Skip to content
Critical MediaTek flaw lets attackers steal phone crypto

Critical MediaTek flaw lets attackers steal phone crypto

Itbrief.Au March 11, 2026

Ledger has disclosed a critical vulnerability affecting some Android smartphones that use MediaTek processors and Trustonic's trusted execution environment (TEE). The flaw could let an attacker with physical access extract sensitive data from a powered-off device in under a minute.

Ledger's Donjon security research team demonstrated a proof-of-concept attack against a Nothing CMF Phone 1 connected to a laptop over USB. In the test, the team breached the phone's foundational security within 45 seconds, without booting into Android.

According to Ledger, the exploit recovered the handset PIN, decrypted storage, and extracted seed phrases from several software wallets. Affected apps named by Ledger include Trust Wallet, Base, Kraken Wallet, Rabby, Tangem's Mobile Wallet, Phantom, and others.

Ledger said the weakness sits in MediaTek's secure boot chain, which runs before the operating system loads. A successful attacker could connect the device over USB and extract cryptographic keys that protect Android full-disk encryption.

With those keys, the phone's storage can be decrypted offline and the PIN can be brute-forced quickly, exposing application data on the device, including wallet recovery phrases and other secrets.

The disclosure highlights a broader class of risks that blends traditional mobile security concerns with the growth of software wallets on phones. Under the same conditions, messages, photos, and saved credentials could also be exposed.

Ledger estimates the issue could affect smartphones using MediaTek chips that rely on Trustonic's TEE-roughly a quarter of Android phones. It also cited the Solana Seeker phone as a potentially affected device.

Ledger's description suggests the attack requires access to the phone and a USB connection. Its proof-of-concept used a laptop. The scenario does not require the device to be unlocked or for Android to be running.

Ledger said it found the issue while investigating security behind flash encryption in Android. It also pointed to other phone attacks that do not require user interaction, including so-called zero-click exploits that can take control of a device remotely.

Donjon is Ledger's internal security research team. It audits Ledger products and investigates third-party hardware and software, using responsible disclosure so vendors can issue fixes before criminals exploit vulnerabilities.

Ledger said it disclosed the vulnerability to MediaTek and Trustonic under a 90-day disclosure standard. According to Ledger, MediaTek has confirmed it provided a fix to affected device makers. The vulnerability has been made public as CVE-2025-20435.

Patch distribution for Android devices varies by manufacturer and model. Updates often depend on an original equipment manufacturer integrating vendor fixes into firmware and security releases.

Ledger urged users of affected phones to install the latest available security updates, and argued that upgradeable firmware is important for long-term device security.

For the crypto industry, the disclosure underscores a recurring tension between convenience and custody. Many users keep recovery phrases and keys in software wallets on general-purpose phones, and security teams have long warned that handset compromise can lead directly to theft of digital assets.

Ledger, which sells hardware devices that store private keys offline, said the research is part of a broader effort to improve security across the ecosystem.

"The Ledger Donjon doesn't publish this research to create fear-they publish it so the industry can fix it. That's what the Donjon exists to do," Guillemet added.

Ledger noted it has made a series of security disclosures in recent years, including findings related to Android chips and PIN-bypass attacks affecting other wallets. It said the Donjon team will continue to investigate widely used consumer devices and disclose vulnerabilities to vendors for remediation.

Extracted Entities

Companies (1)

MITRE ATT&CK (1)

Platforms (1)