It’s completely understandable to be concerned given the recent...

To clarify, the issue discovered by Aikido Security was a supply chain attack on the xrpl.js NPM package — a tool used by developers to build applications that interact with the XRP Ledger. A malicious update introduced a backdoor that could steal seed phrases or private keys if someone used that package in their app and a user entered sensitive info.
That said, this has nothing to do with the XRP Ledger itself, and it does not affect wallets like Tangem.
Your XRP on Tangem is completely safe because:
1. Tangem is a secure hardware wallet — your private key never leaves the card, and it’s never exposed to software or the internet.
2. You are not interacting directly with xrpl.js, nor entering your seed into a potentially compromised app or interface.
Unless you’ve manually typed your seed phrase into a third-party site or software using that infected package (which we highly doubt), there is no risk to your funds.
