At XRPL Labs, we are constantly working on improving the XRP Ledger user experience for consumers and businesses.
XUMM is a non-custodial XRP Ledger client (wallet). This means that you, and only you, have access to your funds because your funds are in your own account, to which you own the keys. Your keys are encrypted securely on your iOS/Android device.
Keeping your keys safe
While keeping your keys encrypted on your device makes a lot of sense for your daily spending (lower-value accounts, to be accessed on the fly), your keys to your XRPL savings are best kept offline, away from your iOS/Android device (or any device you carry around, for that matter).
Existing methods to keep your key(s) to your high(er) value accounts safe all have disadvantages, if you want to be able to potentially/periodically move funds from your savings to your spending account.
A paper wallet (your secret offline, written down) is not user friendly. It's hard to use, because it will have to be imported to eg. XUMM when you want to access your funds. Hardware wallets have to be charged, are slightly harder (or even scary) to use. Air gapped clients require manual data entry when signing.
Enter XUMM Tangem Cards
Just like XRPL Labs, Tangem is making the cryptocurrency space a safer, more user-friendly place. Their take on keeping keys for XRPL accounts safe is one we at XRPL Labs appreciate a lot. To the point where we feel confident using their cards ourselves to keep the key to our savings.
Instead of using a hardware wallet, or a static, written down secret (that can't be used easily), their cards contain a chip and use NFC (near field communication). The chip generates a private key, while being powered using NFC (by your iOS/Android device). This means the cards are shipped without a private key on them, and the private key will never leave the card. The chip used in XUMM Tangem cards offers bank grade security and have been fully audited.
Security + usability
Because the key stays in the (chip in the) card, signing happens in the (chip in the) card. This means your secret will never leave the card.
You hold your card against your NFC enabled iOS/Android device to sign a transaction. XUMM will then send transaction details to the card, the card will sign and return the signature (for the signed transaction) to XUMM so XUMM can submit it to the XRP Ledger.
This offers the best combination of user experience and security. Using your smartphone with decent screen size, and the XUMM + XRPL ecosystem to compose and review transactions, while using a separate (dedicated, low level, offline) piece of hardware (the Tangem card) to sign transactions.
While Tangem already offered XRP cards, one could only use them for regular XRP payments. The XRPL has much more to offer than simple XRP payments: Issued tokens / IOU's (decentralized exchange), account settings, multi signing, escrow, etc. All fully supported by XUMM.
We are very excited and proud to share that, by supporting Tangem cards in XUMM, all XRP Ledger features and all transaction types will be available for all existing Tangem card owners.
Because the chip inside a XUMM Tangem card generates and holds the (non-extractable) private key to access your funds, a lost card means you won't be able to access your funds anymore.
As the XRPL offers clever, on-Ledger features like "regular keys" and multi signing, XUMM will allow users to setup a secondary, offline Secret Numbers key pair. This key pair should be written down, kept secure away from the card. This key will be configured on Ledger to be a back-up key ("regular key") to the XUMM Tangem card account.
Further explanation & FAQ's
What's the typical use case for a XUMM Tangem card + XRPL?
Your XUMM Tangem card has it's own r-address. It's a separate XRP Ledger account. XUMM, in combination with your XUMM Tangem card, enables all XRPL features.The most common use case would be to use two XRP Ledger accounts: one for receiving funds & daily spending and one for your savings. Your daily spending account in XUMM (as read/write account), and your savings account using a XUMM Tangem card.When you want to top up your spending account, you use your XUMM Tangem card to sign a transaction from your savings account to your spending account.When your spending account has a higher balance than you're comfortable with, you simply use XUMM to send some of your funds to your XUMM Tangem card account.
No, you cannot. While all Tangem cards feature a bank grade secure chip, the chip is programmed to work only for crypto-currencies with Apps supporting the cards: ATM's and retail payment terminals will not recognize a XUMM Tangem card.
Can I use an existing XRP Tangem cards with XUMM?
Yes, definitely! All existing & future Tangem XRP cards will work with XUMM. All XRPL features will be available to all Tangem card owners using XUMM.
XUMM Pro is a paid subscription, do I need XUMM Pro to use XUMM Tangem cards?
No, XUMM Pro will include one (globally) shipped XUMM Tangem card, but you can use both regular Tangem XRP cards and XUMM Tangem cards with the free version of XUMM. (Not all countries are eligible to receive the cards due to customs restrictions.)
How can I get XUMM Tangem cards?
They are available here: https://xrpl-labs.com/tangem/product
Can I extract or backup the secret / private key from my XUMM Tangem card?
No, you cannot. The secret / private key of a XUMM Tangem card is stored safely inside the chip in the card. The card can only sign for you, it will never expose the secret / private key.While you cannot extract & backup the secret / private key of the card, XUMM can setup a recovery account, and attach the recovery account to your XUMM Tangem card account. Using this recovery account, you will be able to regain access to your funds in case of a lost, stolen or damaged card.
How is the XUMM Tangem card protected? Can someone else use my card if they have physical access?
XUMM will allow you to setup a PIN / Password on your card. If you do so, signing transactions with your card also requires that you to enter the PIN / Password. This will protect you against physical access attacks, as one not only needs your card, but your PIN / Password as well.
If you did not configure a PIN / Password on your card, anyone with physical access to the card can move all your funds.
If you use your XUMM Tangem card to keep significant amounts of XRP (or other currencies), it is advisable to both enable PIN / Password protection on your card and not to keep your card with you during your daily commute.
Where will XUMM Tangem Cards be shipped?
To most countries around the world.
Can I import my existing account (r-address) to a XUMM Tangem card?
No. The cards will have their own r-address.
Does a XUMM Tangem card require another 10 XRP reserve?
As each card has their own r-address, they will require activation (the 10 XRP reserve, as required by the XRP Ledger).