A critical pair of vulnerabilities in MediaTek processors could allow attackers to steal cryptocurrency seed phrases from roughly one in four Android phones, according to research published by Ledger’s white-hat security team, Donjon, in March 2026. The more alarming of the two flaws is permanently unfixable because it resides in the chip’s immutable Boot ROM, a component baked into the silicon during manufacturing. With an estimated 36 million people managing digital assets on mobile devices, the discovery puts the security of software-based crypto wallets on smartphones into serious doubt.
The research demonstrated full device compromise on a Nothing CMF Phone 1 in under 45 seconds, successfully extracting seed phrases from popular wallets including Trust Wallet, Kraken Wallet, and Phantom. Devices from major manufacturers such as Samsung, Motorola, Xiaomi, and OPPO could also be affected if they use MediaTek processors paired with Trustonic’s Trusted Execution Environment (TEE).
Perhaps most notably, the Solana Seeker, a crypto-focused smartphone built on the MediaTek Dimensity 7300 chip, sits squarely in the crosshairs. Solana Mobile has continued its token launch plans despite the security concerns, highlighting the tension between crypto adoption on mobile devices and the fundamental hardware limitations of consumer-grade chips.
Two Exploits, One Chip: What Ledger’s Donjon Found
Ledger’s security researchers, Charles Christen and Leo Benito, uncovered two distinct attack vectors targeting MediaTek’s secure boot chain.
The USB-Based Exploit
The first vulnerability allows an attacker with physical access and a USB cable to bypass all security layers on a MediaTek-powered Android phone. The attack works without ever booting into the Android operating system:
- Attack time: Approximately 45 seconds for full compromise
- Method: Exploits the secure boot chain managed by Trustonic TEE
- Result: Automatically recovers the device PIN, decrypts storage, and extracts wallet seed phrases
- Demonstrated on: Nothing CMF Phone 1
- Patch status: MediaTek released a software fix on January 5, 2026
The Electromagnetic Fault Injection (EMFI) Attack
The second, more severe vulnerability targets the Dimensity 7300 (MT6878) chip’s Boot ROM using precisely timed electromagnetic pulses during the boot sequence:
- Attack time: Minutes (repeated attempts at one per second)
- Success rate: 0.1-1% per individual attempt
- Method: Electromagnetic pulses destabilize the boot process, granting EL3 (ARM’s highest privilege level) access
- Result: Complete device takeover, including rewriting memory and reading the Boot ROM
- Patch status: Permanently unfixable (silicon-level flaw)
| Attack Vector | Time to Compromise | Patchable | Equipment Needed |
|---|---|---|---|
| USB exploit | ~45 seconds | Yes (patched Jan 2026) | USB cable, software |
| EMFI attack | Minutes | No (hardware flaw) | EMFI equipment, physical access |

Which Devices and Wallets Are at Risk?
The vulnerabilities affect a broad range of Android devices. Any phone using MediaTek processors paired with Trustonic TEE is potentially vulnerable to the USB-based exploit, while the EMFI attack specifically targets the Dimensity 7300 chipset.
Confirmed Affected Devices
- Nothing CMF Phone 1: Used in the live demonstration
- Solana Seeker: Crypto-focused phone using the Dimensity 7300
- Budget Android phones: Devices from Samsung, Motorola, Xiaomi, POCO, Realme, Vivo, OPPO, Tecno, and iQOO using MediaTek chips
Wallets Successfully Compromised in Testing
Ledger’s researchers extracted seed phrases from the following wallets during their demonstration:
- Trust Wallet
- Kraken Wallet
- Phantom
- Rabby
- Tangem Mobile Wallet
- Base
The exploit targets the device’s secure storage layer rather than individual wallet apps, meaning any software wallet storing seed phrases on the device is potentially vulnerable.
The Solana Seeker Problem
The discovery carries particular significance for the Solana Seeker, a crypto-native smartphone that launched with the promise of bringing decentralized applications to mobile users. The phone uses the exact Dimensity 7300 chip identified as having the unfixable Boot ROM vulnerability.
Despite the security concerns raised by Ledger’s research, Solana Mobile moved forward with plans to launch its SKR governance token in January 2026, allocating 30% for airdrops to Seeker users and ecosystem participants. Think about that for a second: a phone marketed for crypto use runs on a chip that security researchers have proven cannot safely store private keys.
How to Protect Your Crypto
If you use an Android phone with a MediaTek processor, here are the steps you should take immediately:
- Install the latest security updates: MediaTek released patches on January 5, 2026. Check your phone’s settings for available updates.
- Check your chipset: Go to Settings > About Phone to identify your processor. MediaTek Dimensity and Helio chipsets from 2022-2025 models are the most at risk.
- Move significant holdings off mobile wallets: Transfer large balances to a dedicated hardware wallet or another secure storage solution.
- Use a hardware wallet for long-term storage: Devices with dedicated secure elements (such as Ledger or Trezor) are engineered to resist the types of physical attacks demonstrated in this research.
- Avoid leaving your phone unattended: Both exploits require physical access to the device, so physical security is your first line of defense.
The Bigger Picture: Mobile Wallets and Hardware Trust
The MediaTek vulnerability disclosure arrives at a pivotal moment for mobile crypto adoption. The number of people managing digital assets on smartphones has grown steadily, reaching approximately 36 million as of early 2025. Yet the security architecture of consumer smartphones was never designed with high-value cryptographic key storage in mind.
The Trustonic TEE, which is supposed to provide a secure enclave for sensitive operations, proved insufficient against both of Ledger’s demonstrated attacks. This casts doubt on the security of any mobile device storing private keys, not just those with MediaTek chips.
The vulnerability has existed for approximately a decade without public discovery, according to researchers. While MediaTek’s January 2026 software patch addresses the USB-based exploit, the EMFI vulnerability in the Boot ROM will persist in every affected chip already manufactured and deployed.
This is not financial advice. Cryptocurrency investments and security decisions carry significant risk. Always conduct your own research and consult qualified professionals before making investment or security decisions.
Related Reading
- SEC and CFTC Sign Historic MOU to End Regulatory Turf War and Unify Crypto Oversight
- Bitcoin Holds Above $70,000 as CPI Matches Forecasts and IEA Announces Record 400 Million Barrel Oil Release
- Ethereum Network Activity Hits All-Time Highs, But ETH Price and Fee Revenue Keep Falling
Sources
- Cointelegraph: MediaTek Patches Bug Allowing Attackers To Steal Crypto Seeds
- Decrypt: Android Phone Crypto Wallets Could Be at Risk Due to MediaTek Exploit: Ledger
- ZDNET: A Major Security Flaw Could Affect 1 in 4 Android Phones
- Android Authority: Major MediaTek Security Flaw Could Expose Data on Millions of Android Phones
- Coin Edition: Ledger Flags Unpatchable MediaTek Chip Flaw Risking Crypto
- Decrypt: Ledger Finds Popular Smartphone Chip Vulnerable to Unpatchable Attacks




