Crypto wallet provider Tangem has recently addressed a significant security vulnerability in its mobile app that inadvertently collected users' private keys via email interactions.
Crypto wallet provider Tangem has recently addressed a significant security vulnerability in its mobile app that inadvertently collected users' private keys via email interactions.
A Reddit user, identified as u/areklanga, claimed that the problem allowed private keys to remain accessible in both user and Tangem email histories, as well as in a ticket tracking system. This raised concerns among the community, leading to accusations that Tangem had not adequately responded to the allegations when they were first raised. The user also noted that the original post detailing the glitch had been deleted.
The company stated that when users created a wallet with a seed phrase, the private key was logged mistakenly. This log could be accessed during support interactions, posing a risk to user security.
Tangem asserted that the bug affected a limited number of users—specifically those who generated a seed phrase and immediately submitted a support request. The company confirmed that all logs and attachments sent to its support team have been permanently deleted to ensure no residual data remains.
Despite the prompt action to resolve the issue, some members of the crypto community criticized Tangem for its muted response, noting that the company had not made announcements on its social media platforms regarding the vulnerability.