Ledger Security Team Discovers MediaTek Processor Vulnerability That Could Lead to Wallet Mnemonic Theft

Gate News: On March 11, security research team Donjon, a subsidiary of crypto wallet Ledger, discovered a vulnerability in the MediaTek processor secure boot chain. Attackers can physically connect to the phone via USB before the operating system loads to extract encryption keys, decrypt device storage, and obtain the device PIN and encrypted wallet seed phrase within approximately 45 seconds. In a proof-of-concept test, the vulnerability successfully extracted sensitive data from Trust Wallet, a certain exchange wallet, and Phantom wallet applications. Researchers stated that this vulnerability could affect about 25% of Android phones, specifically models using MediaTek chips and Trustonic Trusted Execution Environment. Ledger’s Chief Technology Officer Charles Guillemet said that smartphones were never designed to be vaults. While the vulnerability can be fixed with a patch, it highlights the inherent risks of storing keys on non-secure devices, and users are advised to update security patches as soon as possible.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Kyrgyzstan-based CEX Halts Trading After $15M USDT Cyberattack and Wallet Breach

A Kyrgyzstan-based cryptocurrency exchange suspended trading after hackers stole over $15 million USDT. The attackers moved funds across blockchains to evade detection. The incident highlights risks in centralized exchanges, especially in less regulated areas.

GateNews12m ago

Zonda CEO Reveals 4,503 BTC Cold Wallet Inaccessible as Founder Remains Missing Since 2022

Zonda, a Polish cryptocurrency exchange, faces a crisis as its cold wallet containing 4,503 Bitcoin is inaccessible, prompting a surge in withdrawal requests. CEO Kral claims the private key was never transferred during the company's takeover, and authorities are investigating the situation amid bankruptcy fears.

GateNews3h ago

French Authorities Boost Security for Crypto Executives Amid Kidnapping Threats

French authorities are enhancing security for digital-asset executives and investors due to recent kidnappings. Following these threats, police escorted Paris Blockchain Week attendees, and protective measures for crypto holders are being developed.

GateNews8h ago

Zonda Exchange Discloses 4,500 BTC Cold Wallet as Private Keys Remain Untransferred

Zonda, a Polish crypto exchange, revealed a cold wallet with 4,503 BTC amid a withdrawal crisis. CEO Przemysław Kral addressed fund misappropriation allegations and promised legal action against false claims, emphasizing that private keys were never transferred due to the former CEO's disappearance.

GateNews8h ago

The OneCoin Ponzi scheme begins restitution, with the U.S. Department of Justice setting aside $40 million to compensate victims

The OneCoin Ponzi scheme was founded by Ruja Ignatova in 2014, attracting 3.5 million investors and scamming about $4 billion. The U.S. Department of Justice will provide $40 million in compensation for victims, the founder has gone missing, is listed as the FBI’s No. 1 most-wanted fugitive, and the case has prompted cooperation among law enforcement agencies worldwide, resulting in sanctions against several co-conspirators.

ChainNewsAbmedia9h ago

Rhea Finance Suffers Attack, Loses Approximately $7.6M

Rhea Finance experienced a security breach where an attacker created fake token contracts and manipulated liquidity pools, misleading the oracle system and extracting at least $7.6 million in assets.

GateNews9h ago
Comment
0/400
No comments