Close Menu
Crypto Breaking News
    Crypto Breaking News
    • News
      • Press Release
      • Featured
      • Events
      • Exchanges
      • Bitcoin
      • Ethereum
      • Solana
      • Cardano
      • Ripple
      • Press Releases by PR Newswire
      • News by CoinPedia
      • News by Coincu
      • News by Blockchain Wire
      • Binance News
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    Crypto Breaking News
    Crypto News Exchanges Markets & Finance

    MediaTek patches flaw that enabled crypto seed theft in 45 seconds

    12 March 2026Updated:14 March 2026
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    Mediatek Patches Flaw That Enabled Crypto Seed Theft In 45 Seconds
    Mediatek Patches Flaw That Enabled Crypto Seed Theft In 45 Seconds

    Security researchers have identified a vulnerability affecting certain Android devices powered by MediaTek chipsets that could allow an attacker with physical access to a phone to extract sensitive data using a USB connection. The issue was disclosed by Ledgerโ€™s white-hat security team, Donjon, and MediaTek published a security bulletin on Jan. 5, 2026, providing fixes to device manufacturers. Users who have not yet installed the latest available security updates are advised to do so as soon as possible.

    According to Ledgerโ€™s account shared with Cointelegraph, the vulnerability affected the secure boot chain, the low-level mechanism intended to ensure that a device starts only with authorized software. In a proof-of-concept demonstration, Donjon researchers connected a Nothing CMF Phone 1 to a laptop and were able to compromise the deviceโ€™s protections in roughly 45 seconds.

    Ledger said the attack could allow recovery of a device PIN, decryption of storage, and extraction of seed phrases from several popular software wallets, including Trust Wallet, Base, Kraken Wallet, Rabby, Tangemโ€™s mobile wallet, and Phantom. Importantly, the attack scenario described requires physical access to the device and depends on the phone remaining unpatched.

    MediaTek has already issued fixes to OEMs, and Ledger said it does not expect the issue to remain an ongoing systemic problem once patches are properly deployed. The case nonetheless highlights the security risks that can arise when smartphones are used to store or manage sensitive crypto credentials, especially if devices are lost, stolen, or not kept up to date.

    For users, the immediate takeaway is practical: keep device firmware and security patches current, avoid leaving phones unattended, and consider additional layers of protection for crypto holdings. More broadly, the episode reinforces a longstanding industry discussion around the limits of general-purpose mobile hardware for high-security crypto use cases.

    Key takeaways

    • A vulnerability affecting certain MediaTek-powered Android devices could allow a physically present attacker to extract sensitive data through a USB-based attack path.
    • MediaTek published fixes for the issue on Jan. 5, 2026, and users should install the latest available security updates from their device manufacturer.
    • Ledgerโ€™s Donjon team demonstrated a proof of concept on a Nothing CMF Phone 1 in about 45 seconds.
    • According to Ledger, the exploit could recover a device PIN, decrypt storage, and extract seed phrases from several popular mobile wallets on vulnerable, unpatched devices.
    • The reported attack requires physical access and does not depend on the victim actively unlocking the phone during the attack sequence.

    Sentiment: Neutral

    Market context: The report adds to ongoing concerns around mobile wallet security and reinforces the importance of hardware security, physical device protection, and timely firmware updates for crypto users.

    Why it matters

    As more users rely on smartphones to manage digital assets, any weakness in low-level device security can have outsized consequences. Even if a flaw is patched quickly, the real-world risk can remain meaningful when users delay updates or when device manufacturers take time to distribute fixes. For crypto users in particular, seed phrases and wallet credentials remain high-value targets.

    The case also underscores the importance of independent security research and responsible disclosure. In this instance, Ledgerโ€™s researchers disclosed the issue before public reporting, and MediaTek issued fixes through its normal security process. That sequence matters because it reduces the likelihood of widespread exploitation while still informing users and the broader ecosystem about the need for defensive hygiene.

    What to watch next

    • How quickly OEMs distribute the relevant MediaTek security fixes to affected devices.
    • Whether users apply those updates promptly after they become available.
    • Any further technical clarification from MediaTek, Ledger, or device makers about which models were affected and how mitigation has been implemented.
    • Whether wallet providers add more safeguards for mobile seed storage on general-purpose smartphones.

    Sources & verification

    • Cointelegraph reporting on Ledger Donjonโ€™s findings and MediaTekโ€™s Jan. 5 patch rollout.
    • MediaTekโ€™s January 2026 Product Security Bulletin.
    • Ledger Donjonโ€™s public research discussing smartphone hardware security and MediaTek-related testing.

    Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

    Crypto Breaking News
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • Tumblr
    • LinkedIn

    The Crypto Breaking News editorial team curates the latest news, updates, and insights from the global cryptocurrency and blockchain industry.

    Related Posts

    Cz Claims Rival Crypto Exchanges Opposed His Pardon Bid

    CZ Claims Rival Crypto Exchanges Opposed His Pardon Bid

    3 minutes ago
    Seven Major Bitcoin Mining Pools Back Stratum V2, Form Working Group

    Seven Major Bitcoin Mining Pools Back Stratum V2, Form Working Group

    2 hours ago
    Strategy Limits Btc Sales To Defined Scenarios, Says Phong Le

    Strategy limits BTC sales to defined scenarios, says Phong Le

    4 hours ago
    Attorney: Clarity Act Could Bring Crypto Firms Back To The U.s.

    Attorney: CLARITY Act Could Bring Crypto Firms Back to the U.S.

    6 hours ago
    Nobitex: Iran's Largest Exchange Stays Off Ofac Blacklist

    Nobitex: Iran’s Largest Exchange Stays Off OFAC Blacklist

    8 hours ago
    Regulatory Clarity Could Bring Crypto Firms Back To Us, Lawyer Says

    Regulatory Clarity Could Bring Crypto Firms Back to US, Lawyer Says

    8 hours ago

    Search Crypto News

    Featured Crypto News

    Openvpp Ceo Parth Kapadia On Building The โ€œinternet Of Energyโ€ With Real-Time Blockchain Payments

    OpenVPP CEO Parth Kapadia on Building the “Internet of Energy” With Real-Time Blockchain Payments

    8 May 2026
    Cb Img 41f1c78f D4d2 4cdb 8092 2e2cc5ffc1a8 Gmail Com 1

    2026 Mining Guide: SHR Miner Offers Cryptocurrency Enthusiasts a Profitable Path to Earning $5,777

    8 May 2026
    Tangem Wallet Launches New Promo With Btc Rewards And Prize Draw

    Tangem Wallet launches new promo with BTC rewards and prize draw

    4 May 2026

    Latest News

    • CZ Claims Rival Crypto Exchanges Opposed His Pardon Bid
    • Seven Major Bitcoin Mining Pools Back Stratum V2, Form Working Group
    • Strategy limits BTC sales to defined scenarios, says Phong Le
    • Attorney: CLARITY Act Could Bring Crypto Firms Back to the U.S.
    • Nobitex: Iran’s Largest Exchange Stays Off OFAC Blacklist
    • Regulatory Clarity Could Bring Crypto Firms Back to US, Lawyer Says
    • 2017 Linux flaw resurfaces as a risk to crypto infrastructure
    • Kraken’s Parent Seeks OCC Banking Charter, Expanding Crypto Banking
    • Court Allows Arbitrum DAO to Shift $71M North Korea-Linked ETH to Aave
    • Spot BTC ETFs log 6th straight week of net inflows, first in 9 months

    Join 17,000+ Crypto Followers

    • Facebook2.3K
    • Twitter4.3K
    • Instagram5.6K
    • LinkedIn4K
    • Telegram52
    • Threads800
    AVATRADE
    Global Blockchain Show - Riyadh

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Web3 Digital L.L.C-FZ
    License Number: 2527596
    ๐Ÿ“ž +971 50 449 2025
    โœ‰๏ธ info@cryptobreaking.com
    ๐Ÿ“Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrBlueskyLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions

    advertising

    Bitpanda
    © 2026 CryptoBreaking.com | All rights reserved | Powered by Web3 Digital & Osom One

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!