Tangem Addresses Security Flaw After Community Backlash

Source Beincrypto

Tangem, a crypto wallet provider, recently identified a significant security risk in its mobile app that inadvertently collected users’ private keys during email interactions.

This fix followed repeated warnings from members who expressed concerns about the potential security risks. They indicated that users’ private keys were collected via email interactions within the Tangem mobile app.

Tangem Users Face Critical Security Risks

On December 29, a discussion on Reddit highlighted a potential security vulnerability in Tangem’s wallet. Users revealed that private keys were being stored in email histories, potentially exposing them to Tangem employees.

A Reddit user known as “u/areklanga” exposed the vulnerability in a forum, sparking community concern.

“So, user private keys remain in both user email history, Tangem email history, and perhaps in some Tangem ticket tracking system and are available for Tangen employees. Which makes all Tangem users compromised,” the user said.

Users also noted that the original Reddit post detailing the glitch was mysteriously deleted, raising suspicions about Tangem’s initial response. As soon as these concerns were validated, users flooded Tangem employees and support via email.

Meanwhile, on December 30, Tangem acknowledged the issue and attributed it to a bug within the mobile app’s log processing function. They issued a statement confirming that they “fully resolved” the bug.

“When creating a wallet with a seed phrase, the private key was mistakenly logged in the application’s logs. These logs could later be accessed during interactions with our support team,” Tangem said in a statement on Reddit.

Tangem clarified that the bug had a limited impact. It affected only users who generated a seed phrase and immediately made a support request. It added that Tangem deleted all of the logs received by the support team. 

Users Accuse Tangem of Downplaying Situation

While Tangem promptly addressed the vulnerability, some members of the crypto community expressed concerns about the company’s communication strategy. Specifically, they criticized the lack of public announcements regarding the vulnerability on Tangem’s official social media platforms.

“I find it frustrating how Tangem is downplaying the scope of this event. While they claim that only a “very small group of users” sent an email with their keys, how many users had their keys written in plain text to their phones in a log file?” said one Reddit user.

At the time of publication on December 31, Tangem had not yet made any official announcements regarding the security risk on its social media channels.

Tangem advised all users to immediately update their mobile applications to the latest version to mitigate potential risks associated with the vulnerability.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
XRP Price Prediction: Ripple Rally Expected but Altcoin Dubbed the ‘Next XRP’ Set for 5800% GainsThe crypto market is aiming for a rebound in early 2025 after a turbulent end to 2024. Ripple (XRP) is now making some waves in this environment. Its value is rising on the charts. Even some market analysts like XRP Whale have made a bullish price prediction for this altcoin.
Author  Cryptopolitan
Yesterday 12: 55
The crypto market is aiming for a rebound in early 2025 after a turbulent end to 2024. Ripple (XRP) is now making some waves in this environment. Its value is rising on the charts. Even some market analysts like XRP Whale have made a bullish price prediction for this altcoin.
placeholder
Tesla Just Did Something It Has Never Done BeforeIn this video, I will talk about Tesla (NASDAQ: TSLA) and explain why the stock started the year on the wrong foot. Watch the short video to learn more, consider subscribing, and click the special offer link below.
Author  The Motley Fool
Yesterday 12: 53
In this video, I will talk about Tesla (NASDAQ: TSLA) and explain why the stock started the year on the wrong foot. Watch the short video to learn more, consider subscribing, and click the special offer link below.
placeholder
Opinion: Bitcoin price predictions for 2025 shouldn’t be trustedWe are barely 3 days into the year, and Bitcoin’s price predictions have already flooded the crypto space. Several industry veterans, analysts, prominent business people – everyone seems to have their forecast for the leading cryptocurrency’s future. But should these predictions be taken seriously? The short answer: NO.
Author  Cryptopolitan
Yesterday 12: 52
We are barely 3 days into the year, and Bitcoin’s price predictions have already flooded the crypto space. Several industry veterans, analysts, prominent business people – everyone seems to have their forecast for the leading cryptocurrency’s future. But should these predictions be taken seriously? The short answer: NO.
placeholder
PBoC: Will cut RRR and interest rates at proper timeThe People's Bank of China's (PBoC) Monetary Policy Committee said on Friday that they will cut the reserve ratio requirements (RRR) and interest rates at proper time, per Reuters.
Author  FXStreet
Yesterday 12: 51
The People's Bank of China's (PBoC) Monetary Policy Committee said on Friday that they will cut the reserve ratio requirements (RRR) and interest rates at proper time, per Reuters.
placeholder
Here's Why Boeing Stock Gained Back Ground in DecemberBoeing (NYSE: BA) stock rose by 13.9% in December, according to data provided by S&P Global Market Intelligence. The move put a little shine on a disappointing year for the company and comes down to some positive news for Boeing.
Author  The Motley Fool
Yesterday 12: 49
Boeing (NYSE: BA) stock rose by 13.9% in December, according to data provided by S&P Global Market Intelligence. The move put a little shine on a disappointing year for the company and comes down to some positive news for Boeing.
goTop
quote