Tangem on security architecture
8.0/ 35% of the score
Keys are generated inside a certified chip with no interface to export the private key; the card has no screen, so transaction details are verified on the paired phone rather than on the device.
Journalism for the digital-asset economy
Best Hardware Wallets · Rank 07 of 8
People who will never write down a seed phrase
Last verified August 15, 20264 scored axes
Documented, with gaps
Tangem scores 8.0 out of 10 and ranks #7 of 8 in the best hardware wallets table, strongest on usability (9.2) and weakest on openness (7.4).
A card you tap against a phone, with the key generated inside a certified chip and backed up by issuing two or three identical cards instead of a seed phrase. It solves the backup problem that actually loses people their coins, at the cost of a very different threat model.
4 axes, weighted as published in the table’s methodology. Each score below is read from the fact printed under it.
8.0/ 35% of the score
Keys are generated inside a certified chip with no interface to export the private key; the card has no screen, so transaction details are verified on the paired phone rather than on the device.
7.4/ 25% of the score
The app is published and card firmware can be attested through the app, but the firmware itself is closed and audited by a named third party.
7.6/ 20% of the score
No seed phrase by default: backup is a set of two or three cards holding the same key, so recovery depends on physically holding another card; an optional seed-phrase mode exists.
9.2/ 20% of the score
Tap-to-sign on a phone with no cable or battery; broad chain list, but the absence of a device screen limits what can be verified.
Most crypto lost to self-custody is lost to backups: seed phrases photographed, mistyped, stored in a drawer that flooded, or never written at all. Tangem replaces the phrase with a set of two or three identical cards holding the same key. Backup becomes a physical object you distribute rather than a procedure you must execute correctly under pressure.
Keys are generated inside a certified chip with no interface to export the private key, and the card firmware can be attested through the app. That is a strong guarantee on the storage side.
There is no display, so transaction details are verified on the paired phone rather than on an independent device. That breaks the property other hardware wallets are built around: an attacker who controls your phone controls what you see. For small everyday balances it is a reasonable trade; for a large cold position it is the wrong architecture.
Non-technical holders, travellers and anyone who would realistically never maintain a seed backup — for whom the alternative is not a better wallet but an exchange account.
Store the duplicate cards in separate places, treat the phone as untrusted for large transfers, and keep balances at a size where a compromised phone would be painful rather than catastrophic.
Keys are generated inside a certified chip that cannot export them, and backup is achieved by issuing duplicate cards. The weakness is the absence of a screen: you verify transactions on your phone, so a compromised phone can misrepresent what you are signing.
Any of the duplicate cards issued at setup restores access, which is why the set should be stored in separate locations. An optional seed-phrase mode also exists.
It is better suited to everyday balances. For a large cold position, a device with its own screen lets you verify a transaction independently of the phone it came from.
8 services in best hardware wallets