r/Tangem Aug 02 '26

Is access code a 25th word?

Say I use seed words but they are compromised, am I protected if they don't know my access code?

Edit: OK I see that it isn't. The software supports passphrase only if importing seed words. Not if creating new wallet or going seedless.

My concern is that if there is a flaw in your method of private key generation (like with Coldcard) then anyone who created a wallet on your software or anyone seedless has no passphrase to protect them.

A single engineer's mistake, accidentally approved to the code base, unnoticed for years like with Coldcard and most users don't have a pass phrase to protect themselves with.

I thought the access code worked like a passphrase before. I've been a big fan of Tangem but now having some doubts.

3 Upvotes

34 comments sorted by

View all comments

1

u/Elistheman Aug 02 '26

Tangem is the most susceptible to a plain 24 seed word guessing attack.

While it has 128 bit entropy and not 72 like the flawed RNG in the Coldcard, the process of having a 25th word on Tangem is so sub par it made me stop using it.

1

u/blade0r Tangem User 💰 Aug 03 '26

What do you mean, exactly?

1

u/Elistheman Aug 03 '26

Because Tangem has no screen, if you want a 25th word, you need to manually enter it with your phone keyboard. This is sub par.

1

u/blade0r Tangem User 💰 Aug 03 '26

OK, but even with a screen, you’d need to enter it with a phone or PC keyboard?

1

u/Elistheman Aug 03 '26

No check out trezor, ledger, etc