Ledger’s Donjon security team has disclosed a critical flaw affecting some Android smartphones powered by MediaTek chips. With physical access and a USB connection, an attacker could extract encrypted data in under 45 seconds, including passwords, wallet-related secrets and seed phrases.
The issue was first identified in January, according to Ledger Chief Technology Officer Charles Guillemet. He said the exploit works before Android even starts loading, at the secure boot stage. That matters because the attack does not need to boot into the operating system to recover the phone PIN, decrypt storage and pull sensitive wallet data stored on the device.
The exploit targets the secure boot chain
Researchers said the weakness sits in the secure boot chain, the core startup process that runs at the highest privilege level before the operating system loads. If that layer is bypassed, the device’s normal protections can be stripped away. From there, the attacker can recover the PIN, decrypt local storage and extract information kept on the phone.
Ledger’s team demonstrated the attack on a Nothing device, specifically the CMF 1, using a laptop. The compromise took less than 45 seconds. Guillemet said the exploit automatically recovered the PIN, decrypted storage and extracted seed phrases from widely used software wallets, all without booting Android.
Software wallets are exposed when secrets stay on-device
The report named Trust Wallet, Base, Kraken Wallet, Rabby, Tangem’s mobile wallet and Phantom as potentially exposed. The common issue is local storage: seed phrases and other sensitive credentials are kept on the handset itself. If an attacker gets hold of the phone and can trigger the flaw, those secrets may be recoverable.
Guillemet said the vulnerability has the potential to affect millions of Android smartphones. The article also cited estimates that nearly 36 million people manage digital assets on their smartphones, putting a large number of wallets at risk if the flaw is exploited in the wild.
Patch released, but unpatched phones remain vulnerable
MediaTek has released a security patch to address the bug. Devices that have not received or installed the latest updates may still be exposed. Guillemet advised using devices with dedicated secure elements for key protection, arguing that such hardware can keep sensitive data protected even during a physical attack.
Ledger also described a separate test carried out in December on the MediaTek Dimensity 7300 (MT6878). In that case, the team used electromagnetic fault injection to disrupt the chip’s boot process, bypass security checks and gain full control of the smartphone at the highest privilege level. The findings show the threat is not limited to a single attack path.
Crypto device risks go beyond Android
The report noted that crypto users have also been targeted on iOS, macOS and Windows. Android is often easier to compromise because of its more open ecosystem and flexible app distribution, but Apple devices have seen their own attack methods, including malicious frameworks hidden inside otherwise legitimate apps.
Last year, researchers found a malicious app that infiltrated both iOS and Android devices by requesting file access and scanning local storage for wallet data. The technique was less severe than a hardware-level exploit, but it still stole more than $1.8 million in cryptocurrency. Around the same period, Kaspersky warned of a campaign spread through malicious software development kits embedded in seemingly harmless applications.

