Firmware & Authenticity
How can I be sure that I bought an authentic wallet?
The wallet cannot be modified from a software or physical standpoint because it contains a monolithic chip inside.
When scanning the wallet, the Tangem app can accurately verify:
— that Tangem actually produced the wallet.
— that the wallet contains the Tangem firmware.
The Tangem app verifies the authenticity of both the chip and the firmware, providing adequate protection against counterfeiting. Thanks to this technology, it is entirely safe to buy anywhere.
The main points are:
1. You have installed the official Tangem app.
2. The device should prompt you to create a wallet; if they do not, reset them to factory settings.
Find more information in the blog: How to Tell If Your Tangem Wallet Is Authentic.
How do I confirm that I have received a wallet not used by anyone before?
When activated, you should see a prompt to create a wallet. If not, reset the device to factory settings and then create a wallet. Resetting the wallet completely erases its contents and deletes any keys. After this, new public and private keys can be generated.
How do I verify the authenticity of the Tangem firmware?
Tangem employs a "security through obscurity" approach. Revealing the source code would expose its hardware wallets to vulnerabilities.
To prove that the Tangem firmware does not have backdoors or bugs that could lead to loss of funds, we went through two independent audits of the Tangem firmware. The first audit was conducted in 2018 by the Swiss company Kudelski Security, and the second in 2023 by the international security laboratory Riscure.
Both audits confirmed the integrity of our system, establishing that the private key was generated using a hardware random number generator and that there were no backdoors or bugs that could lead to the loss of funds.
You can read the detailed reports of both audits. Kudelski Security's audit results are available here, and information about the second audit conducted by Riscure can be found here.
Can the wallet's firmware be updated?
The Tangem firmware is downloaded into the chip once and cannot be updated again. This eliminates the risk of installing malware and possible theft of funds. Updating a hardware wallet's firmware means that you will have to trust the wallet manufacturer and hope that, at some point, you won't receive an update that compromises your keys.
Tangem's firmware has undergone two independent audits from Kudelski Security and Riscure. Both audits confirmed the integrity of our system, establishing that the private key was generated using a hardware random number generator and that there are no backdoors or bugs that could lead to the loss of funds.
You can read the detailed reports of both audits. Kudelski Security's audit results are available here, and information about the second audit conducted by Riscure can be found here.