Articles
Crypto Market Analysis

MediaTek patches bug enabling crypto seed theft in just 45 seconds

User Image

بواسطة مجهول

تم الإنشاء March 12, 2026|2 دقائق للقراءة
Main Image

Ledger’s white-hat security team said it found a flaw in MediaTek's secure boot chain that can be used to steal sensitive information from certain Android devices.

Mobile phone chipmaker MediaTek patched a vulnerability affecting its chipsets in January that could have allowed an attacker to steal crypto seed phrases on affected devices using just a USB cable and the right software. 

The flaw was discovered by Ledger’s white-hat security team, Donjon, who had shared the vulnerability with MediaTek before a patch was rolled out on Jan. 5, though users who have not installed the latest security patches are advised to do so, said Ledger. 

According to Ledger, the flaw came from MediaTek’s secure boot chain, a security mechanism built into its chips that ensures a phone starts safely and only with authorized software during startup. 

In a statement shared with Cointelegraph, Ledger explained that the flaw meant an attacker with access to an Android phone could connect it to a computer via USB and bypass security protections, potentially gaining access to sensitive data on the device, including crypto wallet seed phrases. 

Around 25% of Android phones use the Trustonic Trusted Execution Environment (TEE) and MediaTek processors, which the security flaw exploits.

Donjon demonstrated the hack by connecting a Nothing CMF Phone 1 to a laptop and compromising the device’s security in approximately 45 seconds. 

“Without ever even booting into Android, the exploit automatically recovered the phone’s PIN, decrypted its storage, and extracted the seed phrases from the most popular software wallets: Trust Wallet, Base, Kraken Wallet, Rabby, Tangem’s Mobile Wallet and Phantom,” Ledger said.

While Ledger urged users to update their devices, a Ledger spokesperson told Cointelegraph they “don’t anticipate this to be an ongoing issue.” 

With almost 36 million people managing digital assets on their phones as of early 2025, even a single vulnerability could put a significant number of wallets at risk.

In December 2025, Ledger revealed that it tested an attack on the MediaTek Dimensity 7300 (MT6878), and bypassed its security measures to gain “full and absolute control over the smartphone, with no security barrier left standing.”

Ledger chief technology officer Charles Guillemet told Cointelegraph in June 2020 that mobile phones, whether Android or iPhone, are “very difficult to have secure applications.”

Related: SlowMist introduces Web3 security stack for autonomous AI agents

He reinforced a similar view on Wednesday, posting on X:  “Smartphones aren’t built for security. Even when powered off, user data - including pins & seeds - can be extracted in under a minute.” 

“This research highlights a fundamental architectural difference: General-purpose chips are built for convenience. Secure Elements are built for key protection. A dedicated Secure Element isolates secrets from the rest of the system, protecting them even under physical attack,” he said.

Magazine: All 21 million Bitcoin is at risk from quantum computers

Source: CoinTelegraph


مقالات أخرى نشرت مؤخرا

Bitcoin to $100K in Q2? Strategy’s STRC unlocks potential to buy 3K BTC in two days
Bitcoin to $100K in Q2? Strategy’s STRC unlocks potential to buy 3K BTC in two days

Bitcoin

Strategy’s potential 3,127 BTC buy this week, alongside falling stablecoin dominance, suggests mor...

US government asks for $1M forfeiture from ex-Celsius exec ahead of sentencing
US government asks for $1M forfeiture from ex-Celsius exec ahead of sentencing

Crypto Market Analysis

Former Celsius chief revenue officer Roni Cohen-Pavon, scheduled to be sentenced on Thursday after a...

Societe Generale deploys stablecoins on Canton for tokenized finance
Societe Generale deploys stablecoins on Canton for tokenized finance

Blockchain

France's SocGen plans to use its EURCV and USDCV stablecoins for tokenized collateral, repo financin...

Price predictions 5/13: BTC, ETH, BNB, XRP, SOL, DOGE, HYPE, ADA, ZEC, BCH
Price predictions 5/13: BTC, ETH, BNB, XRP, SOL, DOGE, HYPE, ADA, ZEC, BCH

Bitcoin

Bitcoin’s pullback is expected to find support near $79,000, but every recovery attempt is likely ...

Bitcoin traders expect ‘fast move’ to $90K following CLARITY Act vote
Bitcoin traders expect ‘fast move’ to $90K following CLARITY Act vote

Bitcoin

Bitcoin traders eye a possible move higher as short-term selling pressure fades and the CLARITY Act ...

Polymarket's monthly volume declines for first time since August
Polymarket's monthly volume declines for first time since August

Trading Strategies

Prediction markets trading volume had been tracking monthly gains as the sector gains popularity amo...