Mcap -- BTC -- ETH -- SOL -- BNB -- XRP -- F&G -- View Market
Loading prices…

Ledger: MediaTek Flaw Can Steal Crypto Seeds From 25% of Android

Cracked smartphone revealing circuit board and seed phrase data with electromagnetic pulses representing the MediaTek chip vulnerability discovered by Ledger

A critical pair of vulnerabilities in MediaTek processors could allow attackers to steal cryptocurrency seed phrases from roughly one in four Android phones, according to research published by Ledger’s white-hat security team, Donjon, in March 2026. The more alarming of the two flaws is permanently unfixable because it resides in the chip’s immutable Boot ROM, a component baked into the silicon during manufacturing. With an estimated 36 million people managing digital assets on mobile devices, the discovery puts the security of software-based crypto wallets on smartphones into serious doubt.

The research demonstrated full device compromise on a Nothing CMF Phone 1 in under 45 seconds, successfully extracting seed phrases from popular wallets including Trust Wallet, Kraken Wallet, and Phantom. Devices from major manufacturers such as Samsung, Motorola, Xiaomi, and OPPO could also be affected if they use MediaTek processors paired with Trustonic’s Trusted Execution Environment (TEE).

Perhaps most notably, the Solana Seeker, a crypto-focused smartphone built on the MediaTek Dimensity 7300 chip, sits squarely in the crosshairs. Solana Mobile has continued its token launch plans despite the security concerns, highlighting the tension between crypto adoption on mobile devices and the fundamental hardware limitations of consumer-grade chips.

Two Exploits, One Chip: What Ledger’s Donjon Found

Ledger’s security researchers, Charles Christen and Leo Benito, uncovered two distinct attack vectors targeting MediaTek’s secure boot chain.

The USB-Based Exploit

The first vulnerability allows an attacker with physical access and a USB cable to bypass all security layers on a MediaTek-powered Android phone. The attack works without ever booting into the Android operating system:

The Electromagnetic Fault Injection (EMFI) Attack

The second, more severe vulnerability targets the Dimensity 7300 (MT6878) chip’s Boot ROM using precisely timed electromagnetic pulses during the boot sequence:

Attack VectorTime to CompromisePatchableEquipment Needed
USB exploit~45 secondsYes (patched Jan 2026)USB cable, software
EMFI attackMinutesNo (hardware flaw)EMFI equipment, physical access
MediaTek stated the Dimensity 7300 was designed for “mass-market consumer electronics” rather than high-security financial applications and is “not specifically hardened against EMFI hardware physical attacks.” Ledger emphasized that dedicated hardware wallets with secure elements remain the only safe option for private key storage.

Diagram showing MediaTek chip vulnerability attack vectors comparing USB exploit and EMFI attack on Android devices

Which Devices and Wallets Are at Risk?

The vulnerabilities affect a broad range of Android devices. Any phone using MediaTek processors paired with Trustonic TEE is potentially vulnerable to the USB-based exploit, while the EMFI attack specifically targets the Dimensity 7300 chipset.

Confirmed Affected Devices

Wallets Successfully Compromised in Testing

Ledger’s researchers extracted seed phrases from the following wallets during their demonstration:

The exploit targets the device’s secure storage layer rather than individual wallet apps, meaning any software wallet storing seed phrases on the device is potentially vulnerable.

The Solana Seeker Problem

The discovery carries particular significance for the Solana Seeker, a crypto-native smartphone that launched with the promise of bringing decentralized applications to mobile users. The phone uses the exact Dimensity 7300 chip identified as having the unfixable Boot ROM vulnerability.

Despite the security concerns raised by Ledger’s research, Solana Mobile moved forward with plans to launch its SKR governance token in January 2026, allocating 30% for airdrops to Seeker users and ecosystem participants. Think about that for a second: a phone marketed for crypto use runs on a chip that security researchers have proven cannot safely store private keys.

Ledger’s Donjon team concluded that smartphones, regardless of brand, are “not designed for the secure storage of private keys” and that the MediaTek findings reinforce the case for dedicated hardware wallets built with secure elements engineered to resist both software and physical attacks.

How to Protect Your Crypto

If you use an Android phone with a MediaTek processor, here are the steps you should take immediately:

  1. Install the latest security updates: MediaTek released patches on January 5, 2026. Check your phone’s settings for available updates.
  2. Check your chipset: Go to Settings > About Phone to identify your processor. MediaTek Dimensity and Helio chipsets from 2022-2025 models are the most at risk.
  3. Move significant holdings off mobile wallets: Transfer large balances to a dedicated hardware wallet or another secure storage solution.
  4. Use a hardware wallet for long-term storage: Devices with dedicated secure elements (such as Ledger or Trezor) are engineered to resist the types of physical attacks demonstrated in this research.
  5. Avoid leaving your phone unattended: Both exploits require physical access to the device, so physical security is your first line of defense.

The Bigger Picture: Mobile Wallets and Hardware Trust

The MediaTek vulnerability disclosure arrives at a pivotal moment for mobile crypto adoption. The number of people managing digital assets on smartphones has grown steadily, reaching approximately 36 million as of early 2025. Yet the security architecture of consumer smartphones was never designed with high-value cryptographic key storage in mind.

The Trustonic TEE, which is supposed to provide a secure enclave for sensitive operations, proved insufficient against both of Ledger’s demonstrated attacks. This casts doubt on the security of any mobile device storing private keys, not just those with MediaTek chips.

The vulnerability has existed for approximately a decade without public discovery, according to researchers. While MediaTek’s January 2026 software patch addresses the USB-based exploit, the EMFI vulnerability in the Boot ROM will persist in every affected chip already manufactured and deployed.

Bottom line
Ledger exposed two critical MediaTek chip flaws affecting ~25% of Android phones, including the Solana Seeker. The USB exploit steals seed phrases in 45 seconds (patched), but the EMFI attack on the Dimensity 7300’s Boot ROM is permanently unfixable. Move significant holdings off mobile wallets and use dedicated hardware wallets.

This is not financial advice. Cryptocurrency investments and security decisions carry significant risk. Always conduct your own research and consult qualified professionals before making investment or security decisions.

Sources

Frequently asked questions

Which Android phones are affected by the MediaTek crypto vulnerability?

Approximately 25% of Android phones using MediaTek processors paired with Trustonic TEE are potentially affected. This includes devices from Nothing, Samsung, Motorola, Xiaomi, POCO, Realme, Vivo, OPPO, Tecno, and iQOO. The Solana Seeker crypto phone, which uses the Dimensity 7300 chip, is also affected.

Can the MediaTek chip vulnerability be fixed with a software update?

The USB-based exploit received a software patch from MediaTek in January 2026. However, the deeper electromagnetic fault injection (EMFI) vulnerability exists in the chip’s immutable Boot ROM, meaning it is permanently unfixable through software updates since the flaw is baked into the silicon.

How can I protect my crypto wallet from the MediaTek exploit?

Install the latest Android security updates, avoid storing large crypto holdings on MediaTek devices, and use a dedicated hardware wallet for long-term storage.

Which crypto wallets were compromised in the MediaTek vulnerability demonstration?

Ledger’s researchers successfully extracted seed phrases from Trust Wallet, Kraken Wallet, Phantom, Rabby, Tangem Mobile Wallet, and Base wallet during their demonstration on a Nothing CMF Phone 1, all without booting into Android.

How long does the MediaTek crypto exploit take to execute?

The USB-based attack can compromise a device and extract crypto seed phrases in approximately 45 seconds. The electromagnetic fault injection attack has a 0.1-1% success rate per attempt but can be repeated every second, achieving full device compromise within minutes.
Share:
Twitter Facebook LinkedIn Reddit WhatsApp Telegram Email