The post Android Phone Crypto Wallets Could Be at Risk Due to MediaTek Exploit: Ledger appeared on BitcoinEthereumNews.com. In brief Ledger researchers say a flawThe post Android Phone Crypto Wallets Could Be at Risk Due to MediaTek Exploit: Ledger appeared on BitcoinEthereumNews.com. In brief Ledger researchers say a flaw

Android Phone Crypto Wallets Could Be at Risk Due to MediaTek Exploit: Ledger

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

In brief

  • Ledger researchers say a flaw in certain MediaTek-powered Android phones could expose encrypted user data in about 45 seconds.
  • The exploit allows attackers to retrieve a device PIN and decrypt storage before Android even boots.
  • MediaTek issued a fix to device makers in January, though the company did not publicly address the issues until March.

A vulnerability in certain Android smartphones powered by MediaTek processors could allow attackers to extract encrypted user data in under a minute using only a USB connection, according to new research from cryptocurrency hardware wallet maker Ledger.

Ledger’s internal security research team, known as the Donjon, found that white hat hackers were able to demonstrate the flaw by connecting a Nothing CMF Phone 1 to a laptop and compromising the device’s security in under 45 seconds.

“Donjon has struck again, discovering a MediaTek vulnerability potentially impacting millions of Android phones. Another reminder that smartphones aren’t built for security,” Ledger Chief Technology Officer Charles Guillemet wrote on X. “Even when powered off, user data—including PINs and [seed phrases]—can be extracted in under a minute.”

The Donjon team reported they were able to recover the Nothing CMF Phone 1’s PIN, decrypt its storage, and extract seed phrases from several crypto wallets without booting Android, including Trust Wallet, Base, Kraken Wallet, Rabby, Tangem’s mobile wallet, and Phantom.

Released in 2024 by London-based Nothing, the Nothing CMF Phone 1 is a low-cost and modularly customizable mobile phone that runs the Android operating system. The exploit targets the phone’s secure boot chain, Donjon said, which allows an attacker to connect through USB and extract root cryptographic keys before the operating system loads, enabling the device’s storage to be decrypted offline.

According to a July 2025 report by Chainalysis, personal wallet compromises represented a growing share of total cryptocurrency theft, with attackers increasingly targeting individual users, making up 23.35% of all stolen fund activity YTD in 2025.

Ledger said the Donjon team discovered the vulnerability while analyzing Android’s flash encryption security. The company disclosed the exploit to MediaTek and Trustonic under a 90-day responsible disclosure policy, and the vulnerability was publicly disclosed by MediaTek earlier this month.

Other devices that use MediaTek chips include the crypto-centric Solana Seeker, along with smartphones from brands including Samsung, Motorola, Xiaomi, POCO, Realme, Vivo, OPPO, Tecno, and iQOO. However, it’s not yet clear which other handsets beyond the Nothing CMF Phone 1 may be susceptible to the exploit.

Although the demonstration focused on crypto wallets, Donjon said the exposure could extend to other sensitive information stored on the device, including messages, photos, financial information, and account credentials.

Crypto wallets typically come in two flavors: software and hardware wallets designed to store private keys that allow users to access their digital assets. Software or hot wallets are designed for mobile devices, while physical hardware wallets are meant to be used with desktop or laptop computers. These wallets, like the Ledger Nano S, can be removed from computers for better security.

However, software wallets are more accessible and typically free to download and use, compared to hardware wallets that can vary in price. However, Guillemet said the software-only approach comes with trade-offs, and highlights a fundamental architectural difference between “general-purpose” phone chips and those specifically designed for private key protection.

“General-purpose chips are built for convenience,” he wrote. “Secure Elements are built for key protection. A dedicated Secure Element isolates secrets from the rest of the system, protecting them even under physical attack.”

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Source: https://decrypt.co/360722/android-phone-crypto-wallets-could-be-exposed-to-exploit-heres-who-is-at-risk

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Wormhole Unleashes W 2.0 Tokenomics for a Connected Blockchain Future

Wormhole Unleashes W 2.0 Tokenomics for a Connected Blockchain Future

TLDR Wormhole reinvents W Tokenomics with Reserve, yield, and unlock upgrades. W Tokenomics: 4% yield, bi-weekly unlocks, and a sustainable Reserve Wormhole shifts to long-term value with treasury, yield, and smoother unlocks. Stakers earn 4% base yield as Wormhole optimizes unlocks for stability. Wormhole’s new Tokenomics align growth, yield, and stability for W holders. Wormhole [...] The post Wormhole Unleashes W 2.0 Tokenomics for a Connected Blockchain Future appeared first on CoinCentral.
Share
Coincentral2025/09/18 02:07
BitGo wins BaFIN nod to offer regulated crypto trading in Europe

BitGo wins BaFIN nod to offer regulated crypto trading in Europe

                                                                               BitGo’s move creates further competition in a burgeoning European crypto market that is expected to generate $26 billion revenue this year, according to one estimate.                     BitGo, a digital asset infrastructure company with more than $100 billion in assets under custody, has received an extension of its license from Germany’s Federal Financial Supervisory Authority (BaFin), enabling it to offer crypto services to European investors. The company said its local subsidiary, BitGo Europe, can now provide custody, staking, transfer, and trading services. Institutional clients will also have access to an over-the-counter (OTC) trading desk and multiple liquidity venues.The extension builds on BitGo’s previous Markets-in-Crypto-Assets (MiCA) license, also issued by BaFIN, and adds trading to the existing custody, transfer and staking services. BitGo acquired its initial MiCA license in May 2025, which allowed it to offer certain services to traditional institutions and crypto native companies in the European Union.Read more
Share
Coinstats2025/09/18 06:02
Solana Price Prediction: SOL’s $100 Target Stays On Course While AVAX Grinds Toward $10, but Pepeto’s 300x Presale Shows Moonshot Potential

Solana Price Prediction: SOL’s $100 Target Stays On Course While AVAX Grinds Toward $10, but Pepeto’s 300x Presale Shows Moonshot Potential

Crypto adoption is accelerating in unexpected places. The beta launch of X Money on Elon Musk’s social platform is generating fresh attention for digital payments
Share
Techbullion2026/03/12 09:10