Hardware wallets are considered a particularly secure form of self-storage. With a seedless wallet... TangemThe device is designed so that, according to the manufacturer, the private key is generated within the security chip and should not leave it. Nevertheless, in forensic practice we encounter cases where funds flow from a hardware wallet without the owner claiming to have initiated a transaction.
In one of these cases, there were approximately six minutes between entry and unauthorized exit.
This article explains what is technically possible in such constellations, what follows from this – and above all, what the consequences are. not The initial suspicion often falls on the wallet technology. However, in the case described here, the circumstances of the transfer and setup are at least as important.
The case in briefA client received a Tangem hardware wallet, which, according to him, was in its original packaging. He then transferred Bitcoin from his own hardware wallet, which he had been using for some time, to the receiving address of the new wallet. The Bitcoins were received there without any problems. Five minutes and fifty-one seconds later, the same amount left the address again – without any action from the client. Further tracing via the blockchain revealed a multi-stage chain of intermediate addresses, a division into partial amounts according to a recurring amount pattern, a cross-chain exchange to another network, and several addresses where the funds converged with amounts from other sources. The case and client are anonymized; we do not disclose amounts, addresses, or data here. |
Forensic classification of the case
Proven: The funds were received at the designated Bitcoin address. Five minutes and fifty-one seconds later, the amount was transferred without any transaction initiated by the client. The subsequent flow of funds can be traced on-chain through several stages. Plausible explanations: A wallet set up before the handover, a retained backup device, a compromised seed phrase, or a signature capability obtained by other means can explain such a sequence of events. Not proven: The blockchain alone does not reveal who initiated the transaction, nor how the signature capability was obtained. Likewise, it provides no evidence of a vulnerability in the Tangem device or its manufacturer. |
One detail is crucial for the evaluation: The Bitcoin initially arrived at the intended address. This argues against the simpler attack variant where a different receiving address is used during transmission, as can occur with clipboard manipulation. The funds were only disbursed after being received.
Why timing is so important in forensic science
With Bitcoin, a transaction cannot be initiated simply by knowing the public receiving address. Anyone wishing to spend Bitcoin must sign the transaction with the corresponding private key. A valid signature is created only from the key itself.
This leads to an unpleasant but unambiguous conclusion: If funds are withdrawn from an address, someone had the opportunity to sign for that address.
The short interval between entry and exit suggests a pre-planned or automated process. Technically, this could be due to a monitored address or notifications about a... Block Explorer or a script that detects incoming transactions and then automatically forwards them. Such automated forwarding systems are often called "sweepers".
However, the time interval alone does not tell us anything not to deduce how access to the key was gained. This very separation – observable finding here, explanation there – is the core of sound forensic work.
Does this mean that Tangem has been "hacked"?
No, and this answer deserves more than one sentence.
The private key in a Tangem wallet is generated on the chip and, according to the manufacturer, should not leave the chip in plaintext. The firmware is loaded onto the chip once and cannot be updated afterward – this prevents malware from being installed later, but also makes subsequent corrections impossible. During scanning, the Tangem app checks stored certificates to verify that the device is indeed from Tangem and contains Tangem firmware.
Independent audits are available in three stages:
- Kudelski Security (2018) and Riskure (2023) They examined the firmware of the cards. According to the manufacturer, both audits confirmed the integrity and found no backdoors that could lead to a loss of credit.
- Cure53 (work completed in November 2025, summary from February 2026) The report examined the Android and iOS SDKs of the Tangem application – that is, software components of the mobile application, not the map itself. It identifies twelve findings. Three of these were classified as vulnerabilities with a measurable security risk and were fixed; an additional seven less significant findings were also addressed. Two remaining issues were identified as weaknesses with minor impact and, according to Cure53, negligible exploitation potential. No critical or high-risk vulnerabilities were reported.
The allocation of audit scope is crucial: an app audit says nothing about reading keys from the chip, and a firmware audit says nothing about the app itself. Anyone arguing based on audits should know which report covers which aspect.
Based on current public knowledge, there is no reliable evidence that private keys can be easily read from a correctly configured Tangem card. However, an audit is always a snapshot of a defined scope of testing and not a lasting guarantee.
This shifts the crucial question away from the technology:
Was the wallet truly new at the time of handover – and solely under the control of the future owner? |
Original packaging does not mean unused.
The packaging of a hardware wallet is not cryptographic proof. Foil can be replaced, seals can be reprinted, boxes can be resealed. A security feature that can be replicated with household items is, in case of doubt, not a security feature at all.
To determine whether a wallet has already been activated on the device, the initial scan with the official application is particularly important. Tangem clearly describes this in its help center: If the app prompts you during the first scan, to create a wallet, If the device was not previously activated, and it reports that the wallet is already activated, then the device has already been used.
In this case, the application even displays an explicit warning before an access code can be entered – essentially saying: Anyone who is asked to enter or change an existing access code upon first use should not use the wallet because it is a fraudulent attempt.
The manufacturer's recommendation in such a case is unequivocal: do not use the existing wallet, reset the device to factory settings, and create a new wallet. The reset process will delete the existing keys and generate new ones.
Tangem has also been warning in a separate article since October 2025 about pre-activated wallets, which are sold via third-party platforms. Two points are important in practice: Tangem never ships devices with pre-generated keys or access codes, and an included "initialization password" is a clear warning sign – a genuine wallet does not include such a password.
Therefore, anyone who receives a wallet with pre-configured access data is not holding a conveniently set-up device, but rather a stranger's.
The backup mechanism – and why it plays a role in fraud cases
Current second-generation Tangem hardware wallets are used with two or three devices as a backup system. In a seedless setup, the private key is copied between the devices via an encrypted channel; the devices authenticate each other, and according to the manufacturer, the app cannot decrypt the transferred keys. An internet connection is required for this process because certificates are downloaded for authentication.
Three characteristics of this procedure are crucial for forensic evaluation:
1. There is no "main device" and no technically subordinate "backup device". All devices in a set are equivalent and, with knowledge of the respective access code, allow the same access to the same wallet. Therefore, a card that is kept behind can be a security risk.
2. Device backup is only possible once with a seedless setup. For security reasons, the key can only be copied to the selected number of devices during this backup process. Additional devices cannot be easily added later. Additional recovery options apply when using a seed phrase.
3. In a seedless setup, the initial setup determines how many device copies of the key exist. This decision is made during the backup process – so possibly before the eventual owner has even seen the device.
Anyone wishing to add another device to the backup set of a seedless wallet later on must reset the existing setup and recreate the wallet with the intended devices. Before such a reset, the assets must be transferred to another, securely controlled wallet. Technically, the reset deletes the keys stored on the device; the Bitcoin themselves remain on the blockchain, but can become inaccessible without a remaining valid key.
In practical terms, this means that a wallet whose initial setup you didn't control cannot be secured by subsequent measures. Either it's clean from the start – or it must be completely reset and recreated.
The seed phrase variant shifts the risk
Newer Tangem wallets can alternatively be set up with recovery words (seed phrase) or imported from an existing seed phrase.
This fundamentally changes the security situation. A key generated exclusively on the chip is bound to the cards. A seed phrase, on the other hand, is copyable information: anyone who knows it can reconstruct the wallet on any compatible device or in any wallet software – without any Tangem card.
A seed phrase that someone else has created, written down, photographed, or provided is permanently compromised. It "belongs" to the person who saw it, regardless of who possesses the map.
Four scenarios that explain a drain without a manufacturer's weakness
1. Pre-activated wallet with retained device. The wallet was set up before the handover; several cards were linked during this process, but only part of the set was handed over. The person who set it up retains an equivalent card and knows the access code set during setup. They can sign transactions at any time. This usually only becomes noticeable when funds are deposited.
2. Predefined or read-aloud seed phrase. The wallet was set up with recovery words that another person generated, wrote down, or "kept safe" for safekeeping. Access is then no longer dependent on the hardware.
3. Manipulation during setup. The setup was handled by a retailer, consultant, acquaintance, or supposed expert. Any situation is critical in which another person first connects the device to their smartphone, manages the backup devices, sees or specifies the recovery words, knows the access code, or provides the delivery address.
4. Smartphone or fake application. While the private key isn't stored on the phone with Tangem, the app acts as an intermediary between the user, the card, and the blockchain. A manipulated application could, for example, display incorrect receiving addresses. However, a typical malware infection of the phone isn't a sufficient explanation for the outflow of funds from a correctly configured wallet without a seed phrase – it doesn't explain how the key stored on the card could have fallen into the wrong hands.
In the case described at the beginning, the Bitcoin initially arrived at the intended address. This argues against the simple explanation of a receiving address being changed during the sending process. Scenarios 1 to 3 thus become more likely, but are not proven by the passage of time alone.
What the blockchain answers – and what it doesn't
Blockchain technology provides excellent evidence of processes and poor evidence of motives. The data reveals the following:
- Block allocation as well as – depending on the analysis source used – observed times of entry and exit,
- Amounts and network fees paid,
- the complete route via intermediate addresses,
- Divisions, mergers and amount patterns,
- Switching to other networks via bridge or swap services,
- Deposits to trading platforms and other attributable services.
What can be derived from this? not This allows us to deduce how the perpetrator gained access to the signature capability. This question can only be answered by examining the circumstances of the handover and setup – chat histories, purchase receipts, witnesses, the number of cards in the set, and the information displayed by the app during the initial scan.
Another limitation is at least as important in practice: as soon as a payment path encounters an address that pays out significantly more than it received from the traced cash flow, funds from other sources are involved. From this point on, subsequent payments can only be considered as upper limit The amount can no longer be attributed precisely. Anyone who attributes the full amount of the victim's claim to a stock exchange deposit made to such a collective address is calculating incorrectly – and damaging the credibility of the entire report.
Our reports therefore strictly distinguish between our own calculations, attributions adopted from an analytics platform, and information provided by the client. For investigative authorities, this distinction is precisely the point at which a Appraise carries or falls.
Checklist: How to properly adopt a new hardware wallet
1. Only the official application use, installed directly from the manufacturer's official app store.
2. Check that the set is complete. Tangem supplies sets of two or three cards. If a card is missing, the question of where it is is legitimate.
3. Pay attention to the message during the first scan. The app must prompt the user to create a new wallet. Any notification about an already activated wallet is grounds for termination.
4. Do not accept any enclosed "initialization password". Genuine devices are delivered without pre-generated keys and without an access code.
5. If in doubt, reset and create again. – for each device in the set, before the first deposit.
6. Set your own access code and tell no one.
7. Never use recovery words. They may only be produced and viewed by the owner himself.
8. Test first, then transfer. Transfer a small amount, leave it there for several days, monitor the account balance – and only then move larger sums. This single rule would have limited the damage to just a few euros in several of the cases we handled.
9. Buy from the manufacturer or an authorized dealer. Devices purchased from private sales, marketplaces, or as gifts related to investment recommendations deserve special caution.
If the assets have already been disbursed
Blockchain transactions cannot be reversed. However, the subsequent path of the funds can be reconstructed, and this provides starting points for investigation.
Immediately:
- Do not make any further deposits to the affected wallet – not even for testing purposes. If the keys are compromised, any further amount will also be lost.
- Transfer remaining funds from other wallets set up in the same context to a demonstrably self-initialized wallet.
- Secure all evidence unchanged: packaging, cards, serial numbers, proof of purchase, chat histories, emails, instructions and screenshots of the wallet application with transaction ID and timestamp.
- Record the circumstances of the handover in writing while the memory is fresh: who, when, where, how many cards, which app, which messages.
Afterward:
- File a criminal complaint and attach the secured documents.
- Commission a crypto-forensic analysis: It reconstructs the path of funds, identifies dormant assets and deposits with service providers, and prepares the findings in such a way that investigative authorities can work with them – especially for security and information requests.
- Have the affected addresses included in a surveillance system so that subsequent movements do not go unnoticed.
And a warning that is unfortunately necessary: Victims of crypto fraud are often contacted a second time. Alleged recovery services, supposed law firms, or purported employees of regulatory authorities demand advance payments, "taxes," or "activation fees." Basic rule: no advance payments, no sharing of access data, and no installation of remote access software.
Conclusion
Hardware wallets offer good technical protection for the private key. However, they do not protect against someone taking over a wallet already set up by a third party.
The security of a hardware wallet therefore depends not only on the chip, but also on the controlled initial setup. If the official app prompts you to create a new wallet during the first scan, this is a strong positive indication that the device was not previously activated. Conversely, if the app reports an already activated wallet, the existing setup should not be used; instead, the device should be completely reset and set up again according to the manufacturer's instructions.
If Bitcoins flow out a few minutes after a deposit without the owner's intervention, it is therefore necessary to reconstruct exactly who set up the wallet, how many devices were connected, whether recovery words were involved, and how the funds subsequently moved across the blockchain.
Only the combination of these two levels – the history of the furnishings and the on-chain analysis – yields a reliable picture.
FAQs – Frequently Asked Questions about Bitcoin Seizure
Yes. Even though hardware wallets are considered a secure form of self-storage, funds can be siphoned off if someone has a valid signature. In the described case, the Bitcoin left the address a few minutes after being received.
No. The blockchain alone does not provide proof of a vulnerability in the device or manufacturer. It shows that a transaction took place, but not how the signature capability was obtained.
A very short interval can indicate a pre-planned or automated process, such as a script that recognizes and forwards incoming transactions. However, this does not necessarily explain how access to the key was gained.
The blockchain can show incoming and outgoing transactions, amounts, network fees, intermediate addresses, splits, mergers, cross-chain exchanges, and potential deposits with service providers. It does not, however, prove motives or the identity of perpetrators.
Packaging is not cryptographic proof. Foil, seals, or boxes can be replaced or replicated. What matters is whether the wallet was truly reinitialized upon first use.
On the first scan, the official app should prompt you to create a new wallet. If the app reports that the wallet is already activated or that an existing access code needs to be entered, the device should not be used.
With seedless Tangem wallets, two or three devices can contain the same key. There is no technically subordinate backup device; any card in the set can be a security risk if the access code is known.
A seed phrase is copyable information. Anyone who knows it can reconstruct the wallet on a compatible device or in wallet software. A seed phrase generated, seen, or photographed by a third party is permanently compromised.
Do not make any further deposits, transfer remaining funds to a self-initialized wallet, secure evidence, document the circumstances of the handover, file a criminal complaint and commission a crypto-forensic analysis.
Only use the official app, check that the set is complete, pay attention to the prompt to create a wallet during the first scan, do not accept any pre-prepared access data, and test with a small amount first.
Do you have a similar case? Finanz Forensik GmbH analyzes crypto transactions and prepares the results for law enforcement and legal representatives. The sooner evidence is secured, the more can be reconstructed. |