According to Cointelegraph, cryptocurrency wallet provider Tangem has resolved a significant security flaw in its mobile application that exposed certain users' private keys via email. This action followed repeated alerts from Reddit users who highlighted the risk to investors' funds due to the exposure of private keys to email accounts and Tangem employees.
The issue gained attention on December 29 when a Reddit discussion accused Tangem of misappropriating private keys through emails. A Reddit user, u/areklanga, criticized Tangem for not responding adequately when the problem was initially reported. The user claimed that private keys were stored in user email histories, Tangem's email records, and possibly in Tangem's ticket tracking system, making them accessible to Tangem employees. They also noted that an earlier Reddit post about the glitch was inexplicably removed.
On December 30, Tangem acknowledged the problem, attributing it to a bug in the mobile app's log processing, which has since been "fully resolved." The company explained that the issue occurred when creating a wallet with a seed phrase, where the private key was mistakenly logged in the application's logs. These logs could be accessed during interactions with Tangem's support team. Tangem confirmed that all logs and attachments sent to its support team have been permanently deleted to ensure no residual data remains.
Tangem stated that the bug affected a small group of users, specifically those who generated a seed phrase and immediately submitted a support request through the app. The company is proactively reaching out to these users for caution and support. Despite the update on December 30 to prevent further leaks, members of the crypto community criticized Tangem's subdued response. As of December 31, Tangem had not made any official announcements on its social media channels, including Twitter, Discord, or Telegram. However, all Tangem users are advised to update their mobile applications promptly to prevent seed phrase leaks.