Home MediaTek Fixes Critical Bug That Could Expose Crypto Seed Phrases

MediaTek Fixes Critical Bug That Could Expose Crypto Seed Phrases

Share
MediaTek Fixes Critical Bug That Could Expose Crypto Seed Phrases
News
Share

A significant vulnerability that might have allowed hackers to retrieve bitcoin wallet seed phrases from compromised Android smartphones in less than a minute has been fixed by mobile chip manufacturer MediaTek.

Donjon, the security research branch of Ledger, a hardware wallet firm, found the vulnerability. MediaTek was able to deliver a security patch on January 5 when researchers informed them of the problem prior to it being made public.

Ledger claims that MediaTek’s secure boot chain—a mechanism intended to guarantee smartphones start safely using approved applications during startup—was the source of the vulnerability.

Due to the vulnerability, an attacker with physical access to a device might utilise USB to connect the phone to a computer and get around important security measures. This would make it possible to access private information kept on the device, such as seed phrases for cryptocurrency wallets.

Phones that employ MediaTek processors and the Trustonic Trusted Execution Environment (TEE), a security architecture found in about 25% of Android handsets globally, are vulnerable.

In order to demonstrate the exploit, Ledger researchers connected a Nothing CMF Phone 1 to a laptop and compromised the device in roughly 45 seconds. The assault recovered the device’s PIN, decrypted its storage, and got past the phone’s security measures during the test.

After gaining access, the attack was able to retrieve seed phrases from a number of well-known mobile wallets, such as Phantom, Trust Wallet, Base Wallet, Kraken Wallet, Rabby, and Tangem Mobile Wallet.

Users are highly encouraged to get the most recent security updates to safeguard their devices, even if MediaTek has already provided a patch.

Millions of individuals use smartphones to directly handle digital assets, according to security experts. With an estimated 36 million people storing cryptocurrency on mobile devices, a single vulnerability might put a sizeable number of wallets in danger.

Additionally, Charles Guillemet, chief technology officer at Ledger, cautioned that smartphones are typically not made for the highest levels of key security. Sensitive information, like private keys and seed phrases, is better protected by specialised hardware solutions with secure components.

Share
Written by
Kapil Rajyaguru -

Kapil Rajyaguru is a news editor at 3.0 TV with over 15 years of professional writing experience and more than four years dedicated to the cryptoverse.

An engineer by education and a writer by passion, Kapil brings a rare mix of technical insight and storytelling finesse. A firm believer that cryptocurrencies, blockchain and AI are the building blocks of the future, he crafts in-depth news and analysis to educate, empower and prepare the masses for the next frontier of Web3.

Leave a comment

Leave a Reply

Latest News

Dubai Police, US & China Avert $562M In Crypto Scam Losses, Unravel "Pig Butchering" Network
News

Dubai Police, US & China Avert $562M In Crypto Scam Losses, Unravel “Pig Butchering” Network

A massive, coordinated international law enforcement operation has struck a blow to the booming cryptocurrency scam industry. Authorities have arrested 276 people...

OKX Rolls Out Agent Payments Protocol For Full AI-driven Transactions
News

OKX Rolls Out Agent Payments Protocol For Full AI-driven Transactions

OKX has introduced an open standard for agent-led transactions, rolling out its Agent Payments Protocol (APP) to support full-cycle business activity handled...

Wall Street To Launch The First Ever Prediction Market ETFs For U.S. Elections
News

Wall Street To Launch The First Ever Prediction Market ETFs For U.S. Elections

Roundhill Investments is set to launch the first U.S. exchange-traded funds (ETFs) tied to prediction markets next week, with two other asset...

MoonPay Acquires Israeli Crypto Security Firm Sodot In $100M Stock Deal
News

MoonPay Acquires Israeli Crypto Security Firm Sodot In $100M Stock Deal

Crypto payments firm MoonPay has acquired Sodot, an Israeli crypto security startup, as part of its plan to launch MoonPay Institutional, a...

Latest Blogs

“Click, Token, Own!” Why RWA Is The Future Of Finance?

A financial revolution, RWA tokenization bringing real-world assets onto blockchain RWA tokenization increases accessibility, quickness and transparency, pushing markets to expand rapidly,...

Top 5 Ways To Spot The Best AI Coin

Artificial Intelligence (AI) is the talk of the town as it goes on to completely alter the intrinsic landscape of our industries...

Stablecoins Go Mainstream: How Hong Kong’s Bold Regulation Is Shaping Future Of Digital Finance

The word “stablecoin” is no longer limited to tech jargon in today’s quickly changing financial scene. It is now a structural component...

How Blockchain Is Revolutionizing Real Estate Market

Introduction The real estate business is seeing significant, long-term expansion, fueled by expanding urbanization and increased investments. As it is, the global...

Related Articles

“Click, Token, Own!” Why RWA Is The Future Of Finance?

A financial revolution, RWA tokenization bringing real-world assets onto blockchain RWA tokenization...

Top 5 Ways To Spot The Best AI Coin

Artificial Intelligence (AI) is the talk of the town as it goes...

Stablecoins Go Mainstream: How Hong Kong’s Bold Regulation Is Shaping Future Of Digital Finance

The word “stablecoin” is no longer limited to tech jargon in today’s...

How Blockchain Is Revolutionizing Real Estate Market

Introduction The real estate business is seeing significant, long-term expansion, fueled by...