Trading Education Platform SystemSubscribe for FreeSupport
Wallets / Tangem Wallet
HARDWARE WALLET REALITY CHECK · READ 11 OCT 2026

Tangem Wallet: what the sources say

Current 1 disclosed weakness 1 company incident 1 not fixed per source

Key facts

The questions, with sources

QuestionWhat the sources saySource
Status
Current — Tangem Wallet card sets (2- and 3-card) are listed on the official site on 2026-10-11 alongside Tangem Ring, Tangem Pay and Tangem Mobile. Two card generations exist: Tangem 1.0 and Tangem 2.0 (launched Sept 2023, adds optional seed phrase, import, passphrase).
Company
Tangem AG, Switzerland
List price
$54.90 — Official pricing page shows USD only: 2-card set $54.90, 3-card set $69.90 (home page meta text says 'From $55.90'). Price per set; no 1-card set listed. Each card in a set holds the same key (backup). Prices 'in your currency' per page; EUR not displayed to our fetch.
Secure element
Yes: Samsung Semiconductor secure element (S3D232A per Hacker News report); EAL6+ (maker claim; chip developed with Samsung Semiconductor)
Firmware code
Not verified; reproducible build: not verified. Tangem states its GitHub holds full open-source code for the Android and iOS apps. Whether the card firmware is open source was not stated.
Companion app
Yes. Tangem states the GitHub repository holds the full open-source code for Android and iOS apps, plus APK; license not named on pages read.
Connections
USB: no. Bluetooth: no. NFC: yes. QR: no. microSD: no.
Screen
None (card); touch: no
Assets
14,100+ tokens across 90+ blockchains (home page); a March 2026 post says 16,000+ cryptocurrencies and tokens across 87+ networks; Bitcoin-only option: no (not mentioned)
Multisig and PSBT
Not verified. Not mentioned on pages read.
—
Passphrase
Yes. Per May 2024 blog, passphrase can be used when importing a seed phrase (Tangem 2.0 cards); creating a new wallet with a passphrase was not yet supported at that date. Current status not re-verified.
Shamir backup (SLIP-39)
No. Not mentioned; backup is by identical cards in the set.
Recovery phrase standard
Optional: default key generated on-chip with no seed phrase; seed phrase (12/15/18/21/24 words) can be generated in-app or imported (2.0 cards)
Optional recovery service
None. Backup via additional cards (2- or 3-card set); no paid recovery service found. Access code reset requires two cards from the set; recovery can be disabled on 2.0.
FIDO / passkeys
Not verified. Not mentioned.
—
Bug bounty
Yes
Warranty
Home page states a 25-year limited hardware warranty; terms not read.
—

"n/v" or "not verified" means we could not confirm it from a source we could read. Maker claims are marked as such. Confirm on the maker's site before you buy. Education only, not investment advice.

Summary

Five facts

  • Tangem Wallet is sold as a set of 2 or 3 NFC cards that each hold the same key, listed at $54.90 and $69.90 on the official pricing page [source 1][source 8].
  • The card uses a Samsung secure element that Tangem describes as EAL6+ certified [source 3].
  • Tangem lists audits by Cure53 (2026-03, mobile wallet), Riscure (2023-12, hardware wallet and firmware) and Kudelski Security (2018, smartcard code) [source 4].
  • In July 2026 Ledger Donjon disclosed a physical laser fault-injection attack that can reset a card's access code; Tangem says cards cannot be patched and calls the attack lab-only [source 13][source 14].
  • In December 2024 a Tangem app bug logged private keys of seed-phrase wallets in support logs; Tangem fixed it on 2024-12-30 and states no funds were lost [source 11].
Independent checks

Audits

  • 2026-03 Cure53. Scope: Mobile wallet (iOS / Android) source
  • 2023-12 Riscure. Scope: Mobile hardware wallet and firmware: secure element usage, firmware integrity, wallet architecture source
  • 2018-12 Kudelski Security. Scope: Smartcard code (older than 5 years) source
Device record

Publicly disclosed weaknesses

  • 2026-07 Ledger Donjon (security team of Ledger, a competing wallet maker) reported to Tangem on 2026-02-10 a laser fault-injection attack on the card's Samsung secure element that bypasses the recovery-mode check so a new access code can be set without the old code or a second card. Requires physical possession, decapsulation and lab equipment (Donjon estimates about $250,000 lab, about two hours per card). Tangem states cards cannot be firmware-updated, so existing cards are not patched; Tangem calls it lab-only, affecting secure elements generally, and states no known real-world losses. Funds lost: no. Not fixed (as of the source) source

Disclosed weaknesses are listed whatever their severity. "Funds lost" is what the sources say. "Fixed" means the source states a fix exists, which only helps if you update.

Company record

Incidents at the maker or its service providers

  • 2024-12 Tangem mobile app logged the private key when a wallet was activated with a seed phrase; logs could be seen by support if the user contacted support via the app within 7 days. Reported on Reddit 2024-12-29; Tangem fixed in app versions 5.19.1 (iOS) / 5.19.2 (Android) on 2024-12-30 and erased support logs. Customer funds lost: no. Outcome: Tangem states fewer than 0.1% of users could be affected and no funds lost; critics said the company downplayed it (Cointelegraph). Affected users advised to move funds to a new wallet. source

These affect the company or its customers and apply to every device of the brand. They are not weaknesses of this device.

Questions

Questions about Tangem Wallet

Is Tangem Wallet safe?

We do not give a yes or no, because safety depends on what you need to protect and on facts that change. We found 1 publicly disclosed weakness, 1 of them not fixed according to the source and 1 company incident in our search. Read the sources above before you buy.

Does Tangem Wallet need an internet connection?

Signing happens on the device. How the device talks to your phone or computer depends on its connections: NFC. The companion app or software that builds the transaction is online.

Who found the weaknesses listed for Tangem Wallet?

The page names who disclosed each one when the source does. Several were found by a competing maker's research team or by independent security firms. We cite the affected company's own statement where we found one, and label press-only reports.

Sources

Where this comes from

Not verified: EUR price not displayed (USD only). Card firmware open-source status, multisig, passkeys, current passphrase-on-create status not verified. Audit PDFs not read (summary page only). EAL6+ and Samsung chip are maker claims. Which card generations are affected by the laser attack not stated. Donjon article itself not read (via press report and Tangem reply).

See how we check. To report an error, use corrections and right of reply.