Ledger Warns MediaTek Android Flaw Can Expose Wallet Seeds in 45 Seconds

Ledger Warns MediaTek Android Flaw Can Expose Wallet Seeds in 45 Seconds

N
News Editor 01
2026-07-22 20:40:14
Ledger researchers said a hardware flaw affecting some MediaTek-based Android phones can let attackers extract PINs and wallet seed phrases after 45 seconds of physical access, with up to 25% of Android devices potentially exposed.
LedgerAndroid securityMediaTekcrypto walletseed phrase

Ledger’s security team has disclosed a hardware-level flaw in certain Android phones powered by MediaTek chips. With roughly 45 seconds of physical access, an attacker could extract a device PIN and recover seed phrases or private keys from several widely used crypto wallets. The researchers estimate that as much as 25% of Android phones worldwide could be affected.

The weakness targets the secure boot chain

The finding came from Donjon, Ledger’s internal white-hat research unit. According to the team, the issue sits in MediaTek’s secure boot chain and affects devices that combine MediaTek processors with the Trustonic trusted execution environment, or TEE. An attacker can connect to the phone over USB before Android finishes loading, obtain the key used for full-disk encryption, and then decrypt the data offline.

This is not described as a remote exploit. It depends on brief physical possession of the phone, but the window is short. Once the encrypted storage is opened, sensitive data stored by wallet apps may be exposed.

PoC tests recovered data from major wallet apps

In proof-of-concept testing, Donjon said it successfully extracted sensitive wallet data and seed phrases from Trust Wallet, Kraken Wallet, and Phantom, a wallet widely used in the Solana ecosystem. Ledger CTO Charles Guillemet said smartphones were never designed to function as vaults, and that crypto stored on a phone is only as safe as the weakest part of the device.

Ledger said it published the research to give the industry time to patch the flaw before malicious actors exploit it at scale. The issue can be fixed through software updates, and the team urged users to install the latest security patches released by MediaTek and device manufacturers as soon as possible.

Private key theft is taking a larger share of losses

The report arrives as attacks on personal wallets remain elevated. Data cited from TRM Labs shows that of the $2.1 billion stolen in the first half of 2025, more than 80% came from infrastructure attacks such as private key theft and seed phrase exposure. Chainalysis also said crypto theft losses topped $3.41 billion in 2024, while the share tied to compromises of personal wallets jumped from 7.3% in 2022 to 44% in 2024, with more than 158,000 cases recorded.

That puts fresh attention on the risk of storing meaningful crypto holdings on general-purpose mobile devices. Patch availability, device model, and whether private keys remain on a phone for long periods all shape the level of exposure.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.