Home MediaTek Fixes Critical Bug That Could Expose Crypto Seed Phrases

MediaTek Fixes Critical Bug That Could Expose Crypto Seed Phrases

Share
MediaTek Fixes Critical Bug That Could Expose Crypto Seed Phrases
News
Share

A significant vulnerability that might have allowed hackers to retrieve bitcoin wallet seed phrases from compromised Android smartphones in less than a minute has been fixed by mobile chip manufacturer MediaTek.

Donjon, the security research branch of Ledger, a hardware wallet firm, found the vulnerability. MediaTek was able to deliver a security patch on January 5 when researchers informed them of the problem prior to it being made public.

Ledger claims that MediaTek’s secure boot chain—a mechanism intended to guarantee smartphones start safely using approved applications during startup—was the source of the vulnerability.

Due to the vulnerability, an attacker with physical access to a device might utilise USB to connect the phone to a computer and get around important security measures. This would make it possible to access private information kept on the device, such as seed phrases for cryptocurrency wallets.

Phones that employ MediaTek processors and the Trustonic Trusted Execution Environment (TEE), a security architecture found in about 25% of Android handsets globally, are vulnerable.

In order to demonstrate the exploit, Ledger researchers connected a Nothing CMF Phone 1 to a laptop and compromised the device in roughly 45 seconds. The assault recovered the device’s PIN, decrypted its storage, and got past the phone’s security measures during the test.

After gaining access, the attack was able to retrieve seed phrases from a number of well-known mobile wallets, such as Phantom, Trust Wallet, Base Wallet, Kraken Wallet, Rabby, and Tangem Mobile Wallet.

Users are highly encouraged to get the most recent security updates to safeguard their devices, even if MediaTek has already provided a patch.

Millions of individuals use smartphones to directly handle digital assets, according to security experts. With an estimated 36 million people storing cryptocurrency on mobile devices, a single vulnerability might put a sizeable number of wallets in danger.

Additionally, Charles Guillemet, chief technology officer at Ledger, cautioned that smartphones are typically not made for the highest levels of key security. Sensitive information, like private keys and seed phrases, is better protected by specialised hardware solutions with secure components.

Share
Written by
Kapil Rajyaguru -

Kapil Rajyaguru is a news editor at 3.0 TV with over 15 years of professional writing experience and more than four years dedicated to the cryptoverse.

An engineer by education and a writer by passion, Kapil brings a rare mix of technical insight and storytelling finesse. A firm believer that cryptocurrencies, blockchain and AI are the building blocks of the future, he crafts in-depth news and analysis to educate, empower and prepare the masses for the next frontier of Web3.

Leave a comment

Leave a Reply

Latest News

Revolut Secures Full Banking License In UK
News

Revolut Secures Full Banking License In UK

Revolut, a cryptocurrency-friendly fintech startup, has officially obtained a full banking licence in the UK, enabling it to grow its clientele and...

Bullish Overtakes Coinbase To Become Third-largest Crypto Exchange
News

Bullish Overtakes Coinbase To Become Third-largest Crypto Exchange

Crypto trading platform Bullish has risen to the third top position among the three centralised exchanges by spot trading volume. It has...

MediaTek Fixes Critical Bug That Could Expose Crypto Seed Phrases
News

MediaTek Fixes Critical Bug That Could Expose Crypto Seed Phrases

A significant vulnerability that might have allowed hackers to retrieve bitcoin wallet seed phrases from compromised Android smartphones in less than a...

SEC & CFTC Agree To Coordinate Crypto Market Regulation
News

SEC & CFTC Agree To Coordinate Crypto Market Regulation

The Securities and Exchange Commission (SEC) and the Commodity Futures Trading Commission (CFTC), two of the most potent financial authorities in the...

Latest Blogs

AI-enabled Fraud: Real Cases, Scammer Tactics & Smart Prevention Tips

Hey, congratulations! You won the Rs 2 Crore lottery. To withdraw funds, share your bank details along with a one-time password (OTP)...

Healthcare Will Never Be The Same, Thanks To Blockchain

We have all heard this famous saying, “Health is Wealth’. Success, wealth, and accomplishments are meaningless without good health. Nothing is more...

AI-enabled Fraud Detection In Digital Finance

Do you remember the last time you used an Automated Teller Machine(ATM) to withdraw money? Well, with the advent of Unified Payments...

“Bitcoin Hi Bhavishya Hai?” A Latest Statement Of Michael Saylor About BTC

Key Takeaways In the Sujal Show podcast, Michael Saylor shared easy lessons about Bitcoin and saving money. He said Bitcoin is like...

Related Articles

AI-enabled Fraud: Real Cases, Scammer Tactics & Smart Prevention Tips

Hey, congratulations! You won the Rs 2 Crore lottery. To withdraw funds,...

Healthcare Will Never Be The Same, Thanks To Blockchain

We have all heard this famous saying, “Health is Wealth’. Success, wealth,...

AI-enabled Fraud Detection In Digital Finance

Do you remember the last time you used an Automated Teller Machine(ATM)...

“Bitcoin Hi Bhavishya Hai?” A Latest Statement Of Michael Saylor About BTC

Key Takeaways In the Sujal Show podcast, Michael Saylor shared easy lessons...