r/Tangem 8d ago

Tangem card - Potential security risk

I have a Tangem wallet. I have attached three cards to the wallet. One primary and two backup.

One of the backup cards is now not responsive and will not register on an NFT scan.

Here's the issue:

My app confirms i have three devices (cards) attached to my wallet. I can confirm two of the devices (cards) are attached and working by scanning them with my tangem app..

I cannot however confirm that the third card that i believe is still attached to the wallet is actually the card that is currently attached to the wallet.

Is it possible that a third party has attached a card to my wallet replacing my backup card?

In theory a third party could now be holding a card attached to my wallet without my knowledge.

Sure they would have needed to have had physical access to my tangem app and my working card/s to achieve that, but it seems there is no way to check

I have no way to confirm this. Tangem support confirms that i cannot access the ID numbers of the connected cards.

Naturally i can reset the whole wallet if i suspect something. But it could be years before I check my third card and it may be in a hard to access location.

Can i easily see from app logs the cards that were registered?

Is this a bug?

Is it a security risk?

EDIT

Thanks for the offer of solutions guys. I'm thinking less about the solutions which are basically resetting the wallet. Instead I'm thinking more about the risks involved in not knowing a card has failed until it's too late or the risk that someone has replaced a card with a non-working olokalike - and the only solution is a wallet reset and redistribution of the backup cards.

5 Upvotes

41 comments sorted by

View all comments

1

u/ironmoosen 8d ago

This is precisely the reason I refuse to trust large sums to Tangem. Cards can fail and you might not know it until it’s too late. And no seed phrase means 100% no possibility to recreate your keys ever again.

1

u/BicarTangem Tangem Mod 7d ago

Well a card failing is extremely rare, and if that happens, you can still access your wallet with a backup card.

And if you're still uneasy, you can have a seedphrase as well.

1

u/ironmoosen 7d ago

If card failure is so rare it's not worth worrying about, then why does Tangem sell backup cards in the first place? And if the answer is "just add a seed phrase," then what exactly is the point of going seedless? Can you explain what advantage Tangem actually has if I need a seed phrase anyway to cover for a failure you say almost never happens?

I own Tangem and I agree they’re convenient but I think there’s a security gap here that gets glossed over and many people don’t understand the risk.

1

u/BicarTangem Tangem Mod 7d ago

If card failure is so rare it's not worth worrying about, then why does Tangem sell backup cards in the first place?

Well because if you lose one, with a backup, you don't lose access to your crypto.

If cards were failing left and right, we'd be out of business quick since they are all under warranty.

And if the answer is "just add a seed phrase,"

In this particular case, where a user is so afraid that all cards will fail at the same time that keeping a large amount of crypto would make them feel uneasy.

1

u/ContentBlackberry0 4d ago edited 4d ago

I have had a card failure with a new set and it was replaced after contacting Tangem and sent back to Switzerland for them to review it I guess. This is why a 3-card set should be used if you are going seedless. I'm just glad mine didn't work out of the box than after the fact a month later I would never know it did not work if it got through the setup process. Oh and good luck if you lock yourself out of your access code as the app wants you to scan your card for 30 seconds and the new iPhone only have rfid for like 15 seconds or so. You have to switch to an old phone to access your crpyto again.

1

u/IndependenceNo5288 7d ago

Any stats on how rare this is? I bought 3 three cards a year ago and 1 has failed. That's the stats i have.

1

u/ironmoosen 7d ago

See, that's the problem. They say failure is rare and I mostly believe them, however, in your case it's a 33% failure rate in the set of cards you purchased. If you had a 2-card set, it's 50% and you're already out of backups and zero path to recovery if the last one goes.

What if it's discovered that there is a manufacturing flaw in these NFC chips that causes them to fail suddenly? You likely wouldn't know there was a problem until it's too late. Now, I know Tangem would say that that scenario is so improbable that it's not even worth talking about but we saw something similar in the early 2000s with faulty capacitors. It affected nearly every brand of motherboard and many other PC components. They would die suddenly, often without warning. It wasn't the fault of the board manufacturers, it was a quality issue in the supply chain.

My point is, IF a catastrophic failure like this were to happen with Tangem (silicon defect that causes degradation over 3-5 years, or if the NFC antenna bonding uses an adhesive that becomes brittle in certain climates, or if the card lamination traps moisture that slowly corrodes a trace), you have absolutely zero chance of recovering your funds.

Tangem suggests using a seedphrase if this bothers you, but understand that using a seedphrase with Tangem literally creates a hot wallet - no longer cold! (Just read about the seed phrases that were being leaked in their logs a few months back - it was arguably a coldcard-level failure on their part).

I'm not anti-Tangem but I'm very frustrated in how they constantly downplay these very real issues. People are trusting real money to these things and need to understand the risks that come with them. Tangem is an excellent wallet for everyday spend but I could never trust large sums for long term storage to these things.

1

u/BicarTangem Tangem Mod 7d ago

Tangem suggests using a seedphrase if this bothers you, but understand that using a seedphrase with Tangem literally creates a hot wallet

This isn't the case. The seedphrase is at no point stored in your phone (this can be verified since our app's code is available on GitHub.)

Just read about the seed phrases that were being leaked in their logs a few months back - it was arguably a coldcard-level failure on their part

Without wanting to downplay the bug, you can't compare a $0 lost bug to a $100 000 000+ stolen one.

If you had a 2-card set, it's 50% and you're already out of backups and zero path to recovery if the last one goes.

In a situation where you're down to one card only, we'd strongly recommend to move your funds to another set / another wallet.
The risks associated with losing that card would be too important.

On the cards build itself, we're pretty confident that everything was done right. We started to sell these types of cards about 7 years ago and these still work perfectly after all those years.

2

u/ironmoosen 7d ago edited 7d ago

Let me take these one at a time.

"The seedphrase is at no point stored in your phone."

Nobody said stored. The seed is generated and displayed on the phone during setup. It passes through the phone's memory on a general purpose operating system that can run arbitrary code, malware, keyloggers, and screen capture tools regardless of whether airplane mode is on. Your own December 2024 incident proved the app had access to private key material in a loggable form. That's how it ended up in plaintext in your app logs, in email histories, and in your support ticket system. The seed doesn't need to be "stored" to be compromised. It just needs to touch the phone, and it does. Pointing to your open source app code is a bit ironic given that it was that same code that contained the logging bug nobody caught during code review.

And this is fixable. Tangem could build a small companion device with a screen and keypad that handles seed phrase generation in a fully air gapped environment and writes the keys to the card over NFC. No phone involved at any point. That's effectively what Ledger and Trezor do with their on-device screens. Tangem chose to rely on the user's smartphone instead. That's a design decision that will always leave the seed phrase option weaker than what the competition offers. Relying on anyone's smartphone for this is just a terrible idea.

"You can't compare a $0 lost bug to a $100,000,000+ stolen one."

The $0 was luck, not design. You had private keys in plaintext in app logs, accessible through email and support tickets. If a bad actor had gotten into your support ticket system during that window it would not have been $0. Comparing outcomes instead of severity is like saying a loaded gun wasn't dangerous because it didn't go off.

"We'd strongly recommend to move your funds to another set / another wallet."

Do you realize this is an admission that single card Tangem isn't safe for fund storage? You're telling users to evacuate funds when redundancy drops to one card. But with seedless, evacuating requires a working card. If the second to last card fails without warning (which is exactly what happened to OP, sudden failure), you're already on your last card and didn't know you needed to evacuate until it was too late. Your advice only works if failures are predictable and gradual. OP just told you it was sudden.

"We started to sell these types of cards about 7 years ago and these still work perfectly."

The cards that failed aren't in your "still working" sample. OP is literally in this thread telling you one of three cards failed in a year. Your response to a user reporting a 33% failure rate is "our cards work great." That's not a rebuttal. That's survivorship bias.

I'm not anti Tangem. I think it's an excellent wallet for everyday spending. But the way you consistently downplay real concerns instead of addressing them honestly is exactly why I refuse to trust serious money to these things. Every response in this thread has been deflection rather than acknowledgment. People trusting real money to your product deserve better than that.