logo

The Ledger security team discovered an Android vulnerability that can extract cryptocurrency wallet recovery phrases in 45 seconds

By: rootdata|2026/03/11 21:43:43
0
Share
copy

According to The Block, Ledger's security research team Donjon has discovered a vulnerability in the secure boot chain of MediaTek processors, allowing attackers to extract encryption keys via USB connection before the operating system loads, provided they have physical access to the phone. This could enable them to decrypt device storage and obtain the device PIN code and encrypted wallet mnemonic within approximately 45 seconds.

In proof-of-concept tests, the vulnerability successfully extracted sensitive data from wallet applications such as Trust Wallet, Kraken Wallet, and Phantom. Researchers indicate that this vulnerability may affect about 25% of Android phones, involving models that use MediaTek chips and Trustonic's Trusted Execution Environment. Ledger's Chief Technology Officer Charles Guillemet stated that smartphones were never designed to be vaults. Although the vulnerability can be patched, it highlights the inherent risks of storing keys on non-secure devices, and users are advised to update security patches as soon as possible.

According to data from TRM Labs, over 80% of the $2.1 billion in stolen crypto assets in the first half of 2025 stemmed from infrastructure attacks such as private key theft, mnemonic theft, and front-end hijacking. Chainalysis data shows that losses from crypto asset theft exceeded $3.41 billion in 2024, with the proportion of stolen personal wallets rising from 7.3% in 2022 to 44% in 2024.

-- Price

--

You may also like

Tom Lee's Ethereum Thesis: Why the Man Who Called the Last Cycle Is Doubling Down on Bitmine

Tom Lee is emerging as one of Ethereum’s most influential supporters. From Fundstrat to Bitmine, his Ethereum thesis combines staking yield, treasury accumulation, and long-term network value. Here is why “Tom Lee Ethereum” has become one of crypto’s most watched narratives.

Naval personally takes the stage: The historic collision between ordinary people and venture capital

Naval personally stepped in as the chairman of the USVC Investment Committee. This SEC-registered fund launched by AngelList attempts to bring top private tech assets like OpenAI, Anthropic, and xAI to the general public with a $500 entry threshold. It is not just a new fund, but a structural experi...

a16z Crypto: 9 Charts to Understand the Evolution Trends of Stablecoins

Stablecoins are evolving from trading tools into universal payment infrastructure, and this process is quieter and more thorough than most people expected.

Refutation of Yang Haipo's "The End of Cryptocurrency"

This may be the true test of cryptocurrency. It's not about whether the price has reached a new high, nor about who will achieve financial freedom in the next bull market, but rather whether, after all the grand narratives have been washed away by cycles, it can still leave behind some simpler, more...

Can a hairdryer earn $34,000? Interpreting the reflexivity paradox of prediction markets

Prediction markets are essentially betting on reality, and when participants can access or even influence this path earlier, the market no longer just reflects reality but begins to shape it in return.

6MV Founder: In 2026, the "landmark turning point" for crypto investment has arrived

"I will deploy funds in 2026, so I will tell you this is the best year in history."

Contents

Popular coins

Latest Crypto News

Read more