Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Tangem Addresses Security Flaw After Community Backlash

Tangem Addresses Security Flaw After Community Backlash

BeInCryptoBeInCrypto2025/01/01 16:50
By:Camila Grigera Naón

Tangem addresses a security vulnerability involving the collection of user private keys during email interactions.

Tangem, a crypto wallet provider, recently identified a significant security risk in its mobile app that inadvertently collected users’ private keys during email interactions.

This fix followed repeated warnings from members who expressed concerns about the potential security risks. They indicated that users’ private keys were collected via email interactions within the Tangem mobile app.

Tangem Users Face Critical Security Risks

On December 29, a discussion on Reddit highlighted a potential security vulnerability in Tangem’s wallet. Users revealed that private keys were being stored in email histories, potentially exposing them to Tangem employees.

A Reddit user known as “u/areklanga” exposed the vulnerability in a forum, sparking community concern.

“So, user private keys remain in both user email history, Tangem email history, and perhaps in some Tangem ticket tracking system and are available for Tangen employees. Which makes all Tangem users compromised,” the user said.

Users also noted that the original Reddit post detailing the glitch was mysteriously deleted, raising suspicions about Tangem’s initial response. As soon as these concerns were validated, users flooded Tangem employees and support via email.

Meanwhile, on December 30, Tangem acknowledged the issue and attributed it to a bug within the mobile app’s log processing function. They issued a statement confirming that they “fully resolved” the bug.

“When creating a wallet with a seed phrase, the private key was mistakenly logged in the application’s logs. These logs could later be accessed during interactions with our support team,” Tangem said in a statement on Reddit.

Tangem clarified that the bug had a limited impact. It affected only users who generated a seed phrase and immediately made a support request. It added that Tangem deleted all of the logs received by the support team. 

Users Accuse Tangem of Downplaying Situation

While Tangem promptly addressed the vulnerability, some members of the crypto community expressed concerns about the company’s communication strategy. Specifically, they criticized the lack of public announcements regarding the vulnerability on Tangem’s official social media platforms.

“I find it frustrating how Tangem is downplaying the scope of this event. While they claim that only a “very small group of users” sent an email with their keys, how many users had their keys written in plain text to their phones in a log file?” said one Reddit user.

At the time of publication on December 31, Tangem had not yet made any official announcements regarding the security risk on its social media channels.

Tangem advised all users to immediately update their mobile applications to the latest version to mitigate potential risks associated with the vulnerability.

0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Who decides the fate of 210 billions euros in frozen Russian assets? German Chancellor urgently flies to Brussels to lobby Belgium

In order to push forward the plan of using frozen Russian assets to aid Ukraine, the German Chancellor even postponed his visit to Norway and rushed to Brussels to have a working meal with the Belgian Prime Minister, all in an effort to remove the biggest "obstacle."

Jin102025/12/05 11:56

The "Five Tigers Competition" concludes successfully | JST, SUN, and NFT emerge as champions! SUN.io takes over as the new driving force in the ecosystem

JST, SUN, and NFT are leading the way, sparking increased trading and community activity, which is driving significant capital inflows into the ecosystem. Ultimately, the one-stop platform SUN.io is capturing and converting these flows into long-term growth momentum.

深潮2025/12/05 10:47
The "Five Tigers Competition" concludes successfully | JST, SUN, and NFT emerge as champions! SUN.io takes over as the new driving force in the ecosystem

The End of Ethereum's Isolation: How EIL Reconstructs Fragmented L2s into a "Supercomputer"?

EIL is the latest answer provided by the Ethereum account abstraction team and is also the core of the "acceleration" phase in the interoperability roadmap.

深潮2025/12/05 10:47
The End of Ethereum's Isolation: How EIL Reconstructs Fragmented L2s into a "Supercomputer"?
© 2025 Bitget