Tropic Square is a Prague fabless semiconductor company behind TROPIC01. Openness helps people examine a design, but does not itself establish the resilience of a particular revision or complete device.
Tropic Square names the company, TROPIC01 its security chip. The announcement of 6 October 2025 describes full production and global distribution; it does not establish current stock availability for every variant. [Tropic Square — Full production, October 2025]
The TROPIC01 repository exposes RTL design, firmware and security architecture. It identifies the RISC-V core and SPECT coprocessor. These materials enable an audit; publication alone does not mean the reader has performed one. [Tropic Square — TROPIC01 documentation]
Tropic Square warns on GitHub that published repositories may not exactly match shipped products. Practical circumstances and third-party rights can delay publication. An assessment must therefore connect the specific part and firmware to their corresponding documentation. [Tropic Square — Repository publication scope]
The February 2025 partnership with EPS Global covers secure provisioning and distribution. PKI assigns a cryptographic device identity; this manufacturing activity differs from opening the source design or independently auditing an end-user wallet. [Tropic Square — EPS Global partnership]
The announcement of 12 May 2026 states that Jan Pleskač leaves the CEO role, remains a shareholder and is succeeded on an interim basis by Ladislav Veselý. Older CEO quotations cannot therefore be reused without dates as current organizational facts. [Tropic Square — Leadership transition, May 2026]
On 3 June 2026, Tropic Square described laser fault injection investigated by Ledger Donjon that can bypass TROPIC01 firmware verification. It requires physical access and a specialized laboratory. The recommended disabling of maintenance mode increases attack complexity but does not eliminate it. [Tropic Square — Laser fault injection disclosure, June 2026]
Trezor distinguishes the TROPIC01 evaluation from the entire Trezor Safe 7 architecture and describes additional PIN protection layers. A component attack must not automatically be presented as a compromise of the entire wallet or proof of its invulnerability. [Trezor — TROPIC01 component vulnerability]
The company's CVD process separates security advisories, errata and evaluation reports. Chip research also does not replace the end-product manufacturer's rules. Assessing Tropic Square means following specific revisions, disclosed findings and remediation, not merely the open-hardware label. [Tropic Square — Coordinated vulnerability disclosure]
For the clearest picture, read this entry together with Jan Pleskač, TROPIC01, SatoshiLabs, Secure Element. The reverse links also lead from Secure Element, Jan Pleskač, TROPIC01.