Ledger’s security team has disclosed a hardware-level flaw in certain Android phones powered by MediaTek chips. With roughly 45 seconds of physical access, an attacker could extract a device PIN and recover seed phrases or private keys from several widely used crypto wallets. The researchers estimate that as much as 25% of Android phones worldwide could be affected.
The weakness targets the secure boot chain
The finding came from Donjon, Ledger’s internal white-hat research unit. According to the team, the issue sits in MediaTek’s secure boot chain and affects devices that combine MediaTek processors with the Trustonic trusted execution environment, or TEE. An attacker can connect to the phone over USB before Android finishes loading, obtain the key used for full-disk encryption, and then decrypt the data offline.
This is not described as a remote exploit. It depends on brief physical possession of the phone, but the window is short. Once the encrypted storage is opened, sensitive data stored by wallet apps may be exposed.
PoC tests recovered data from major wallet apps
In proof-of-concept testing, Donjon said it successfully extracted sensitive wallet data and seed phrases from Trust Wallet, Kraken Wallet, and Phantom, a wallet widely used in the Solana ecosystem. Ledger CTO Charles Guillemet said smartphones were never designed to function as vaults, and that crypto stored on a phone is only as safe as the weakest part of the device.
Ledger said it published the research to give the industry time to patch the flaw before malicious actors exploit it at scale. The issue can be fixed through software updates, and the team urged users to install the latest security patches released by MediaTek and device manufacturers as soon as possible.
Private key theft is taking a larger share of losses
The report arrives as attacks on personal wallets remain elevated. Data cited from TRM Labs shows that of the $2.1 billion stolen in the first half of 2025, more than 80% came from infrastructure attacks such as private key theft and seed phrase exposure. Chainalysis also said crypto theft losses topped $3.41 billion in 2024, while the share tied to compromises of personal wallets jumped from 7.3% in 2022 to 44% in 2024, with more than 158,000 cases recorded.
That puts fresh attention on the risk of storing meaningful crypto holdings on general-purpose mobile devices. Patch availability, device model, and whether private keys remain on a phone for long periods all shape the level of exposure.

