BPOI Banner
SEC Distributes $4.6 Million to BitClave ICO Investors After Lawsuit SEC Distributes $4.6 Million to BitClave ICO Investors After Lawsuit

Tangem Addresses Security Flaw After Community Backlash

Tangem, a crypto wallet provider, recently identified a significant security risk in its mobile app that inadvertently collected users’ private keys during email interactions.

This fix followed repeated warnings from members who expressed concerns about the potential security risks. They indicated that users’ private keys were collected via email interactions within the Tangem mobile app.

Tangem Users Face Critical Security Risks

On December 29, a discussion on Reddit highlighted a potential security vulnerability in Tangem’s wallet. Users revealed that private keys were being stored in email histories, potentially exposing them to Tangem employees.

A Reddit user known as “u/areklanga” exposed the vulnerability in a forum, sparking community concern.

“So, user private keys remain in both user email history, Tangem email history, and perhaps in some Tangem ticket tracking system and are available for Tangen employees. Which makes all Tangem users compromised,” the user said.

Users also noted that the original Reddit post detailing the glitch was mysteriously deleted, raising suspicions about Tangem’s initial response. As soon as these concerns were validated, users flooded Tangem employees and support via email.

Meanwhile, on December 30, Tangem acknowledged the issue and attributed it to a bug within the mobile app’s log processing function. They issued a statement confirming that they “fully resolved” the bug.

“When creating a wallet with a seed phrase, the private key was mistakenly logged in the application’s logs. These logs could later be accessed during interactions with our support team,” Tangem said in a statement on Reddit.

Tangem clarified that the bug had a limited impact. It affected only users who generated a seed phrase and immediately made a support request. It added that Tangem deleted all of the logs received by the support team. 

Users Accuse Tangem of Downplaying Situation

While Tangem promptly addressed the vulnerability, some members of the crypto community expressed concerns about the company’s communication strategy. Specifically, they criticized the lack of public announcements regarding the vulnerability on Tangem’s official social media platforms.

“I find it frustrating how Tangem is downplaying the scope of this event. While they claim that only a “very small group of users” sent an email with their keys, how many users had their keys written in plain text to their phones in a log file?” said one Reddit user.

At the time of publication on December 31, Tangem had not yet made any official announcements regarding the security risk on its social media channels.

Tangem advised all users to immediately update their mobile applications to the latest version to mitigate potential risks associated with the vulnerability.

Disclaimer

In adherence to the Trust Project guidelines, BeInCrypto is committed to unbiased, transparent reporting. This news article aims to provide accurate, timely information. However, readers are advised to verify facts independently and consult with a professional before making any decisions based on this content. Please note that our Terms and ConditionsPrivacy Policy, and Disclaimers have been updated.

Source link

Camila Grigera Naón

https://beincrypto.com/tangem-addresses-security-risk-after-community-backlash/

2025-01-02 00:50:14

bitcoin
Bitcoin (BTC) $ 95,429.57 2.50%
ethereum
Ethereum (ETH) $ 3,349.41 3.16%
tether
Tether (USDT) $ 1.00 0.24%
xrp
XRP (XRP) $ 2.31 0.28%
bnb
BNB (BNB) $ 693.87 1.89%
solana
Solana (SOL) $ 197.84 4.74%
dogecoin
Dogecoin (DOGE) $ 0.346351 5.04%
usd-coin
USDC (USDC) $ 1.00 0.20%
cardano
Cardano (ADA) $ 0.9728 6.84%
staked-ether
Lido Staked Ether (STETH) $ 3,346.69 3.15%
tron
TRON (TRX) $ 0.252322 2.25%
avalanche-2
Avalanche (AVAX) $ 38.16 6.44%
wrapped-steth
Wrapped stETH (WSTETH) $ 3,994.66 3.78%
sui
Sui (SUI) $ 4.61 5.72%
the-open-network
Toncoin (TON) $ 5.34 2.26%
chainlink
Chainlink (LINK) $ 20.66 6.24%
shiba-inu
Shiba Inu (SHIB) $ 0.000022 4.18%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 95,154.49 2.70%
stellar
Stellar (XLM) $ 0.413529 4.22%
hedera-hashgraph
Hedera (HBAR) $ 0.279744 7.08%
polkadot
Polkadot (DOT) $ 6.84 6.23%
weth
WETH (WETH) $ 3,347.42 3.15%
bitcoin-cash
Bitcoin Cash (BCH) $ 438.17 1.80%
leo-token
LEO Token (LEO) $ 9.01 0.64%
uniswap
Uniswap (UNI) $ 13.23 5.76%
litecoin
Litecoin (LTC) $ 102.74 3.33%
bitget-token
Bitget Token (BGB) $ 6.45 0.80%
pepe
Pepe (PEPE) $ 0.000018 4.83%
hyperliquid
Hyperliquid (HYPE) $ 21.11 13.35%
wrapped-eeth
Wrapped eETH (WEETH) $ 3,538.35 3.14%
near
NEAR Protocol (NEAR) $ 5.14 7.67%
ethena-usde
Ethena USDe (USDE) $ 0.99979 0.12%
usds
USDS (USDS) $ 1.00 0.13%
internet-computer
Internet Computer (ICP) $ 11.18 2.66%
aptos
Aptos (APT) $ 9.10 8.62%
aave
Aave (AAVE) $ 293.88 6.71%
mantle
Mantle (MNT) $ 1.22 4.90%
crypto-com-chain
Cronos (CRO) $ 0.14531 4.41%
render-token
Render (RENDER) $ 7.62 8.94%
polygon-ecosystem-token
POL (ex-MATIC) (POL) $ 0.464189 4.43%
ethereum-classic
Ethereum Classic (ETC) $ 25.49 5.13%
bittensor
Bittensor (TAO) $ 468.89 10.44%
mantra-dao
MANTRA (OM) $ 3.91 0.85%
vechain
VeChain (VET) $ 0.045563 5.38%
whitebit
WhiteBIT Coin (WBT) $ 27.17 4.03%
monero
Monero (XMR) $ 199.02 0.39%
tokenize-xchange
Tokenize Xchange (TKX) $ 43.89 6.07%
fetch-ai
Artificial Superintelligence Alliance (FET) $ 1.33 10.12%
dai
Dai (DAI) $ 1.00 0.25%
virtual-protocol
Virtuals Protocol (VIRTUAL) $ 3.43 12.46%