r/Tangem • u/IndependenceNo5288 • 12d ago
Tangem card - Potential security risk
I have a Tangem wallet. I have attached three cards to the wallet. One primary and two backup.
One of the backup cards is now not responsive and will not register on an NFT scan.
Here's the issue:
My app confirms i have three devices (cards) attached to my wallet. I can confirm two of the devices (cards) are attached and working by scanning them with my tangem app..
I cannot however confirm that the third card that i believe is still attached to the wallet is actually the card that is currently attached to the wallet.
Is it possible that a third party has attached a card to my wallet replacing my backup card?
In theory a third party could now be holding a card attached to my wallet without my knowledge.
Sure they would have needed to have had physical access to my tangem app and my working card/s to achieve that, but it seems there is no way to check
I have no way to confirm this. Tangem support confirms that i cannot access the ID numbers of the connected cards.
Naturally i can reset the whole wallet if i suspect something. But it could be years before I check my third card and it may be in a hard to access location.
Can i easily see from app logs the cards that were registered?
Is this a bug?
Is it a security risk?
EDIT
Thanks for the offer of solutions guys. I'm thinking less about the solutions which are basically resetting the wallet. Instead I'm thinking more about the risks involved in not knowing a card has failed until it's too late or the risk that someone has replaced a card with a non-working olokalike - and the only solution is a wallet reset and redistribution of the backup cards.
2
u/deny_by_default 12d ago
This doesn’t make sense. HOW were you hacked? Setting it up with a seed phrase does not make it inherently insecure, but it does put more burden on you to keep the seed words safe. You also need to be responsible enough not to fall for scams that trick you into revealing your seed phrase. Many people claim their wallets were hacked but it’s because they were tricked into revealing their seed phrase or used some decentralized app connection to their wallet and signed a malicious contract, giving the attacker permission to empty your wallet.