Loading stock data...

Tangem Fixes Bug Exposing User Seed Phrases via Email

Media 407e6553 1a82 4fd7 8fd6 0508f45f2275 133807079768105710

Update (Dec. 31, 12:40 pm UTC)

This article has been updated to include Tangem’s statement to Cointelegraph on the security vulnerability, the fix, and its handling of the situation.

In recent news, cryptocurrency wallet provider Tangem has fixed a critical security vulnerability in its mobile app that exposed certain users’ private keys via emails. The fix came after Redditors repeatedly called out Tangem for putting investors’ funds at risk by exposing their private keys on email accounts and to Tangem employees.

Background: A Reddit Discussion Raises Concerns

On December 29, a Reddit discussion on Tangem’s operations gained traction, claiming that the wallet provider allowed private keys to remain on email histories. The Redditor, u/areklanga, added that Tangem had not provided a "sensible reaction" when the issue was pointed out earlier.

So, user private keys remain in both user email history, Tangem email history, and perhaps in some Tangen ticket tracking system and are available for Tangen employees. Which makes all Tangem users compromised.

The Redditor also claimed that the original Reddit post mentioning the glitch "was deleted for some reason." This raised concerns about Tangem’s transparency and handling of user data.

Tangem Acknowledges the Issue and Provides a Fix

Tangem acknowledged the issue on December 30 and said the incident arose from a bug in the mobile app’s log processing, which had been "fully resolved." In a Reddit post, Tangem provided a breakdown of the situation:

What was the issue? When creating a wallet with a seed phrase, the private key was mistakenly logged in the application’s logs. These logs could later be accessed during interactions with our support team.

Tangem got a new update on December 30. Source: Google Play

The Scope of the Vulnerability

According to Tangem’s Reddit post, the bug affected a small group of users, and they are being contacted proactively for caution and support:

It could have affected a very limited group of users: specifically, those who used a generated seedphrase, then immediately submitted a support request through the app. It does not affect any other users.

In a statement sent to Cointelegraph, Tangem confirmed that the vulnerability was limited to fewer than 0.1% of users under specific circumstances:

Only users who activated wallets with a seed phrase and contacted support within seven days of activation were potentially affected. Users without seed phrases or those who did not reach out to support through the app were unaffected.

No Private Keys Were Compromised, No User Funds Lost

Tangem said in the statement that no private keys were compromised, no user funds were lost, and no unauthorized account access occurred:

No private keys were compromised, no user funds were lost, and no unauthorized account access occurred.

This statement was made to address concerns raised by the crypto community about Tangem’s handling of the situation.

Tangem Confirms Permanent Deletion of Logs

Tangem also confirmed in its Reddit response that "all logs and attachments sent to its support team were permanently deleted, ensuring no residual data remains."

Accusations of Downplaying the Situation

While Tangem pushed out an update on December 30 to prevent further leaks of seed phrases, some crypto community members called out the wallet provider’s muted response. However, Tangem told Cointelegraph that it had communicated directly with affected users and handled the issue transparently.

Additional Measures Implemented by Tangem

In response to the issue, Tangem has implemented several additional measures:

  • Enhanced security protocols
  • Proactive outreach program to notify affected users with clear instructions and support
  • Bug bounty program to identify vulnerabilities in exchange for rewards

Conclusion

Tangem’s handling of the situation raises questions about transparency and communication. However, it appears that Tangem has taken steps to address the issue and prevent further leaks.

Related Articles

Subscribe to Our Newsletter

A weekly toolkit that breaks down the latest DeFi developments, offers sharp analysis, and uncovers new financial opportunities to help you make smart decisions with confidence. Delivered every Friday.

By subscribing, you agree to our Terms of Services and Privacy Policy.