The Ledger Donjon security team has uncovered a critical vulnerability in Android's System WebView, dubbed Memory-Mirror. It allows a malicious app running in the background to siphon seed phrases from a target wallet's isolated memory via a shared cache, without any visible signs on the wallet app. The attack happens the instant a user enters a recovery phrase.
How Memory-Mirror Works
Android's security architecture isolates apps from each other, but Memory-Mirror exploits the WebView cache to bypass these protections. If a user inputs a new seed while a rogue app lurks in the background, the sensitive data is grabbed from shared cache memory. The exploit requires the user to have installed a malicious app beforehand - a risk amplified by the rise of counterfeit apps in marketplaces and third-party APK installs.
Ledger Donjon researchers urgently advise installing security updates to prevent this vulnerability from compromising mobile wallets.
Affected Devices and Industry Response
Devices running Android 12, 13, 14, and 15 are vulnerable unless patched with the March 2026 security update. Google released the fix for Pixel devices on March 5; Samsung and Xiaomi are expected to roll it out by month's end. Any device not showing a version ending in .0326 remains at risk.
Leading software wallets have taken swift action. Trust Wallet (the top hot wallet per CoinGecko) and MetaMask have suspended their "Import Seed" functions on Android until devices are confirmed patched. Phantom has also halted seed-based logins on Android as a precaution.
Steps Users Should Take
Check your Android device's Software Update section. If the version ends in .0326, the critical fix is installed. If the manufacturer hasn't delivered the patch yet, avoid entering any new recovery phrase on that device. Beyond Memory-Mirror, on-screen keyboards, clipboard apps, and screen recorders can also expose seed data. Hardware wallets like those from Ledger are unaffected since recovery phrases never leave the encrypted chip.
Until the security update is applied, do not input seed phrases on mobile. Memory-Mirror directly attacks wallet apps' core defenses, and unaddressed, it could lead to severe loss of digital assets.

