Bitcoin Forum
July 02, 2025, 03:53:33 AM *
News: Latest Bitcoin Core release: 29.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Tangem Wallet - Apparent issues with seed phrase wallets  (Read 227 times)
MoparMiningLLC (OP)
aka Stryfe
Legendary
*
Online Online

Activity: 2492
Merit: 2746


EIN: 82-3893490


View Profile WWW
December 31, 2024, 08:55:35 AM
Merited by klarki (2), dkbit98 (1), Hox (1)
 #1

I need to - or others can as well - do more research but I wanted to share this as I just saw it.

https://www.reddit.com/r/Tangem/comments/1hq6hyj/if_you_have_a_tangem_wallet_with_a_seed_phrase/

https://www.reddit.com/r/Tangem/comments/1hpj4p2/tangem_come_clean_on_what_happened_with_seed/

https://www.reddit.com/r/Tangem/comments/1hqaj8h/private_key_leak_ios_only_or_android_too/

https://www.reddit.com/r/Tangem/comments/1hpyjjp/just_saw_another_commit_regarding_the_private_key/

Mine BTC @ kano.is
Offering escrow services https://bitcointalk.org/index.php?topic=5154480
All Bitcoin 3D printing needs at CryptoCloaks
_act_
Legendary
*
Offline Offline

Activity: 1302
Merit: 1505


They are not altcoins, they are shit coins.


View Profile
December 31, 2024, 09:05:43 AM
 #2

The last time I do research about Tangenm wallet, it is a hardware wallet. What if the users that were affect have huge amount on the wallet, thinking that it is a hardware wallet, which is secure than those software wallet that are always connected online. Their coins can be gone in just some seconds or few minutes. This has been one of the reasons I prefer wallet on airgapped devices. I remember in the past that common hardware wallets like Trezor and the now non-recommended Ledger Nano suffer some security breached in the past.

.
 MΞTAWIN 
▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
 
 THE FIRST WEB3 CASINO 
▄▄██▀███▀███▄▄
████░░▀░▄█████
▄█████░█▄▀█░█████▄
███████▀░▄░░██████
▐███████▄███▄██████▌
███████████████
███████████████
███████████
█████████
▀█████████████▀
▀█
██████████▀
██
███████████
▄████████████████████▄
████
██
██
██
██
██
██
██
██
██
██
██
████
███████████
▄███████████████████▄
█████████████████████
████▄░▄░███████▀▄████
█████▄▀█▄▀███▀▄██████
███████░██░▀▄████████
████████▄▀█▄▀████████
████████▀▄▀██░███████
██████▀▄███░██▄▀█████
████▀▄██████▄▀▀░▀████

█████████████████████
▀███████████████████▀
        █████
▄███████████████████▄
█████████████████████
███████████████▀▀████
███████████▀▀░░░░████
███████▀▀░░▄▄▀░░▐████
████▀░░░▄██▀░░░░█████
███████░█▀░░░░░▐█████
████████░░▄▄░░░██████
██████████████▄██████

█████████████████████
▀███████████████████▀
███████████
████
██
██
██
██
██
██
██
██
██
██
██
████
 
. PLAY NOW .
Hox
Sr. Member
****
Offline Offline

Activity: 837
Merit: 320



View Profile WWW
December 31, 2024, 09:39:33 AM
 #3

Interesting. It sounds like they were logging the seed phrase on setup. I don't know why they would do this in the first place. Then when submitting a support request these logs were sent, leaking the seed.

I recently got the tangem ring and when setting it up it does warn that using a seed phrase is significantly less secure, but this is another thing entirely. Its a shame, they made some interesting products. I am only interested in collecting and never intended to use them as a wallet, but it sucks to see a company who made such nice hardware make silly software decisions like this.

Coin.Community    
   A place for cryptocurrency collectors and artists.
Discover on the Coin Wiki. See all my coins for sale: Kialara, Casascius, Finite by Design, Satori coin and more.
MoparMiningLLC (OP)
aka Stryfe
Legendary
*
Online Online

Activity: 2492
Merit: 2746


EIN: 82-3893490


View Profile WWW
December 31, 2024, 09:54:55 AM
 #4

Interesting. It sounds like they were logging the seed phrase on setup. I don't know why they would do this in the first place. Then when submitting a support request these logs were sent, leaking the seed.

I recently got the tangem ring and when setting it up it does warn that using a seed phrase is significantly less secure, but this is another thing entirely. Its a shame, they made some interesting products. I am only interested in collecting and never intended to use them as a wallet, but it sucks to see a company who made such nice hardware make silly software decisions like this.

I agree - I have used a few of them to test em out, play with etc but I never leave funds on a hot wallet. The only 2 hot wallets I use are Strike (easy conversion of fiat job pay and zero fee sending) and Balletcrypto pro wallet (no risk if wallet is taken as requires a passphrase only the user knows).  Cold storage is non-hardware wallet - total airgap - offline etc

Mine BTC @ kano.is
Offering escrow services https://bitcointalk.org/index.php?topic=5154480
All Bitcoin 3D printing needs at CryptoCloaks
owlcatz
Legendary
*
Offline Offline

Activity: 4018
Merit: 2025

https://icarus-cards.eu


View Profile WWW
January 01, 2025, 01:58:44 AM
 #5

Interesting - I have a couple of these - one fairly older one and a newer one, but never really messed with either... I thought they had NFC or maybe that was a different one.
MoparMiningLLC (OP)
aka Stryfe
Legendary
*
Online Online

Activity: 2492
Merit: 2746


EIN: 82-3893490


View Profile WWW
January 01, 2025, 03:30:07 AM
 #6

this appears to be only affecting the wallets that used "seed generation" something about if a person used the app to file a ticket or w/e it would send the seed to Tangem who then would send it back via email as an attachment or some crazy thing like that. There are a dozen threads on reddit over the past 2 days about it. Hard to know for sure what is correct or what is not. This appears to be only affecting the new ones. But  I could be wrong.

Mine BTC @ kano.is
Offering escrow services https://bitcointalk.org/index.php?topic=5154480
All Bitcoin 3D printing needs at CryptoCloaks
owlcatz
Legendary
*
Offline Offline

Activity: 4018
Merit: 2025

https://icarus-cards.eu


View Profile WWW
January 01, 2025, 03:57:06 AM
 #7

this appears to be only affecting the wallets that used "seed generation" something about if a person used the app to file a ticket or w/e it would send the seed to Tangem who then would send it back via email as an attachment or some crazy thing like that. There are a dozen threads on reddit over the past 2 days about it. Hard to know for sure what is correct or what is not. This appears to be only affecting the new ones. But  I could be wrong.

Oh shit, thanks man. Maybe I'm just better off not reading it at all, since I haven't funded any, I just thought one or two were cool at some point, and the other older one was from @Chib long ago. The older one is a bit different, I'll have to find it and probaly send to mj for auction anyhow.. Tongue

dkbit98
Legendary
*
Offline Offline

Activity: 2646
Merit: 8100


⚡⚡ Availa₿le ⚡⚡


View Profile WWW
January 02, 2025, 07:48:32 PM
 #8

this appears to be only affecting the wallets that used "seed generation" something about if a person used the app to file a ticket or w/e it would send the seed to Tangem who then would send it back via email as an attachment or some crazy thing like that. There are a dozen threads on reddit over the past 2 days about it. Hard to know for sure what is correct or what is not. This appears to be only affecting the new ones. But  I could be wrong.
It's concerning to see how they are mostly ignoring this huge issue and they continue to make celebration posts on their social media and telegram group.
Even their website is not showing anything about this, unless you go to their blog post from December 31.
They are blaming everything on NFC logging mechanism for their app, and they are telling customers to go switch to seedless setup.
I can only imagine what would happen in that case if Tangem goes bankrupt and shuts down  Roll Eyes
Much better alternative for Tangem is Satochip.

Stay away from all devices and hardware wallets that are not open source.

▄███████████████████▄
████████████████████████

██████████▀▀▀▀██████████
███████████████▀▀███████
█████████▄▄███▄▄█████
████████▀▀████▀███████
█████████▄▄██▀██████████
████████████▄███████████
██████████████▄█████████
██████████▀▀███▀▀███████
███████████████████████
█████████▄▄████▄▄████████
▀███████████████████▀
.
 BC.GAME 
███████████████
███████████████
███████████████
███████████████
██████▀░▀██████
████▀░░░░░▀████
███░░░░░░░░░███
███▄░░▄░▄░░▄███
█████▀░░░▀█████

███████████████

███████████████

███████████████

███████████████
███████████████
███████████████
███████████████
███████████████
███░░▀░░░▀░░███
███░░▄▄▄░░▄████
███▄▄█▀░░▄█████
█████▀░░▐██████
█████░░░░██████

███████████████

███████████████

███████████████

███████████████
███████████████
███████████████
███████████████
███████████████
██████▀▀░▀▄░███
████▀░░▄░▄░▀███
███▀░░▀▄▀▄░▄███
███▄░░▀░▀░▄████
███░▀▄░▄▄██████

███████████████

███████████████

███████████████

███████████████

DEPOSIT BONUS
.1000%.
GET FREE
...5 BTC...

REFER & EARN
..$1000 + 15%..
COMMISSION


 Play Now 
DaveF
Legendary
*
Offline Offline

Activity: 3892
Merit: 6871


Wheel of Whales 🐳


View Profile WWW
January 03, 2025, 04:08:45 PM
 #9

Being discussed here too: https://bitcointalk.org/index.php?topic=5524810

Dave's opinion (and remember what they say about opinions, they are like buttholes everyone has one and most stink): It's not that big a deal. A major screw up for sure, but not something wt over.

For the compromise to happen you would have to create a wallet with a seed (which they advice against) and then do something that involves having your logs sent to them. Before they were overwritten or purged. At a 1000% guess they had the seed shown in the log for testing and someone forgot to turn that off. The logs were in a location on your phone that the Tangem app should have been the only app that had access to. Because:

If you have other things on your phone that are snooping on other logs and reading / scanning / sending that info to malicious people you have many many many larger issues. Since the info was in a location that only the Tangem app should have access to.

However, and this is just me. Most people who use Tangem products have the card in their wallet or the ring on their finger. You know, right next to the phone that has the app. It's a nice layer of security but not as good as having a hardware wallet locked in a safe that nobody knows about.

-Dave


███████████▄
████████▄▄██
█████████▀█
███████████▄███████▄
█████▄█▄██████████████
████▄█▀▄░█████▄████████
████▄███░████████████▀
████░█████░█████▀▄▄▄▄▄
█████░█
██░█████████▀▀
░▄█▀
███░░▀▀▀██████
▀███████▄█▀▀▀██████▀
░░████▄▀░▀▀▀▀████▀
 

█████████████████████████
████████████▀░░░▀▀▀▀█████
█████████▀▀▀█▄░░░░░░░████
████▀▀░░░░░░░█▄░▄░░░▐████
████▌░░░░▄░░░▐████░░▐███
█████░░░▄██▄░░██▀░░░█████
█████▌░░▀██▀░░▐▌░░░▐█████
██████░░░░▀░░░░█░░░▐█████
██████▌░░░░░░░░▐█▄▄██████
███████▄░░▄▄▄████████████
█████████████████████████

█████████████████████████
████████▀▀░░░░░▀▀████████
██████░░▄██▄░▄██▄░░██████
█████░░████▀░▀████░░█████
████░░░░▀▀░░░░░▀▀░░░░████
████░░▄██░░░░░░░██▄░░████
████░░████░░░░░████░░████
█████░░▀▀░▄███▄░▀▀░░████
██████░░░░▀███▀░░░░██████
████████▄▄░░░░░▄▄████████
█████████████████████████
.
...SOL.....USDT...
...FAST PAYOUTS...
...BTC...
...TON...
MoparMiningLLC (OP)
aka Stryfe
Legendary
*
Online Online

Activity: 2492
Merit: 2746


EIN: 82-3893490


View Profile WWW
January 03, 2025, 04:37:41 PM
 #10

yea - I was reading that this morning - about the slim possibility due to the circumstances needed in order for your key to be exposed. And I agree that while it is a huge fuck up - it could have been much worse.


This is what makes any wallet hard to trust though.

Mine BTC @ kano.is
Offering escrow services https://bitcointalk.org/index.php?topic=5154480
All Bitcoin 3D printing needs at CryptoCloaks
krogothmanhattan
Cypher Hodl LLC
Legendary
*
Offline Offline

Activity: 2940
Merit: 4079


The Stone the masons rejected was the cornerstone.


View Profile WWW
January 03, 2025, 05:06:09 PM
 #11

  Bought Tangem when they first came out years ago....still sealed inside the envelope they came in. Only as a collectable and thats it.

  I mainly use Paper wallets I generate and Trezor. Been very happy with both.

██████▄██▄███████████▄█▄
█████▄█████▄████▄▄▄█
███████████████████
████▐███████████████████
███████████▀▀▄▄▄▄███████
██▄███████▄▀███▀█▀▀█▄▄▄█
▀██████████▄█████▄▄█████▀██
██████████▄████▀██▄▀▀▀█████▄
█████████████▐█▄▀▄███▀██▄
███████▄▄▄███▌▌█▄▀▀███████▄
▀▀▀███████████▌██▀▀▀▀▀█▄▄▄████▀
███████▀▀██████▄▄██▄▄▄▄███▀▀
████████████▀▀▀██████████
 BETFURY ....█████████████
███████████████
███████████████
██▀▀▀▀█▀▀▄░▄███
█▄░░░░░██▌▐████
█████▌▐██▌▐████
███▀▀░▀█▀░░▀███
██░▄▀░█░▄▀░░░██
██░░░░█░░░░░░██
███▄░░▄█▄░░▄███
███████████████
███████████████
░░█████████████
█████████████
███████████████
███████████████
██▀▄▄▄▄▄▄▄▄████
██░█▀░░░░░░░▀██
██░█░▀░▄░▄░░░██
██░█░░█████░░██
██░█░░▀███▀░░██
██░█░░░░▀░░▄░██
████▄░░░░░░░▄██
███████████████
███████████████
░░█████████████
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!