user managing small amounts for frequent transactions, usability and recovery procedures might matter more.
Future directions in side-channel defense
The field of side-channel analysis is evolving. Machine learning techniques are being applied to extract information from power and electromagnetic traces with less manual feature engineering. Researchers are developing new attacks that exploit subtle interactions between the processor’s cache, instruction pipeline, and speculative execution. At the same time, secure element manufacturers are deploying more sophisticated countermeasures, including higher-order masking schemes that are resistant to attacks that combine information from multiple intermediate values, and randomized masking parameters that change constantly.
For hardware wallets, the trend is toward more specialized chips designed specifically for cryptography rather than general-purpose secure elements. This allows manufacturers to implement countermeasures that are deeply integrated with the instruction set and the circuit layout. Tangem’s choice of a card form factor with a built-in secure element reflects this direction: the entire device is optimized for signing operations and key storage, not for the flexibility of a general-purpose processor.
The ultimate implication is that side-channel resistance is not a checkbox but a system property. A device that resists power analysis must also resist electromagnetic analysis, timing attacks, and fault injection. The defenses must work together, not independently. They must persist through firmware updates and evolve as attacks improve. For a user storing cryptocurrency, understanding these physical fundamentals is less important than recognizing that a serious hardware wallet manufacturer has invested in designing the system with these threats in mind. The questions to ask are whether the design choices reflect that investment and whether the manufacturer has a track record of responding to new threats.
Frequently asked questions
Can an attacker extract my private key from a Tangem card using power analysis?
Extracting a key through power analysis requires the attacker to capture many high-resolution power traces during cryptographic operations, perform statistical analysis, and overcome the card’s masking and blinding defenses. The card’s form factor and secure element package make this significantly harder than attacking a tethered hardware wallet. However, no implementation is absolutely immune. The defense is based on making the attack so expensive and time-consuming that it becomes impractical for all but the most resourced adversaries.
What is the difference between power analysis and electromagnetic analysis?
Power analysis measures the electrical current drawn by the chip through the power supply pins. Electromagnetic analysis captures the radiation emitted by the chip itself. Both exploit the correlation between physical measurements and the data being processed. Power analysis requires access to power lines or very close proximity; electromagnetic analysis can sometimes work at a distance. Both are defended against through masking and constant-time implementation.
Does Tangem’s lack of a screen or battery make it more or less secure against side-channel attacks?
The lack of a battery and screen reduces some attack vectors because there is no persistent power consumption to analyze and no screen refresh pattern to observe. However, it does not eliminate side-channel threats. An attacker with physical access can still measure power and electromagnetic emissions during a transaction signing operation. The real benefit is that the card’s limited operational window makes extended statistical attacks impractical in real-world scenarios.
