Hardware review — Tangem
Tangem review: the easiest cold storage, and its unfixable flaw
Tangem removed the seed phrase, which removed the single most common way people lose crypto. Then Ledger's research lab found a way into the chip that cannot be patched, because the cards have no update mechanism at all. Both facts are true and both matter.
- EAL6+ Certified chip — yet still faulted
- No seed Nothing for a phishing site to steal
- US$250k Lab cost of the published attack
- Never Firmware cannot be updated
At a glance
The friendliest onboarding in cold storage, undercut by an unpatchable laser fault-injection finding published in July 2026.
Best for: Absolute beginners who will never manage a seed phrase · Maker: Tangem AG
The idea, and why it was a good one
Start with what Tangem got right, because it is easy to lose in the discussion of the vulnerability. Read enough loss reports and a pattern emerges that has nothing to do with chips or firmware: people lose crypto because of the recovery phrase. They type it into a page that looked like support. They photograph it and the photo syncs to a cloud account with a reused password. They put it in a password manager. They write it down and never test it, then find out three years later that two words were transposed.
Tangem's answer was to delete the phrase. The private key is generated inside a certified chip on a credit-card-shaped device and never leaves it, in the same way as any hardware wallet — but there is no twenty-four word export. Backup works by cloning: at setup the card copies its key to the other identical cards in your set, and any one of them opens the wallet. You tap a card on your phone over NFC to sign a transaction. No cable, no battery, no screen to break, and nothing that a phishing site can ask you to type.
That is a genuinely thoughtful piece of product design aimed at the actual failure mode rather than the theoretical one, and the execution is excellent — the app is one of the better mobile crypto interfaces, it supports thousands of assets and it stakes in-app. For roughly NZ$115 landed you get a complete cold storage arrangement that a non-technical person can set up in five minutes without writing anything down.
Specifications
| Form factor | Credit-card sized NFC card, sold in sets of two or three |
|---|---|
| Price | Around US$55 for a 2-card set, US$70 for a 3-card set — one-time, no subscription |
| Secure element | Common Criteria EAL6+ certified chip |
| Source code | Mobile app is open source; card firmware is closed |
| Firmware updates | None — the cards have no update mechanism |
| Connection | NFC tap to an Android or iOS phone; no cable, no battery |
| Backup model | Card cloning at setup — no BIP39 recovery phrase exists |
| Asset support | 6,000+ assets claimed across many chains |
| Staking | Available in-app for several chains |
| Known vulnerability | Laser fault injection, disclosed to Tangem 10 Feb 2026, published by Ledger Donjon 9 July 2026 — affects all cards, unpatchable |
| NZ availability | Direct from tangem.com; no established NZ reseller |
| Last verified | September 2026 |
What removing the seed phrase costs you
Every design choice has a shadow, and Tangem's has three.
No portability. A BIP39 recovery phrase is a standard, which means a Trezor phrase restores in a Ledger, a BitBox, or a free software wallet. Your access does not depend on any single company continuing to exist or continuing to support your device. Tangem's keys live in the cards and cannot be exported, so if the company folds, discontinues the app, or the app stops working on a future phone OS, you are dependent on whatever compatibility remains. That is a real long-term risk for a savings instrument.
Redundancy is fixed at setup. Cloning happens once, when you initialise the set. You cannot add a fourth card in two years' time. If you bought the two-card set and lose one, you are down to a single point of failure with no way to restore redundancy. This is the strongest practical argument for buying the three-card set even though most people will look at the price difference and choose two.
Total loss is total. With a normal wallet, losing the device is an inconvenience — you buy another one and restore from the phrase. With Tangem, losing every card in the set is permanent and absolute. There is no phrase, no backup file, no support process. That is the trade you accepted when you decided not to have something a phisher could steal.
If you own a two-card set
Keep the two cards in different buildings, starting today. Not different rooms — different buildings. Because you cannot add redundancy after setup and there is no recovery phrase, geographic separation is the entirety of your backup strategy, and a single house fire or burglary that takes both cards ends your access permanently.
The app, which is genuinely very good
Tangem scores 9.2 on our interface axis — the second-highest of anything we have tested, behind only Phantom — and it deserves it.
Setup is the shortest of any cold storage product: install the app, tap the card, set an access code, tap the backup cards. Done. No derivation paths, no firmware update before first use, no twenty-four words to transcribe and verify. Sending funds is a tap to authorise. Asset support is broad, with more than six thousand assets claimed, and staking for several chains is available directly in the app without moving funds anywhere. The app itself is open source, which is worth noting given the card firmware is not.
There is one structural interface weakness, and it is inherent to the form factor rather than a fault in the software: the card has no screen. Every other hardware wallet shows you the destination address and amount on a display driven by its own firmware, which is the specific defence against a compromised computer or phone lying to you about where funds are going. With Tangem you read those details on your phone — the device the whole arrangement is designed to distrust. In practice a phone is a reasonably hardened environment and this is a lower-probability attack than the malware-on-a-laptop scenario, but it is a genuine gap in the trusted-display model.
The balance sheet
What we like, and what we don't
What it does well
- The friendliest onboarding in cold storage — tap and you have a wallet, with nothing to write down
- No recovery phrase means no phrase to phish, photograph, lose or store carelessly, which removes the largest single cause of self-custody loss
- EAL6+ certified chip and keys generated on-card that never leave it
- Card format survives real life better than a USB stick — no cable, no battery, no screen to crack
- Genuinely good mobile app with in-app staking for several chains, and the app is open source
- Very cheap for what it is: a full cold storage set for roughly NZ$115 landed
What we hold against it
- Unpatchable. No firmware update mechanism, so the July 2026 laser fault-injection finding affects every card in circulation permanently
- The attack sets the card password to an attacker-chosen value without needing the existing password or a backup card, and is not mitigated by disabling recovery
- No recovery phrase means no portability — you cannot restore a Tangem wallet in any other wallet software
- Lose every card in the set and the funds are gone with no recovery path of any kind
- You cannot add a card to a set later; redundancy is fixed at setup
- No screen on the card, so transaction details are verified on your phone — which is the device you are meant not to trust
- No established New Zealand reseller, so every purchase is an import
The laser attack, explained accurately
This needs to be described precisely, because both the alarmist and the dismissive versions circulating are wrong.
On 9 July 2026, Ledger Donjon — Ledger's in-house security research laboratory — published a laser fault-injection attack against Tangem cards, found by researcher Baptiste Boileau. The technique directs a single nanosecond laser pulse at a specific region of the card's EAL6+ certified chip. That pulse evades the chip platform's own fault-detection countermeasures and corrupts the execution of one conditional check in Tangem's firmware. Corrupting that check is sufficient to set the card's access password to a value the attacker chooses, which grants control of the assets held on the card.
Three properties make it serious. It does not require knowing the existing access password. It does not require possession of a backup card. And it is not mitigated by disabling the recovery feature. It applies to every Tangem card currently in circulation, and because the cards have no firmware update mechanism, it cannot be patched — not for future cards without a hardware revision, and not for any card already sold, ever.
Three properties limit it. The attacker needs physical possession of your card. They need an estimated US$250,000 of laboratory equipment and genuine expertise in hardware security — this is not a technique anyone runs from a garage. And the attack is invasive, meaning the card shows visible physical damage afterwards, so you would know it had happened.
The disclosure was handled well by everyone involved, which is worth saying. Ledger Donjon notified Tangem on 10 February 2026 and published roughly five months later, a responsible window. Tangem published its own technical analysis of laser fault injection in response rather than denying the finding. There was a public argument between the two companies about severity and framing, which is unsurprising given that the researcher works for a direct competitor, but the technical substance was not in dispute.
What this means for you specifically
If nobody knows you hold cryptocurrency, your cards are in a drawer, and your threat model is malware and phishing — you are unaffected. This attack requires someone to want your specific card enough to fund a hardware security laboratory. If, on the other hand, your name and address have appeared in a crypto vendor data breach, you are publicly associated with holding, or you keep a card somewhere others can reach it, the calculation changes and the absence of any patch path means it will never change back.
The wider lesson: patchability is a security property
The most useful thing to take from the Tangem episode is not about Tangem. It is that an unpatchable device is a bet that nobody will ever find anything, held for the entire lifetime of the product. That bet has never once paid off in the history of computing.
Tangem's reasoning for immutable firmware was not careless — no update path also means no malicious update path, and nothing can be pushed to your card by a compromised server or a coerced company. Given the Ledger Recover controversy, where users discovered firmware could do more than they had assumed, that is a coherent position. But the trade is asymmetric: a malicious-update attack requires compromising a vendor's signing infrastructure, while a firmware bug requires only that the firmware was written by humans.
When you compare hardware wallets, put "can receive verified firmware updates" in the same column as chip certification and code auditability. Every other device on our hardware wallets page can be patched. That is worth more than a certificate.
Buying Tangem in New Zealand
There is no established New Zealand reseller, so this is a direct import from tangem.com. Expect the usual timeline of one to three weeks, with 15% GST collected at checkout for goods under NZ$1,000 and the NZ$2.21 Customs Low-Value Goods levy plus GST from 1 April 2026. A three-card set lands at roughly NZ$145; a two-card set at roughly NZ$115. Buy the three.
If you already own a Tangem set and are wondering what to do, our honest answer is: nothing urgent, but plan a migration when convenient. Move to a device with a standard recovery phrase and a firmware update path — a Ledger Nano S Plus is NZ$99 from GROOV in Christchurch, and a Trezor Safe 3 is US$79. Set the new wallet up properly, send a test amount, then move the balance. Keep the Tangem cards until you have confirmed the new wallet restores from its phrase. And separate your cards geographically in the meantime, because that is the only backup you have.
Our view
We wanted to like Tangem more than we can. It is the only product in this category that took a serious run at the problem that actually loses people money, and the execution is better than almost anything else here. The vulnerability is not really why we mark it down — every device has bugs. We mark it down because it is structurally incapable of being fixed, and a savings instrument you cannot patch and cannot migrate out of is not a good place for a long horizon.
Tangem Wallet FAQ
Tangem Wallet — questions New Zealanders ask
Is Tangem safe after the 2026 laser attack?
It depends entirely on your threat model, and we would not tell you either "yes, don't worry" or "no, sell it". Against remote threats — malware, phishing, a compromised computer — Tangem is unaffected and remains genuine cold storage. Against an adversary who can physically obtain your card and spend roughly US$250,000 on laboratory equipment, it is now known to be breakable, and because the cards have no firmware update mechanism that will never be fixed. If nobody knows you hold crypto and your cards are in a drawer, you are fine. If your address has appeared in a data breach or you are a known holder, that is a different calculation.
How does a Tangem wallet work without a seed phrase?
The private key is generated inside the card's certified chip and never leaves it, exactly as with any hardware wallet — the difference is that Tangem does not export it as twelve or twenty-four words. Backup instead works by cloning: during setup the card copies its key into the other identical cards in your set, so any one of them can access the wallet. You tap a card against your phone over NFC to sign. The upside is that there is no phrase for a phishing site to steal. The downside is total: lose every card in the set and the funds are gone, because there is no phrase to rebuild from.
How many Tangem cards should I buy?
Three, not two. The two-card set at around US$55 leaves you one failure away from a single point of failure; the three-card set at around US$70 lets you keep one at home, one at a family member's house and one somewhere else entirely. Given that there is no recovery phrase, geographic redundancy is the only backup you have, and the fifteen-dollar difference is trivial against that. If you already own a two-card set, note that you cannot add a card later — cloning happens at setup.
Can Tangem firmware be updated?
No, and this is the single most consequential fact about the product. Tangem cards ship with immutable firmware and no update mechanism at all. The design rationale is defensible — no update path means no malicious update path, and nothing can be pushed to your card. The consequence is that when Ledger Donjon published the laser fault-injection attack in July 2026, every card in circulation was affected and none could be patched. Treat "can receive firmware updates" as a first-class security property when comparing devices.
Is Tangem good for beginners in New Zealand?
It has the friendliest onboarding in cold storage by a wide margin — tap a card on your phone and you have a wallet, with no seed phrase to write down or lose. For someone who would otherwise leave everything on an exchange, that is a real improvement, and New Zealand's history with Cryptopia and Dasset says exchange balances are the bigger risk for most people. But we would still point a beginner at a Ledger Nano S Plus at NZ$99 instead: patchable firmware, a standard recovery phrase that works in any wallet, and local stock.
Next in this cluster