Android WebView Flaw Lets Malware Steal Crypto Wallet Seeds: MetaMask, Trust Wallet Halt Imports

Android WebView Flaw Lets Malware Steal Crypto Wallet Seeds: MetaMask, Trust Wallet Halt Imports

N
News Editor 01
2026-07-24 06:35:16
Ledger Donjon discovered a Memory-Mirror vulnerability in Android WebView affecting Android 12-15. Malware in the background can instantly steal seed phrases entered into wallet apps. Trust Wallet, MetaMask, and Phantom have paused seed importing on Android. Users must install the March 2026 security patch.

The Ledger Donjon security team has uncovered a critical vulnerability in Android's System WebView, dubbed Memory-Mirror. It allows a malicious app running in the background to siphon seed phrases from a target wallet's isolated memory via a shared cache, without any visible signs on the wallet app. The attack happens the instant a user enters a recovery phrase.

How Memory-Mirror Works

Android's security architecture isolates apps from each other, but Memory-Mirror exploits the WebView cache to bypass these protections. If a user inputs a new seed while a rogue app lurks in the background, the sensitive data is grabbed from shared cache memory. The exploit requires the user to have installed a malicious app beforehand - a risk amplified by the rise of counterfeit apps in marketplaces and third-party APK installs.

Ledger Donjon researchers urgently advise installing security updates to prevent this vulnerability from compromising mobile wallets.

Affected Devices and Industry Response

Devices running Android 12, 13, 14, and 15 are vulnerable unless patched with the March 2026 security update. Google released the fix for Pixel devices on March 5; Samsung and Xiaomi are expected to roll it out by month's end. Any device not showing a version ending in .0326 remains at risk.

Leading software wallets have taken swift action. Trust Wallet (the top hot wallet per CoinGecko) and MetaMask have suspended their "Import Seed" functions on Android until devices are confirmed patched. Phantom has also halted seed-based logins on Android as a precaution.

Steps Users Should Take

Check your Android device's Software Update section. If the version ends in .0326, the critical fix is installed. If the manufacturer hasn't delivered the patch yet, avoid entering any new recovery phrase on that device. Beyond Memory-Mirror, on-screen keyboards, clipboard apps, and screen recorders can also expose seed data. Hardware wallets like those from Ledger are unaffected since recovery phrases never leave the encrypted chip.

Until the security update is applied, do not input seed phrases on mobile. Memory-Mirror directly attacks wallet apps' core defenses, and unaddressed, it could lead to severe loss of digital assets.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.