Security researchers have identified a serious vulnerability in Android phones that could impact the global smartphone ecosystem. The flaw, discovered by Ledger, could expose sensitive information from millions of Android smartphones running on certain chipsets . According to the researchers, the issue could potentially affect devices representing about 25% of Android phones worldwide. The vulnerability affects certain Android chipsets manufactured by MediaTek and affects devices using ’s Trusted Execution Environment (TEE) Trustonic.

Researchers warned that attackers with brief physical access to a vulnerable device could extract sensitive data, including encryption keys and cryptocurrency wallet seed phrases, in less than a minute.
Vulnerability in MediaTek chips affects millions of Android phones
The security issue was discovered by Ledger’s internal security team, known as the Donjon. Their research revealed that the vulnerability in Android phones originates in the device’s boot chain, a critical security process that verifies system components when the phone is turned on.
See also: Critical vulnerabilities in n8n allow remote code execution
Normally, the boot chain ensures that each stage of the boot process is cryptographically verified before loading the next stage. This mechanism is designed to protect encryption keys and keep sensitive information secure until the operating system is fully loaded.
However, on some Android smartphones, researchers found that attackers could exploit a vulnerability before the Android operating system had finished loading. By connecting the phone to a computer via USB, an attacker could bypass several security protections.
The researchers showed that this process allowed for automated attempts in which attackers could guess the user's PIN, decrypt the storage phone's , and retrieve sensitive information such as messages and cryptocurrency wallet seed phrases.
Proof-of-Concept Attack Completed in 45 Seconds
During a proof-of-concept demonstration, Ledger's Donjon team showed how the vulnerability in Android phones could be exploited in an attack in less than a minute. In their test, a Nothing CMF Phone 1 was connected to a laptop using a USB cable.
See also: CISA: Ivanti EPM and Cisco SD-WAN vulnerabilities in the KEV List

Within 45 seconds, the researchers were able to recover the device's PIN, decrypt its encrypted storage , and extract seed phrases from six cryptocurrency wallet apps: Trust Wallet, Base, Kraken Wallet, Rabby, Tangem, and Phantom.
The attack only required a brief physical connection to a computer and did not involve installing malware or interacting with the phone's screen. The researchers noted that the vulnerability could allow attackers to obtain root cryptographic keys, which are responsible for securing full disk encryption on affected Android smartphones.
Once these keys are exported, the phone's data can be decrypted offline.
Affected Chipsets and Android Devices
The vulnerability affects devices running certain MediaTek Android chipsets that rely on Trustonic's Trusted Execution Environment. MediaTek processors are widely used in Android smartphones, particularly in the low- and mid-range segments.
Industry estimates suggest that MediaTek chips power about a quarter of Android devices worldwide, meaning the issue could potentially affect about 25% of Android phones, although not all devices using MediaTek hardware are vulnerable.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
MediaTek has already distributed a firmware fix to smartphone manufacturers, but the fix needs to be implemented and delivered to users via device updates. Until those updates are installed, affected Android smartphones could remain vulnerable.
See also: Warning! Serious vulnerabilities in HPE Aruba CX switches
MediaTek said it provided a fix to equipment manufacturers (OEMs) in January.

Charles Guillemet, Chief Technology Officer at Ledger, emphasized that smartphones were never designed to function as highly secure storage systems for sensitive digital assets: “Smartphones were never designed to be vaults… If your cryptocurrencies are on a phone, they are only as secure as the weakest link in the phone’s hardware, firmware, or software.”
Ledger advised users of potentially affected Android smartphones to install the latest available security updates as soon as they become available.
