MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: MediaTek fixes a vulnerability that allowed attackers to steal crypto seed data in only 45 seconds
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$72,966.002.79%
  • ethereumEthereum(ETH)$2,242.713.25%
  • tetherTether(USDT)$1.000.03%
  • rippleXRP(XRP)$1.361.91%
  • binancecoinBNB(BNB)$607.701.25%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$85.153.78%
  • tronTRON(TRX)$0.318133-0.17%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.15%
  • dogecoinDogecoin(DOGE)$0.0942403.17%
Crypto NewsBitcoin

MediaTek fixes a vulnerability that allowed attackers to steal crypto seed data in only 45 seconds

rahulbadiyafad150c105
Last updated: March 12, 2026 10:45 am
rahulbadiyafad150c105
Published: 4 weeks ago
Share

MediaTek fixed a security vulnerability in its mobile chipsets earlier this year that could have allowed attackers to steal cryptocurrency seed phrases from affected devices using only a USB cable and specialized software.

Contents
  • Test device compromised in 45 seconds
  • Mobile phones are not fully secure, Ledger warns

The issue was discovered by the white-hat security team Donjon at the crypto hardware company Ledger. The researchers responsibly disclosed the vulnerability to MediaTek before the company released a security patch on Jan. 5. Users who have not yet installed the latest security updates are advised to update their devices as soon as possible.

Test device compromised in 45 seconds

According to Ledger, the vulnerability originated in MediaTek’s secure boot chain — a built-in security mechanism that ensures a smartphone boots only with trusted and authorized software.

In a statement shared with Cointelegraph, Ledger explained that the flaw could allow an attacker with physical access to an Android device to connect it to a computer via USB and bypass certain security protections. This could potentially expose sensitive data stored on the device, including cryptocurrency wallet seed phrases.

About 25% of Android smartphones rely on the Trustonic Trusted Execution Environment (TEE) along with processors from MediaTek — the components affected by the discovered vulnerability.

Researchers from the Donjon security team at Ledger demonstrated the exploit using a Nothing CMF Phone 1 connected to a laptop. The team was able to compromise the device’s security in roughly 45 seconds.

“Without ever booting into Android, the exploit automatically recovered the phone’s PIN, decrypted its storage, and extracted seed phrases from several popular software wallets,” Ledger explained. The wallets affected in the test included Trust Wallet, Base Wallet, Kraken Wallet, Rabby Wallet, Tangem Mobile Wallet and Phantom Wallet.

Although Ledger advised users to install the latest security updates, a company spokesperson told Cointelegraph that they “don’t anticipate this to be an ongoing issue.”

Mobile phones are not fully secure, Ledger warns

As of early 2025, nearly 36 million people manage their digital assets using mobile devices, meaning even a single vulnerability could potentially place a large number of wallets at risk.

In December 2025, Ledger revealed that it successfully tested an attack on the MediaTek Dimensity 7300 (MT6878) chipset. The researchers were able to bypass its security protections and gain what they described as “full and absolute control over the smartphone.”

Charles Guillemet, chief technology officer at Ledger, previously told Cointelegraph in June 2020 that mobile devices — whether Android or iPhone — make it extremely challenging to run fully secure applications.

He reiterated a similar warning on the social platform X on Wednesday, writing: “Smartphones aren’t built for security. Even when powered off, user data — including PINs and seed phrases — can be extracted in under a minute.”

According to him, the research highlights a fundamental difference in device architecture. General-purpose smartphone chips are primarily designed for convenience and performance, whereas dedicated Secure Elements are specifically built to protect sensitive cryptographic keys. By isolating secrets from the rest of the system, these Secure Elements can keep critical data safe even during physical attacks.

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Expert Says Selling XRP Today is Like Selling Berkshire Hathaway Too Early
Bored Ape Yacht Club is making a comeback — as a metaverse
How football is driving business, investment, and innovation in Africa – The Observer
Bitcoin “Dump” Call Turns Out to Be a Joke, Not a Crash
Solana to $1,000? Why a Spot ETF could be the final catalyst for SOL’s price
TAGGED:AltcoinBitcoinBitcoin WalletBlockchaincryptocurrenciesLedgerScams & CybercrimeSecurity

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article ECB unveils Appia roadmap for tokenized central bank money in Europe
Next Article Metaplanet launches a new venture firm to expand its Bitcoin-focused strategy
© Market Alert News. All Rights Reserved.
 

Loading Comments...
 

    Welcome Back!

    Sign in to your account

    Username or Email Address
    Password

    Prove your humanity


    Lost your password?

    %d