Microsoft has disclosed an Android-native security flaw that exposed 30 million crypto wallet credentials to malicious actors. The issue was tied to a version of the EngageLab SDK and allowed attackers to bypass Android’s sandbox protections, monitor app activity, and send sensitive user data back to hackers.
The flaw was traced to EngageLab SDK 4.5.4
According to Microsoft’s Defender Security Research Team, the vulnerability was first identified during routine security research in April 2025. The attack started when a user installed a malicious app designed to evade the Android sandbox. That app then sent a message to a vulnerable SDK, specifically version 4.5.4.
SDKs are core components used by mobile apps, and many apps rely on several of them at once. Microsoft said the crafted message could corrupt other apps that received it, tricking them into granting read and write access to internal data. In affected cases, that included crypto wallet seed phrases and addresses.
Microsoft classified the method as intent redirection
The company described the exploit as an intent redirection attack. Microsoft said the issue affected more than 50 million apps, including around 30 million crypto wallets. The scale suggests the exposure went beyond a single wallet provider and touched a wider set of Android apps using the vulnerable component.
The core problem was the breakdown of app isolation. Android’s sandbox is meant to keep apps from accessing each other’s data, but this flaw let attackers cross that boundary and obtain permissions that should not have been available. That opened a path to highly sensitive wallet information.
Patch released after work with Google and Android security teams
Microsoft said it worked with Google and the Android Security Team in May 2025, after which EngageLab released a patched version, SDK 5.2.1. Users are now being told to update their apps quickly and check protection status with Google Play Protect.
Microsoft also advised users to download apps from the Play Store instead of sideloading APK files from websites, since Play Store apps go through stricter security checks. For users who have not updated apps since mid-2025, the guidance is to move wallet funds into new wallets with fresh seed phrases.
Another warning in a series of Android crypto security cases
The report adds to a growing list of Android-related security issues tied to crypto activity. The source also noted that another flaw involving Android chips was flagged early last month. Separately, the US Treasury and crypto firms recently announced a collaboration to share cybersecurity information.

