Hackers can steal Android PINs and crypto wallet data even when phones are switched off, exposing millions globally




  • Ledger’s Donjon team exploited MediaTek phones, recovering PINs and crypto wallet seed phrases
  • Attackers can extract root cryptographic keys from switched-off Android devices via USB
  • Trustonic’s Trusted Execution Environment fails to prevent attacks on one-quarter of Android devices

Ledger’s white-hat hacking team, the Donjon, discovered a vulnerability in MediaTek-powered Android smartphones which allows attackers to access sensitive data in under a minute.

Using a Nothing CMF Phone 1, the Donjon bypassed the Android operating system completely, recovered the PIN, decrypted storage, and extracted seed phrases from multiple crypto wallets.





Source link

The post Hackers can steal Android PINs and crypto wallet data even when phones are switched off, exposing millions globally first appeared on TechToday.

This post originally appeared on TechToday.

Leave a Reply

Your email address will not be published. Required fields are marked *