• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
Sq Magazine LogoSQ Magazine

Smarter Insights for a Fast-Moving Digital World

  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
Sq Magazine Logo
  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
Home » Cybersecurity

Ledger Researchers Find Android Bug That Risks Crypto Wallets

Published on: March 11, 2026
Sofia Ramirez
Written By
Sofia Ramirez
Sofia Ramirez
Senior Tech Writer • 435 Articles
Sofia Ramirez is a technology and cybersecurity writer at SQ Magazine. With a keen eye on emerging threats and innovations, she helps reader...
LATEST POSTS:
Hackers Abuse Microsoft Teams to Conceal Ransomware Activity
FBI Destroys Massive AI Phishing Empire Linked to $1.9B Theft
ShinyHunters Targets Council of Europe in Major Cyberattack
Barry Elad
Reviewed By
Barry Elad
Barry Elad
Founder & Senior Journalist • 713 Articles
Barry Elad is a seasoned journalist and analyst specializing in finance, technology, AI, and founder of SQ Magazine. He explores the world o...
LATEST POSTS:
Sarvam Becomes AI Unicorn After Massive $234M Funding Round
Anthropic Introduces Age Checks and ID Verification for Claude
New Kimi K2.7 Code Promises Faster AI Coding Workflows
Ledger Android Bug That Reveal Wallet Keys
As Featured In
The New York Times LogoForbes LogoWired LogoDeloitte LogoResearch.com Logo
Share on LinkedIn ChatGPT Perplexity Share on X Share on Facebook

A newly disclosed security flaw in some Android phones could allow attackers to extract crypto wallet keys and PIN codes in under a minute.

Quick Summary – TLDR:

  • Ledger’s security research team Donjon discovered a vulnerability in MediaTek powered Android devices.
  • Attackers with physical access could extract encryption keys through USB before the operating system loads.
  • The flaw may affect around 25 percent of Android smartphones using MediaTek chips and Trustonic Trusted Execution Environment.
  • Researchers warn the issue highlights the risks of storing crypto secrets directly on smartphones.

What Happened?

Security researchers at Ledger have revealed a vulnerability in certain Android devices powered by MediaTek processors that could allow attackers to retrieve sensitive crypto wallet data. The exploit can potentially expose device PIN codes and wallet seed phrases in under a minute if attackers gain physical access to the phone.

The flaw targets a weakness in the secure boot chain used in some MediaTek chipsets, which allows malicious actors to extract encryption keys before the Android operating system fully loads.

🚨 @DonjonLedger has struck again discovering a MediaTek vulnerability potentially impacting millions of Android phones. Another reminder that smartphones aren’t built for security. Even when powered off, user data – including pins & seeds – can be extracted in under a minute.

— Charles Guillemet (@P3b7_) March 11, 2026

Ledger Researchers Identify Vulnerability in MediaTek Chips

The discovery was made by Donjon, Ledger’s internal team of security researchers and white hat hackers. During testing, the team found that an attacker could connect a compromised Android device to a computer through a USB connection before the operating system loads.

From there, the attacker could extract cryptographic keys used to protect Android’s full disk encryption. Once those keys are retrieved, the encrypted device storage can be decrypted offline.

According to the researchers, the entire process could take roughly 45 seconds, allowing attackers to gain access to sensitive information stored on the device.

In proof-of-concept testing, the exploit was able to retrieve wallet seed phrases and sensitive data from several well known cryptocurrency wallet applications, including:

  • Trust Wallet
  • Kraken Wallet
  • Phantom

With access to a wallet mnemonic or seed phrase, attackers can fully control a crypto wallet and transfer funds without needing the device again.

Millions of Android Devices Potentially Affected

Researchers estimate the vulnerability could impact about 25 percent of Android smartphones, particularly devices powered by MediaTek processors that rely on the Trustonic Trusted Execution Environment.

MediaTek chips are widely used in mid-range Android devices around the world, which means a large number of smartphones could theoretically be exposed if the flaw is not patched.

Ledger said the issue can be fixed through firmware and security updates, and users are encouraged to install patches released by MediaTek and smartphone manufacturers as soon as they become available.

Newsletter
Subscribe To Our Newsletter!

Be the first to get exclusive offers and the latest news.

Ledger Warns Smartphones Were Never Meant to Be Vaults

Charles Guillemet, Chief Technology Officer at Ledger, said the discovery reinforces long standing concerns about storing highly sensitive information directly on smartphones.

Ledger Chief Technology Officer Charles Guillemet said in the statement:

“

This research proves what we’ve long warned: smartphones were never designed to be vaults. While this can be patched, and we encourage all users to update with the latest security fixes provided by MediaTek and phone manufacturers, it shows the challenge of storing secrets on non secure devices. If your crypto sits on a phone, it’s only as safe as the weakest link in that phone’s hardware, firmware, or software.

Charles GuillemetChief Technology Officer – Ledger

The company said its goal in publishing the research was to give the industry time to address the flaw before it could be exploited at scale.

Crypto Wallet Attacks Are Increasing

The disclosure comes as attacks targeting cryptocurrency users continue to rise. Security reports show that wallet compromises are becoming a major source of crypto theft.

According to blockchain intelligence firm TRM Labs, infrastructure attacks such as private key theft, seed phrase theft, and front end compromises accounted for more than 80 percent of the 2.1 billion dollars stolen in the first half of 2025.

Data from Chainalysis also shows that losses from crypto theft exceeded 3.41 billion dollars in a single year, with personal wallet compromises becoming significantly more common.

These attacks represented 7.3 percent of stolen crypto value in 2022, but jumped to 44 percent by 2024, impacting more than 158000 individual cases.

The growing trend highlights how attackers are increasingly targeting individual wallet users rather than centralized platforms.

SQ Magazine’s Takeaway

I think this discovery sends a strong message to anyone storing crypto on their phone. Smartphones are convenient, but convenience often comes with security tradeoffs. If a flaw in hardware or firmware can expose wallet seed phrases in less than a minute, that is a serious risk.

In my view, this research reinforces why dedicated hardware wallets exist in the first place. Keeping private keys isolated from everyday devices like phones and laptops remains one of the safest ways to protect crypto assets.

This article has been reviewed and fact-checked by Barry Elad. SQ Magazine follows strict Publishing Principles and a documented Fact-Check Policy to ensure accuracy, transparency, and editorial independence across all content.

Add SQ Magazine as a Preferred Source on Google for updates! Follow on Google News
Share ChatGPT Perplexity
Sofia Ramirez

Sofia Ramirez

Senior Tech Writer


Sofia Ramirez is a technology and cybersecurity writer at SQ Magazine. With a keen eye on emerging threats and innovations, she helps readers stay informed and secure in today’s fast-changing tech landscape. Passionate about making cybersecurity accessible, Sofia blends research-driven analysis with straightforward explanations; so whether you’re a tech professional or a curious reader, her work ensures you’re always one step ahead in the digital world.

Related Posts

MetaMask Users Hit by Fake 2FA Scam: Wallets Drained in Seconds
Cybersecurity

MetaMask Users Hit by Fake 2FA Scam: Wallets Drained in Seconds

UEFI Flaw Lets Hackers Bypass Secure Boot on 200,000 Framework Laptops
Cybersecurity

UEFI Flaw Lets Hackers Bypass Secure Boot on 200,000 Framework Laptops

Malicious Chrome Extension Steals Ethereum Wallets
Cybersecurity

Malicious Chrome Extension Steals Ethereum Wallets

Disclaimer: The content published on SQ Magazine is for informational and educational purposes only. Please verify details independently before making any important decisions based on our content.

Reader Interactions

Leave a Comment Cancel reply

Primary Sidebar

Connect With Us

facebook x linkedin google-news telegram pinterest whatsapp email
google-preferred-source-badge Add as a preferred source on Google

You Should Also Read

Trezor Safe 7 Chip Vulnerability Found in Security Audit
Ledger Hit by Fresh Data Leak Through Third-Party Payment Partner
Bitcoin Core v30 Bug Puts Legacy Wallets at Risk of Total Fund Loss

Table of Contents

  • Quick Summary – TLDR:
  • What Happened?
  • Ledger Researchers Identify Vulnerability in MediaTek Chips
  • Millions of Android Devices Potentially Affected
  • Ledger Warns Smartphones Were Never Meant to Be Vaults
  • Crypto Wallet Attacks Are Increasing
  • SQ Magazine’s Takeaway
Connect on Telegram

Footer

SQ Magazine Logo

Smarter Insights for a Fast-Moving Digital World

Connect With Us

Follow Us on Google News

Editorial & Trust

  • About
  • Publishing Principles
  • Fact-Check Policy
  • Corrections Policy
  • Ethics Policy
  • Disclaimer

Worth Checking

  • Social Media Attention Span Stats
  • Reddit Statistics
  • Spotify User Statistics
  • TikTok vs. Instagram Statistics
  • Gen Z Social Media Statistics
Contact Us
13570 Grove Dr #189,
Maple Grove, MN 55311,
United States
10 a.m. – 6 p.m. | Every day

Copyright © 2022–2026 SQ Magazine. All Rights Reserved. Powered by the Neural Stack.

  • Privacy Policy
  • Terms
Company
  • About Us
  • Our Team
  • Our Mission
  • Core Values
Discover
  • Brand Assets
    Brand Assets
  • Stats Methodology
    Stats Research Process
  • Glossary
    Glossary
Categories
  • Internet
  • Gaming
  • Technology
  • Artificial Intelligence
  • Cybersecurity
Internet
YouTube vs TikTok Statistics 2026: Users, Revenue, Creator Economy
YouTube vs TikTok Statistics 2026: Users, Revenue, Creator Economy
Internet Outage Statistics 2026: Frequency, Cost and Causes
Internet Outage Statistics 2026: Frequency, Cost and Causes
Upwork Statistics 2026: Revenue, GSV, AI Work
Upwork Statistics 2026: Revenue, GSV, AI Work
Instagram Reels Statistics 2026: Plays and Engagement
Instagram Reels Statistics 2026: Plays and Engagement
Gig Economy Statistics 2026: Workforce & Earnings
Gig Economy Statistics 2026: Workforce & Earnings
Doomscrolling Statistics: Prevalence, Sleep and Mental Health
Doomscrolling Statistics: Prevalence, Sleep and Mental Health
Gaming
Online Gambling Regulations Statistics 2026: Global Compliance and Enforcement Data
Online Gambling Regulations Statistics 2026: Global Compliance and Enforcement Data
Fantasy Sports Statistics 2026: Users, Revenue & Trends
Fantasy Sports Statistics 2026: Users, Revenue & Trends
Apex Legends Statistics 2026: Players, Revenue, and Esports
Apex Legends Statistics 2026: Players, Revenue, and Esports
Fortnite Statistics 2026: Players, Revenue, Esports, and Engagement
Fortnite Statistics 2026: Players, Revenue, Esports, and Engagement
Gamers Statistics 2026: Players, Habits & Global Data
Gamers Statistics 2026: Players, Habits & Global Data
Minecraft Statistics 2026: 300 Million Copies Sold & 212M Monthly Players
Minecraft Statistics 2026: 300 Million Copies Sold & 212M Monthly Players
Technology
Employee Productivity Statistics 2026: Engagement, Costs & Trends
Employee Productivity Statistics 2026: Engagement, Costs & Trends
Software Engineer Layoff Statistics 2026: Companies, Roles, AI Impact
Software Engineer Layoff Statistics 2026: Companies, Roles, AI Impact
iPhone Ecosystem Statistics 2026: Big Market Trends
iPhone Ecosystem Statistics 2026: Big Market Trends
Average Screen Time by Age Statistics 2026: Latest Insights
Average Screen Time by Age Statistics 2026: Latest Insights
AI SEO Statistics 2026: Adoption, AI Overviews & LLM Citation Data
AI SEO Statistics 2026: Adoption, AI Overviews & LLM Citation Data
Digital Nomads Statistics 2026: Population, Demographics & Visa Data
Digital Nomads Statistics 2026: Population, Demographics & Visa Data
Artificial Intelligence
AI Image Generation Statistics 2026: Market Size, Adoption & Risks
AI Image Generation Statistics 2026: Market Size, Adoption & Risks
AI Influencer Marketing Statistics: Market Size and Engagement
AI Influencer Marketing Statistics: Market Size and Engagement
AI Market Statistics 2026: Size, Growth & Investment
AI Market Statistics 2026: Size, Growth & Investment
Meta AI Statistics 2026: Users, Capex, and Adoption Data
Meta AI Statistics 2026: Users, Capex, and Adoption Data
Predictive AI Statistics 2026: Market Size, Adoption & Accuracy Data
Predictive AI Statistics 2026: Market Size, Adoption & Accuracy Data
AI Overviews Statistics 2026: Google Search Impact Data
AI Overviews Statistics 2026: Google Search Impact Data
Cybersecurity
Password Statistics 2026: Credential Theft, MFA, and the Passkey Tipping Point
Password Statistics 2026: Credential Theft, MFA, and the Passkey Tipping Point
Identity Theft Statistics 2026: Key Fraud Data and Trends
Identity Theft Statistics 2026: Key Fraud Data and Trends
CVE Statistics 2026: Severity Distribution and Top Affected Vendors
CVE Statistics 2026: Severity Distribution and Top Affected Vendors
Dark Web AI Tool Marketplace Statistics 2026: Explosive Market Growth
Dark Web AI Tool Marketplace Statistics 2026: Explosive Market Growth
API Security Breach Statistics 2026: Hidden Threats
API Security Breach Statistics 2026: Hidden Threats
AI Voice Cloning Fraud Statistics 2026: Alarming Trends You Must Know Now
AI Voice Cloning Fraud Statistics 2026: Alarming Trends You Must Know Now
Categories
  • Internet
  • Gaming
  • Technology
  • Artificial Intelligence
  • Cybersecurity
Internet
Telegram Restricted in India as NEET Fraud Crackdown Grows
Telegram Restricted in India as NEET Fraud Crackdown Grows
UK Unveils Under 16 Social Media Ban With Tough New Rules
UK Unveils Under 16 Social Media Ban With Tough New Rules
Facebook and Instagram Hit by Major Global Outage
Facebook and Instagram Hit by Major Global Outage
Pinterest Bets Big on AI With Record $4B AWS Commitment
Pinterest Bets Big on AI With Record $4B AWS Commitment
Lovable Expands Google Cloud Deal, Boosts AI Infrastructure 5x
Lovable Expands Google Cloud Deal, Boosts AI Infrastructure 5x
Shopify Down: Thousands Report Outage and Checkout Issues
Shopify Down: Thousands Report Outage and Checkout Issues
Gaming
Epic Games Teases Unreal Engine 6 for Rocket League
Epic Games Teases Unreal Engine 6 for Rocket League
Stardew Valley Switch 2 Edition Arrives with Online Co-op
Stardew Valley Switch 2 Edition Arrives with Online Co-op
Hogwarts Legacy Crosses 40M Sales, Beating Industry Giants
Hogwarts Legacy Crosses 40M Sales, Beating Industry Giants
PUBG: Black Budget Launches Closed Alpha Test With a Bold PvPvE Twist
PUBG: Black Budget Launches Closed Alpha Test With a Bold PvPvE Twist
Counter-Strike 2’s $5.9 Billion Skin Economy Just Got Shattered
Counter-Strike 2’s $5.9 Billion Skin Economy Just Got Shattered
Battlefield 6 Outperforms Franchise Past with Record-Breaking Launch
Battlefield 6 Outperforms Franchise Past with Record-Breaking Launch
Technology
Android 17 Is Here With Powerful AI Features and Security Boosts
Android 17 Is Here With Powerful AI Features and Security Boosts
Telegram Returns to Wear OS With Smartwatch App Upgrade
Telegram Returns to Wear OS With Smartwatch App Upgrade
Apple Announces macOS 27 Golden Gate at WWDC 2026
Apple Announces macOS 27 Golden Gate at WWDC 2026
Apple iPadOS 27 Introduces New Siri App and Productivity Tools
Apple iPadOS 27 Introduces New Siri App and Productivity Tools
Microsoft Reveals Xbox Series X25 Limited Edition Console
Microsoft Reveals Xbox Series X25 Limited Edition Console
Leaked iOS 27 Features Include AI Siri and More iPhone Support
Leaked iOS 27 Features Include AI Siri and More iPhone Support
Artificial Intelligence
SpaceX Makes Bold $60 Billion Bet on Cursor AI
SpaceX Makes Bold $60 Billion Bet on Cursor AI
Sarvam Becomes AI Unicorn After Massive $234M Funding Round
Sarvam Becomes AI Unicorn After Massive $234M Funding Round
Anthropic Introduces Age Checks and ID Verification for Claude
Anthropic Introduces Age Checks and ID Verification for Claude
New Kimi K2.7 Code Promises Faster AI Coding Workflows
New Kimi K2.7 Code Promises Faster AI Coding Workflows
US Blocks Anthropic Fable 5 Access Over Security Fears
US Blocks Anthropic Fable 5 Access Over Security Fears
McDonald’s Tests Powerful New AI Drive Thru With Google
McDonald’s Tests Powerful New AI Drive Thru With Google
Cybersecurity
Hackers Abuse Microsoft Teams to Conceal Ransomware Activity
Hackers Abuse Microsoft Teams to Conceal Ransomware Activity
FBI Destroys Massive AI Phishing Empire Linked to $1.9B Theft
FBI Destroys Massive AI Phishing Empire Linked to $1.9B Theft
ShinyHunters Targets Council of Europe in Major Cyberattack
ShinyHunters Targets Council of Europe in Major Cyberattack
Urgent Oracle PeopleSoft Flaw Linked to ShinyHunters Campaign
Urgent Oracle PeopleSoft Flaw Linked to ShinyHunters Campaign
73,000 French Government Accounts Exposed in Tchap Breach
73,000 French Government Accounts Exposed in Tchap Breach
High Risk Microsoft Teams Android Bug Could Leak Sensitive Data
High Risk Microsoft Teams Android Bug Could Leak Sensitive Data
Newsletter

Subscribe To Our Newsletter!

Be the first to get exclusive offers and the latest news.

Newsletter

Subscribe To Our Newsletter!

Be the first to get exclusive offers and the latest news.