Hackers can steal Android PINs and crypto wallet data even when phones are turned off, exposing millions globally


  • Ledger’s Donjon team leveraged MediaTek phones, recreated PINs and crypto wallet seed sets
  • Attackers can extract cryptographic root keys from powered-down Android devices via USB
  • Trustonics Trusted Execution Environment does not prevent attacks on a quarter of Android devices

Ledger’s white-hat hacking team, Donjon, discovered a vulnerability in MediaTek-powered Android smartphones that allows attackers to access sensitive data in less than a minute.

Using a Nothing CMF Phone 1, Donjon completely bypassed the Android operating system, recovered the PIN, decrypted storage and extracted seed phrases from several crypto wallets.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top