In a concerning incident for cryptocurrency users, Tangem Wallet has acknowledged a significant security vulnerability that inadvertently exposed users' private keys through an email glitch. The issue, which was brought to light by users on Reddit, has raised alarms about the safety of funds held in the wallet.
Key Takeaways
-
Tangem Wallet experienced a bug that logged users' private keys in emails.
-
The company has since fixed the issue and deleted all related logs.
-
Users are urged to update their apps immediately to prevent further risks.
Overview Of The Incident
On December 30, 2023, Tangem Wallet confirmed that a bug in its mobile application had led to the collection of users' private keys via email communications. This vulnerability was first highlighted in a Reddit discussion, where users expressed their concerns about the potential risks to their funds. The glitch allowed private keys to be logged in both user email histories and Tangem's internal systems, raising fears of unauthorized access by employees.
User Reactions And Concerns
The revelation of this security flaw sparked outrage within the cryptocurrency community. Users criticized Tangem for its lack of transparency and a muted response to the serious allegations. One Reddit user noted that the private keys could be accessible not only to Tangem employees but also through various email histories, compromising the security of all users.
Tangem's Response
In response to the growing concerns, Tangem issued a statement acknowledging the bug and detailing the nature of the issue. The company explained that the private keys were mistakenly logged during the wallet creation process and that these logs could be accessed by support staff during user interactions. Tangem assured users that all logs and attachments related to the incident had been permanently deleted to eliminate any residual data.
Impact On Users
Tangem emphasized that the bug affected only a limited number of users—specifically those who generated a seed phrase and subsequently submitted a support request through the app. The company has proactively reached out to these users to provide guidance and support. Despite the fix, many in the crypto community remain skeptical about Tangem's handling of the situation, particularly due to the absence of announcements on their official social media channels.
Recommendations For Users
To mitigate any potential risks, Tangem has urged all users to update their mobile applications immediately. This update is crucial to ensure that no further leaks of seed phrases occur. Users are also advised to review their security practices and consider changing their private keys if they suspect any compromise.