No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Crypto

MediaTek chip flaw exposed crypto wallets and passwords without booting Android

March 12, 2026
in Crypto
0
MediaTek chip flaw exposed crypto wallets and passwords without booting Android



Security researchers at Ledger have discovered a major flaw in some Android smartphone chips that lets an attacker siphon encrypted user data like passwords and private keys in a matter of seconds using just a USB connection.

Summary

  • Ledger’s Donjon security team discovered a vulnerability in MediaTek and Trustonic TEE chips that could allow attackers to extract encrypted data from Android phones in under 45 seconds.
  • The exploit bypasses the secure boot chain before Android loads, allowing attackers to recover the device PIN, decrypt storage and extract seed phrases from popular wallets.

The vulnerability was first spotted in January by Ledger’s internal security research team, Donjon, Ledger Chief Technology Officer Charles Guillemet wrote in a recent X post. 

According to Guillemet, the vulnerability affected smartphones powered by MediaTek and Trustonic’s TEE processors. 

MediaTek has since issued a security patch to fix the issue; users who have not installed the latest security updates on their devices may still remain at risk.

White hat hackers were able to penetrate a smartphone from manufacturer Nothing, notably the company’s CMF 1 phone, in under 45 seconds using a laptop.

“Without ever even booting into Android, the exploit automatically recovered the phone’s PIN, decrypted its storage, and extracted the seed phrases from the most popular software wallets,” Guillemet said.

This puts software wallets like Trust Wallet, Base, Kraken Wallet, Rabby, Tangem’s mobile wallet, and Phantom at risk, as the seed phrases and other sensitive credentials are stored locally on the device.

In their report, researchers noted that the vulnerability allowed attackers with physical access to bypass the phone’s security protections through the secure boot chain, which is a core startup process that runs at the highest privilege level before the operating system loads. Subsequently, the attacker can recover the device’s PIN, decrypt its storage, and extract the information.

“This has the potential to affect millions of Android smartphones,” Guillemet added.

Estimates suggest nearly 36 million people manage digital assets on their smartphones, which means that if attackers manage to exploit a vulnerability, it could put a large number of wallets at risk. 

Guillemet advised using devices with dedicated secure elements that are built for key protection and can safeguard sensitive data even under physical attack.

The Ledger team also detailed a separate attack it tested on MediaTek Dimensity 7300 processors (MT6878) in December, where the team used electromagnetic fault injection to disrupt the chip’s boot process. It allowed them to bypass security checks and ultimately gain full control over the smartphone at the highest privilege level.

As covered by crypto.news on several occasions, crypto users have been targeted across multiple platforms, including iOS, macOS, and Windows.

While Android devices are often easier to compromise due to Google’s more open ecosystem and flexible app distribution model, Apple’s iOS devices have also developed unique attack vectors that target users through malicious frameworks embedded inside otherwise legitimate apps.

For instance, last year, security researchers discovered a malicious app that infiltrated both iOS and Android devices by requesting file access and subsequently scanning device storage to extract wallet data. Although not as technically severe in nature as hardware-level exploits, the scheme still managed to steal more than $1.8 million in cryptocurrency.

Around the same time, Kaspersky flagged a malware campaign that spread through malicious software development kits embedded in seemingly harmless apps.

Editorial Team

Editorial Team

Related Posts

China confirms 200 Boeing plane purchase amid US trade talks
Crypto

China confirms 200 Boeing plane purchase amid US trade talks

May 17, 2026
Crypto
Crypto

Crypto Confidence Surges As Italy’s Largest Bank Doubles Holdings In Q1

May 17, 2026
Cointelegraph
Crypto

Intesa Sanpaolo’s Crypto Portfolio Hits $235M as Italy’s Biggest Bank Goes Deeper Into Digital Assets

May 17, 2026
SBI, Rakuten and Nomura prepare crypto investment trusts in Japan - 1
Crypto

SBI, Rakuten and Nomura prepare crypto investment trusts in Japan

May 17, 2026
Israel establishes secret military outposts in Iraq amid Iran tensions
Crypto

Israel establishes secret military outposts in Iraq amid Iran tensions

May 17, 2026
crypto
Crypto

Crypto Report Card: How Institutional Investors Allocated Capital In Q1 2026

May 17, 2026
Load More
Next Post
New Zealand Rules NZDD Stablecoin Not a Financial Product

New Zealand Rules NZDD Stablecoin Not a Financial Product

Popular News

  • What cybersecurity pros can learn from first responders

    What cybersecurity pros can learn from first responders

    0 shares
    Share 0 Tweet 0
  • Sports betting weighs on consumers’ credit health

    0 shares
    Share 0 Tweet 0
  • How to Hire an Accountant

    0 shares
    Share 0 Tweet 0
  • The 10 best banks for college students in 2025

    0 shares
    Share 0 Tweet 0
  • A Step-By-Step Guide • Benzinga

    0 shares
    Share 0 Tweet 0

Latest News

One of the market's hottest trades is everything AI can't replace

One of the market’s hottest trades is everything AI can’t replace

May 17, 2026
0

As investors worry about all of the companies that AI will wipe out, they are rotating into the ones that...

China confirms 200 Boeing plane purchase amid US trade talks

China confirms 200 Boeing plane purchase amid US trade talks

May 17, 2026
0

## Market Snapshot The “Trump-Xi Summit Announcements by May 22” market currently shows a 98.2% YES probability for China announcing...

Career Coaching and Partnership Programs Specialist, College of Business Administration

Career Coaching and Partnership Programs Specialist, College of Business Administration

May 17, 2026
0

Career Coaching and Partnership Programs Specialist, College of Business AdministrationJob No: 557680Work Type: StaffLocations: San MarcosCategories: Unit...

Nvidia is getting some help as it props up S&P 500 earnings growth

Nvidia is getting some help as it props up S&P 500 earnings growth

May 17, 2026
0

Micron is expected to be the second-largest contributor to the index’s overall earnings growth — behind Nvidia, whose impact will...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.