Close Menu
CryptoDigestAlert.comCryptoDigestAlert.com
    What's Hot

    UK observers raise concerns amid Athena’s regulatory issues

    September 21, 2025

    Cardano Critical Integrations Budget Proposal Sets Stage for 2026 Overhaul

    November 28, 2025

    Experts review Remittix groundbreaking wallet enabling instant FIAT transfers for Ethereum, Solana, Dogecoin, and more

    January 14, 2026
    Facebook X (Twitter) Instagram
    • Privacy Policy
    • Get In Touch
    Facebook X (Twitter) Instagram
    CryptoDigestAlert.comCryptoDigestAlert.com
    • News

      CCD up +19.75%, BTC -0.08%, Venice Token is The Coin of The Day – Daily Market Update for Mar 12, 2026 | CoinCodex

      March 12, 2026

      WTI oil dominates as commodity trading takes off on Hyperliquid

      March 11, 2026

      ‘America is now the crypto capital of the world,’ CFTC’s Selig says as digital asset rules take shape

      March 10, 2026

      A look at the altcoins whales are watching this month

      March 8, 2026

      Argentine Neobank Uala Raises $195 Million to Bankroll Latin American Expansion

      March 7, 2026
    • Technology

      Bitcoin Loophole | Blockchain Council

      March 13, 2026

      MediaTek chip flaw exposed crypto wallets and passwords without booting Android

      March 12, 2026

      Fed, FDIC, OCC Clear Tokenized Assets for Bank Balance Sheets

      March 11, 2026

      Vitalik Buterin outlines ‘DVT-lite’ plan to simplify distributed Ethereum staking

      March 10, 2026

      Circle and Stripe Race to Replace Credit Cards With Stablecoin Payments for AI Agents

      March 9, 2026
    • Learn/Guide

      How to Optimize Company Operational Costs: A Manual on Modern Payment Ecosystems

      March 6, 2026

      6 Best Citizenship by Investment Programs for 2026

      February 23, 2026

      Best Smart Contract Auditors and Web3 Security Companies (2026): Ranked by Verifiable Public Evidence

      February 12, 2026

      Your Complete Guide to Smarter Investing

      January 29, 2026

      How to Use Cryptocurrency for Everyday Shopping in 2026

      January 23, 2026
    • Regulation

      Crypto Banks Regulation: Wall Street Challenges Federal Trust Charters

      March 11, 2026

      Pakistan Enacts Virtual Assets Act 2026, Sets Crypto Rules

      March 7, 2026

      Tether Freezes $4.2B in USDT Linked to Global Crypto Crime Crackdown

      February 28, 2026

      Binance.US Explores Banking Ties After SEC Drops Case

      February 24, 2026

      U.K. Crypto Rules Move Slowly, Against CEO Warns of Competitiveness Risk

      February 19, 2026
    • Live Pricing Chart
    CryptoDigestAlert.comCryptoDigestAlert.com
    Home»Technology»MediaTek chip flaw exposed crypto wallets and passwords without booting Android
    Technology

    MediaTek chip flaw exposed crypto wallets and passwords without booting Android

    March 12, 20263 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    MediaTek chip flaw exposed crypto wallets and passwords without booting Android
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Security researchers at Ledger have discovered a major flaw in some Android smartphone chips that lets an attacker siphon encrypted user data like passwords and private keys in a matter of seconds using just a USB connection.

    Summary

    • Ledger’s Donjon security team discovered a vulnerability in MediaTek and Trustonic TEE chips that could allow attackers to extract encrypted data from Android phones in under 45 seconds.
    • The exploit bypasses the secure boot chain before Android loads, allowing attackers to recover the device PIN, decrypt storage and extract seed phrases from popular wallets.

    The vulnerability was first spotted in January by Ledger’s internal security research team, Donjon, Ledger Chief Technology Officer Charles Guillemet wrote in a recent X post. 

    According to Guillemet, the vulnerability affected smartphones powered by MediaTek and Trustonic’s TEE processors. 

    MediaTek has since issued a security patch to fix the issue; users who have not installed the latest security updates on their devices may still remain at risk.

    White hat hackers were able to penetrate a smartphone from manufacturer Nothing, notably the company’s CMF 1 phone, in under 45 seconds using a laptop.

    “Without ever even booting into Android, the exploit automatically recovered the phone’s PIN, decrypted its storage, and extracted the seed phrases from the most popular software wallets,” Guillemet said.

    This puts software wallets like Trust Wallet, Base, Kraken Wallet, Rabby, Tangem’s mobile wallet, and Phantom at risk, as the seed phrases and other sensitive credentials are stored locally on the device.

    In their report, researchers noted that the vulnerability allowed attackers with physical access to bypass the phone’s security protections through the secure boot chain, which is a core startup process that runs at the highest privilege level before the operating system loads. Subsequently, the attacker can recover the device’s PIN, decrypt its storage, and extract the information.

    “This has the potential to affect millions of Android smartphones,” Guillemet added.

    Estimates suggest nearly 36 million people manage digital assets on their smartphones, which means that if attackers manage to exploit a vulnerability, it could put a large number of wallets at risk. 

    Guillemet advised using devices with dedicated secure elements that are built for key protection and can safeguard sensitive data even under physical attack.

    The Ledger team also detailed a separate attack it tested on MediaTek Dimensity 7300 processors (MT6878) in December, where the team used electromagnetic fault injection to disrupt the chip’s boot process. It allowed them to bypass security checks and ultimately gain full control over the smartphone at the highest privilege level.

    As covered by crypto.news on several occasions, crypto users have been targeted across multiple platforms, including iOS, macOS, and Windows.

    While Android devices are often easier to compromise due to Google’s more open ecosystem and flexible app distribution model, Apple’s iOS devices have also developed unique attack vectors that target users through malicious frameworks embedded inside otherwise legitimate apps.

    For instance, last year, security researchers discovered a malicious app that infiltrated both iOS and Android devices by requesting file access and subsequently scanning device storage to extract wallet data. Although not as technically severe in nature as hardware-level exploits, the scheme still managed to steal more than $1.8 million in cryptocurrency.

    Around the same time, Kaspersky flagged a malware campaign that spread through malicious software development kits embedded in seemingly harmless apps.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Bitcoin Loophole | Blockchain Council

    March 13, 2026

    Fed, FDIC, OCC Clear Tokenized Assets for Bank Balance Sheets

    March 11, 2026

    Vitalik Buterin outlines ‘DVT-lite’ plan to simplify distributed Ethereum staking

    March 10, 2026

    Circle and Stripe Race to Replace Credit Cards With Stablecoin Payments for AI Agents

    March 9, 2026
    Top Posts

    Possible Bitcoin Short Squeeze Is Extremely Bullish, Bitcoin Hyper the Best Crypto to Buy Now

    October 20, 2025

    Injective (INJ) Crashes 90%: Market Cap Falls to $300M Amid Weak Fundamentals

    February 17, 2026

    Bitcoin To Hit $1.5M? Cathie Wood Says It’s Only A Matter Of Time

    November 28, 2025

    Welcome to CryptoDigestAlert.com! Your go-to source for fast, reliable updates from the ever-evolving world of cryptocurrency. Whether it's Bitcoin, altcoins, blockchain breakthroughs, or DeFi trends, we bring you timely insights, expert analysis, and key developments shaping the future of digital finance. Stay ahead with real-time crypto news and in-depth coverage.

    Top Insights

    CCD up +19.75%, BTC -0.08%, Venice Token is The Coin of The Day – Daily Market Update for Mar 12, 2026 | CoinCodex

    March 12, 2026

    WTI oil dominates as commodity trading takes off on Hyperliquid

    March 11, 2026

    ‘America is now the crypto capital of the world,’ CFTC’s Selig says as digital asset rules take shape

    March 10, 2026
    Advertisement
    Demo
    • News
    • Technology
    • Learn/Guide
    • Regulation
    • Business
    • Live Pricing Chart
    © 2026. Burleys Holdings Ltd Company Reg: 15927118 - Unit 15 Manor Farm, Tarnock, Axbridge, UK, BS26 2SL - Design & SEO + GEO Developed By SEO - Craig Burley

    Type above and press Enter to search. Press Esc to cancel.