Close Menu
CryptoDigestAlert.comCryptoDigestAlert.com
    What's Hot

    Canary’s XRP ETF Clears Path for Launch After Key Update: Here’s the Timeline

    November 5, 2025

    Story launches IP Vault for programmable access to onchain IP data

    September 13, 2025

    Tangem Pay Launches to Let Users Spend USDC with Visa Virtual Card

    November 9, 2025
    Facebook X (Twitter) Instagram
    • Privacy Policy
    • Get In Touch
    Facebook X (Twitter) Instagram
    CryptoDigestAlert.comCryptoDigestAlert.com
    • News

      US lawmakers propose new federal crypto crime task force

      June 12, 2026

      XRPL and RLUSD Take Center Stage as Ripple Joins Mastercard’s AI Payments Push

      June 11, 2026

      XRP Is Oversold On Every Time Frame, And This Could Be The Bullish Signal Everyone Is Waiting For

      June 10, 2026

      Amazon drops AI merch tool that prints creative ideas on shirts

      June 9, 2026

      Why Bitcoin miners are becoming AI data centers

      June 7, 2026
    • Technology

      Blockchain Lender Figure Acquires Kiavi in $717M Market Shake-Up

      June 12, 2026

      Tim Draper claims Bitcoin is safer than Banks in Quantum era

      June 11, 2026

      Oracle stock falls as AI funding plans overshadow earnings beat

      June 10, 2026

      PayPal’s $PYUSD Stablecoin Supply Shrinks 31% From $4.2B ATH to $2.92B

      June 9, 2026

      Vietnam SSC Backs Crypto Assets as Pillar of Digital Economy Growth

      June 7, 2026
    • Learn/Guide

      Wadoozie ($WADZ): The Ethereum Memecoin With a 48-State Tour and Hidden Token Rewards

      May 6, 2026

      How to Optimize Company Operational Costs: A Manual on Modern Payment Ecosystems

      March 6, 2026

      6 Best Citizenship by Investment Programs for 2026

      February 23, 2026

      Best Smart Contract Auditors and Web3 Security Companies (2026): Ranked by Verifiable Public Evidence

      February 12, 2026

      Your Complete Guide to Smarter Investing

      January 29, 2026
    • Regulation

      Hungary Crypto Overhaul Targets EU MiCA Alignment and Market Return

      June 12, 2026

      Over 200 Crypto Groups Urge Senate Clarity Act Vote

      June 9, 2026

      UK FCA Warns Football Clubs Over Crypto Sponsorship Deals

      June 4, 2026

      SEC Charges Texas Man Nathan Fuller in $12.3M AI Crypto Trading Bot Fraud Case

      June 1, 2026

      UK Adds HTX to Russia Sanctions List Over A7, Garantex Ties

      May 27, 2026
    • Live Pricing Chart
    CryptoDigestAlert.comCryptoDigestAlert.com
    Home»Technology»MediaTek chip flaw exposed crypto wallets and passwords without booting Android
    Technology

    MediaTek chip flaw exposed crypto wallets and passwords without booting Android

    March 12, 20263 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    MediaTek chip flaw exposed crypto wallets and passwords without booting Android
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Security researchers at Ledger have discovered a major flaw in some Android smartphone chips that lets an attacker siphon encrypted user data like passwords and private keys in a matter of seconds using just a USB connection.

    Summary

    • Ledger’s Donjon security team discovered a vulnerability in MediaTek and Trustonic TEE chips that could allow attackers to extract encrypted data from Android phones in under 45 seconds.
    • The exploit bypasses the secure boot chain before Android loads, allowing attackers to recover the device PIN, decrypt storage and extract seed phrases from popular wallets.

    The vulnerability was first spotted in January by Ledger’s internal security research team, Donjon, Ledger Chief Technology Officer Charles Guillemet wrote in a recent X post. 

    According to Guillemet, the vulnerability affected smartphones powered by MediaTek and Trustonic’s TEE processors. 

    MediaTek has since issued a security patch to fix the issue; users who have not installed the latest security updates on their devices may still remain at risk.

    White hat hackers were able to penetrate a smartphone from manufacturer Nothing, notably the company’s CMF 1 phone, in under 45 seconds using a laptop.

    “Without ever even booting into Android, the exploit automatically recovered the phone’s PIN, decrypted its storage, and extracted the seed phrases from the most popular software wallets,” Guillemet said.

    This puts software wallets like Trust Wallet, Base, Kraken Wallet, Rabby, Tangem’s mobile wallet, and Phantom at risk, as the seed phrases and other sensitive credentials are stored locally on the device.

    In their report, researchers noted that the vulnerability allowed attackers with physical access to bypass the phone’s security protections through the secure boot chain, which is a core startup process that runs at the highest privilege level before the operating system loads. Subsequently, the attacker can recover the device’s PIN, decrypt its storage, and extract the information.

    “This has the potential to affect millions of Android smartphones,” Guillemet added.

    Estimates suggest nearly 36 million people manage digital assets on their smartphones, which means that if attackers manage to exploit a vulnerability, it could put a large number of wallets at risk. 

    Guillemet advised using devices with dedicated secure elements that are built for key protection and can safeguard sensitive data even under physical attack.

    The Ledger team also detailed a separate attack it tested on MediaTek Dimensity 7300 processors (MT6878) in December, where the team used electromagnetic fault injection to disrupt the chip’s boot process. It allowed them to bypass security checks and ultimately gain full control over the smartphone at the highest privilege level.

    As covered by crypto.news on several occasions, crypto users have been targeted across multiple platforms, including iOS, macOS, and Windows.

    While Android devices are often easier to compromise due to Google’s more open ecosystem and flexible app distribution model, Apple’s iOS devices have also developed unique attack vectors that target users through malicious frameworks embedded inside otherwise legitimate apps.

    For instance, last year, security researchers discovered a malicious app that infiltrated both iOS and Android devices by requesting file access and subsequently scanning device storage to extract wallet data. Although not as technically severe in nature as hardware-level exploits, the scheme still managed to steal more than $1.8 million in cryptocurrency.

    Around the same time, Kaspersky flagged a malware campaign that spread through malicious software development kits embedded in seemingly harmless apps.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Blockchain Lender Figure Acquires Kiavi in $717M Market Shake-Up

    June 12, 2026

    Tim Draper claims Bitcoin is safer than Banks in Quantum era

    June 11, 2026

    Oracle stock falls as AI funding plans overshadow earnings beat

    June 10, 2026

    PayPal’s $PYUSD Stablecoin Supply Shrinks 31% From $4.2B ATH to $2.92B

    June 9, 2026
    Top Posts

    $100M in Commercial Real Estate Assets Tokenized on Stellar

    September 19, 2025

    Ethereum Stablecoin Supply Hits $180B Record High as Public Crypto Fundraising Hits Two-Year Low

    April 15, 2026

    Why Cardano’s social activity surges as ADA crashes

    June 6, 2026

    Welcome to CryptoDigestAlert.com! Your go-to source for fast, reliable updates from the ever-evolving world of cryptocurrency. Whether it's Bitcoin, altcoins, blockchain breakthroughs, or DeFi trends, we bring you timely insights, expert analysis, and key developments shaping the future of digital finance. Stay ahead with real-time crypto news and in-depth coverage.

    Top Insights

    US lawmakers propose new federal crypto crime task force

    June 12, 2026

    XRPL and RLUSD Take Center Stage as Ripple Joins Mastercard’s AI Payments Push

    June 11, 2026

    XRP Is Oversold On Every Time Frame, And This Could Be The Bullish Signal Everyone Is Waiting For

    June 10, 2026
    Advertisement
    Demo
    • News
    • Technology
    • Learn/Guide
    • Regulation
    • Business
    • Live Pricing Chart
    © 2026. Burleys Holdings Ltd Company Reg: 15927118 - Unit 15 Manor Farm, Tarnock, Axbridge, UK, BS26 2SL - Design & SEO + GEO Developed By SEO - Craig Burley

    Type above and press Enter to search. Press Esc to cancel.