Hackers can steal Android PINs and crypto wallet data even when phones are turned off, exposing millions of people around the world.


  • Ledger’s Donjon team exploited MediaTek phones, recovering PINs and seed phrases from crypto wallets
  • Attackers can extract root cryptographic keys from powered off Android devices via USB
  • Trustonic Trusted Execution Environment Fails to Prevent Attacks on a Quarter of Android Devices

Ledger’s white hat hacker team Donjon discovered a vulnerability in MediaTek-powered Android smartphones that allows attackers to access sensitive data in less than a minute.

Using a Nothing CMF Phone 1, Donjon completely bypassed the Android OS, retrieved the PIN, decrypted the storage, and extracted seed phrases from multiple crypto wallets.



Leave a Comment

Your email address will not be published. Required fields are marked *