Ledger’s Donjon research team has disclosed a hardware vulnerability affecting certain Android phones powered by MediaTek chips. The flaw sits in the secure boot chain, letting an attacker with physical access connect a phone to a laptop over USB and break through protections in 45 seconds. In the published test, the researchers used the 2024 Nothing CMF Phone 1, and the attack worked even while the device was powered off.
Seed phrases recovered from major wallet apps
In the demonstration, the team recovered the device PIN, unlocked storage, and extracted seed phrases from several crypto wallet apps. The article names Trust Wallet, Kraken Wallet, Phantom, and Rabby as affected in the test. Once the underlying storage keys are pulled from the device, software defenses such as screen locks and fingerprint authentication no longer offer much protection. The data can then be read on a separate computer, where the PIN can be guessed quickly.
The weakness appears before Android even starts
What makes the issue severe is its position in the boot process. The attack window opens before the operating system loads, not at the app layer and not through a remote exploit path. According to the researchers, an attacker can extract root keys that protect device storage and use them for offline access to stored data. That risk extends beyond crypto holdings to private messages, photos, and login credentials kept on the phone.
Potential exposure spans multiple Android brands
The source says MediaTek chips are used in roughly 25% of Android phones worldwide, which puts the scope in focus. While the public test centered on the Nothing CMF Phone 1, the report lists other brands commonly using MediaTek hardware, including Samsung, Motorola, Xiaomi, OPPO, Vivo, and POCO, along with the crypto-focused Solana Seeker phone. Whether a specific device is exposed depends on the chip inside it and whether the vendor has delivered a patch.
Patch sent to manufacturers, rollout still depends on vendors
Ledger said it notified MediaTek and security firm Trustonic 90 days before public disclosure. MediaTek confirmed it sent a fix to phone makers on January 5, 2026. The vulnerability is being tracked as CVE-2025-20435. Even so, end users still depend on each smartphone brand’s update cycle to receive protection. The source also recommends installing available security updates quickly and keeping significant digital assets in dedicated cold-storage hardware wallets.

