The Ledger security team discovered an Android vulnerability that can extract cryptocurrency wallet recovery phrases in 45 seconds
According to The Block, Ledger's security research team Donjon has discovered a vulnerability in the secure boot chain of MediaTek processors, allowing attackers to extract encryption keys via USB connection before the operating system loads, provided they have physical access to the phone. This could enable them to decrypt device storage and obtain the device PIN code and encrypted wallet mnemonic within approximately 45 seconds.
In proof-of-concept tests, the vulnerability successfully extracted sensitive data from wallet applications such as Trust Wallet, Kraken Wallet, and Phantom. Researchers indicate that this vulnerability may affect about 25% of Android phones, involving models that use MediaTek chips and Trustonic's Trusted Execution Environment. Ledger's Chief Technology Officer Charles Guillemet stated that smartphones were never designed to be vaults. Although the vulnerability can be patched, it highlights the inherent risks of storing keys on non-secure devices, and users are advised to update security patches as soon as possible.
According to data from TRM Labs, over 80% of the $2.1 billion in stolen crypto assets in the first half of 2025 stemmed from infrastructure attacks such as private key theft, mnemonic theft, and front-end hijacking. Chainalysis data shows that losses from crypto asset theft exceeded $3.41 billion in 2024, with the proportion of stolen personal wallets rising from 7.3% in 2022 to 44% in 2024.
You may also like

Morning News | The draft amendment to the People's Bank of China Law aims to clarify the legal status of digital renminbi; South Korea will transfer about 40 unregistered virtual asset service providers to law enforcement agencies

The cryptocurrency industry has entered the "Show Me" era: merely relying on vision is no longer enough

Interpreting the Ethereum Foundation's new structure: Reaffirming self-sovereignty amid institutional trends

Former SpaceX engineer reconstructs the financial execution system using first principles

Tidal Investment: We still have a positive outlook on the AI industry chain, but the reasons have changed

Standard Chartered Bank sings a 50x rhapsody again, aiming for AAVE to reach 3500 USD

The interim executive director of the Ethereum Foundation speaks out: What is our mission?

Why does OKX want to start a new company with the parent company of the New York Stock Exchange?

Why Is PAXG Price Different From Gold? 5 Reasons Crypto Traders Should Know

WEEX OpenAPI 101: 5 Powerful Modules, AI Trading Tools, and Grab Up to 70% Revenue Opportunities
Learn how WEEX OpenAPI connects traders, developers, AI agents, and trading platforms. Discover WEEX API features, Binance-compatible integration, automated trading workflows, revenue opportunities, and ecosystem possibilities.

Interview with NDV Founder Jason Huang: Popping the AI Bubble and the Myth of Microstrategy, Seeking the Ultimate Ace in the Crypto Market

Morning Report | Former Ethereum Foundation researcher establishes Ethlabs; EU Parliament Economic Committee passes digital euro regulatory proposal

Dragonfly partner Haseeb: The fastest-growing companies in the future may all be stuck at 149 people

How xBubble Breaks the Deadlock in VC's Heavy Investment in the OPC Economy

The encrypted unicorn Blockstream is deeply embroiled in a serious fraud case

Morning Report | The South Korean Financial Services Commission plans to expand the regulatory sandbox to include virtual assets; the parent company of the New York Stock Exchange, ICE, has reached a partnership with OKX to jointly establish a cryptocu...

Exclusive Interview with Strategy CEO: Putting Aside the Sale of 32 BTC, the 60 Trillion AI Intelligence is the Ultimate Fate of Bitcoin

