trade crypt

MediaTek Android vulnerability risking crypto wallets via USB — Urgent

HomeMarketsMediaTek Android vulnerability risking crypto wallets via USB — Urgent

-

A security vulnerability has been discovered in certain Android smartphones equipped with MediaTek processors, posing a risk to crypto wallets through USB access. This exploit allows attackers to extract encrypted user data in under a minute. In a demonstration, security researchers were able to compromise a Nothing CMF Phone 1 in under 45 seconds. This vulnerability could potentially expose sensitive information such as PINs and seed phrases, threatening the security of personal cryptocurrency holdings Source.

The MediaTek Android vulnerability centers on an exploit of the device’s secure boot chain, which is crucial in ensuring the safety of the booting process. This vulnerability allows attackers to connect via USB, intercept, and extract root cryptographic keys before the operating system (OS) initializes. This interception enables offline decryption of user data, meaning that encrypted information can be accessed without booting the Android OS. Importantly, this method enables the recovery of crucial security elements such as PINs, decryption of storage, and extraction of seed phrases from crypto wallets.

The vulnerability was publicly demonstrated by the security research team known as Donjon, who successfully executed the exploit on a Nothing CMF Phone 1. They managed to compromise the phone’s security in less than 45 seconds, showcasing the potential ease and speed of such attacks. The capability to perform this attack without the OS initialization underscores the severity of the threat posed to personal and financial data stored on affected devices.

Ledger disclosed the vulnerability to MediaTek and Trustonic under a 90-day responsible disclosure policy. MediaTek publicly disclosed the vulnerability earlier this month. The security research team involved in the demonstration is known as Donjon. Source: Provided Content

The Nothing CMF Phone 1 is a known device on which the vulnerability was demonstrated. Other devices using MediaTek chips include Solana Seeker and smartphones from Samsung, Motorola, Xiaomi, POCO, Realme, Vivo, OPPO, Tecno, and iQOO. It is not yet clear which other handsets may be susceptible beyond the Nothing CMF Phone 1. The exposure could extend beyond crypto wallets to messages, photos, financial information, and account credentials. Source: Provided Content

This section summarizes the disclosure timeline and lists devices known to use MediaTek chips without asserting which additional handsets are affected. It records that Ledger notified MediaTek and Trustonic under a 90-day policy and that MediaTek made a public disclosure earlier this month. The overview also notes the types of user data identified as at risk. Source: Provided Content

The Chainalysis July 2025 report found that personal wallet compromises represented 23.35% of all stolen fund activity year-to-date in 2025. The security research team responsible for the demonstration is known as Donjon, and the team also issued direct statements describing the vulnerability.

“Donjon has struck again, discovering a MediaTek vulnerability potentially impacting millions of Android phones. Another reminder that smartphones aren’t built for security.”

“Even when powered off, user data—including PINs and [seed phrases]—can be extracted in under a minute.”

Security researchers demonstrated an exploit against a Nothing CMF Phone 1 that enabled extraction of protected user information via a USB connection. The demonstration underscores potential implications for other Android devices that use MediaTek processors, while it remains unclear which additional handsets may be vulnerable. The vulnerability is associated with risk to personal data stored on affected devices, including cryptocurrency wallet credentials and other sensitive information.

This website and its articles do not provide any investment advisory services within the meaning of applicable regulations. The information published may be incomplete, outdated, or contain errors. The author makes no representation or warranty regarding the accuracy, completeness, or timeliness of the information presented. Use of this information is entirely at the reader’s own risk. Under no circumstances shall the author be held liable for financial decisions made on the basis of the content published on this website.
Crypto Fan
Crypto Fanhttps://calipsu.com
Calipsu.com is dedicated to providing clear, reliable, and accessible information about cryptocurrencies, blockchain technology, and decentralized finance (DeFi). Its mission is to help readers better understand a rapidly evolving ecosystem that is often complex, technical, and misunderstood. The platform covers a wide range of topics, from major blockchain networks and crypto assets to DeFi protocols, Web3 applications, and emerging trends. The website also publishes practical guides and tutorials that explain how decentralized tools function, such as wallets, staking mechanisms, lending protocols, and liquidity pools. These guides aim to describe processes and risks clearly, helping readers understand the mechanics behind DeFi rather than encouraging participation.

LATEST POSTS

Canada crypto ATM ban advances in Spring Economic Update

Canada crypto ATM ban advances in the Spring Economic Update as regulators target crypto ATMs to curb fraud and money laundering.

AI-generated websites Show 107% Higher Positive Sentiment

By mid-2025, 35% of newly published websites are AI-generated websites or AI-assisted, signaling a rapid AI-driven shift in online content.

What CFTC AI review of crypto registration applications means

CFTC AI review of crypto registration applications is accelerating reviews as the agency trims staff, boosting feedback speed and market surveillance.

Ondo Adds proxy voting for tokenized equities on Platform

Ondo enables proxy voting for tokenized equities, allowing holders to review filings and vote through Broadridge with crypto wallets.

Follow us

116FansLike
745FollowersFollow
148FollowersFollow
trade crypt