Ledger Donjon Finds MediaTek Flaw Exposing Android Wallet Seeds

Ledger Donjon exposed a MediaTek vulnerability that extracts Android wallet seed phrases in under 45 seconds, affecting millions of devices. CVE-2025-20435.

Ledger Donjon has uncovered a serious MediaTek vulnerability. It lets attackers pull wallet seed phrases from Android phones in seconds. The phone does not even need to be on.

Charles Guillemet, posting as @P3b7_ on X, broke the findings publicly. He confirmed that @DonjonLedger had once again discovered a flaw with serious reach. According to Guillemet on X, user data, including PINs and seed phrases, can be extracted in under a minute, even from a powered-off device.

The scale here matters. Millions of Android phones run MediaTek processors. Trustonic’s Trusted Execution Environment is also caught in this.

Your Phone Off Means Nothing Now

As Guillemet tweeted on X, the Ledger Donjon team plugged a Nothing CMF Phone 1 into a laptop. Within 45 seconds, the phone’s foundational security was gone. No complicated setup. No special hardware. Just a laptop connection and a timer.

Worth a read: Crypto security threats are rapidly escalating heading into 2026

The exploit never even touched Android. As Guillemet posted on X, the attack automatically recovered the PIN, decrypted device storage, and pulled seed phrases from the most popular software wallets. All before the operating system loaded.

That is not a small gap. That is a structural failure.

The Chip Architecture Problem Nobody Wanted to Admit

General-purpose chips trade security for speed and ease. Guillemet made that point directly in his X thread. A dedicated Secure Element keeps secrets isolated from everything else on the device. MediaTek chips were not built that way. Trustonic’s TEE sits inside the same chip handling everyday tasks. Physical access collapses that boundary.

This is not the first time researchers have questioned smartphone security for crypto users. It keeps coming back to the same architecture gap. Convenience chip versus security chip. They are not the same thing.

Responsible Disclosure, Then the Fix

Ledger Donjon did not release this publicly without warning. As Guillemet confirmed on X, the team followed a strict responsible disclosure process with all relevant vendors. MediaTek confirmed it provided a fix to OEMs on January 5, 2026. The vulnerability is now publicly listed as CVE-2025-20435.

Must read: Ledger eyes New York listing as crypto wallet hacks surge

OEMs received the fix. Whether those patches reached end users is another question entirely. Android fragmentation is a real problem. Older devices from smaller manufacturers often sit unpatched for months.

Why Software Wallets Took the Hit

Seed phrases stored on a software wallet live inside the device. They depend entirely on the security of the chip underneath. When that chip fails, everything above it fails too.

Guillemet’s thread on X closed with clarity on motive. The research was not done to create fear. It was done so the industry could fix the vulnerability before attackers got there first. That window is now closed, at least for this specific flaw.

Related: Cross-platform wallet drainers are getting harder to detect

Software wallets on Android have always carried this risk. The MediaTek vulnerability just put a number on it. Forty-five seconds. That is all it took.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Litecoin Reorg Undoes MWEB Privacy Layer Exploit

Litecoin underwent a deep chain reorganization on Saturday after attackers exploited a zero-day vulnerability in its MimbleWimble Extension Block (MWEB) privacy layer, according to the Litecoin Foundation. The incident resulted in a three-hour reorg that erased invalid transactions from the

CryptoFrontier4h ago

North Korean IT Workers Laptop Farm Scam: US Co-Conspirator Sentenced to 7–9 Years, Netting $2.8 Billion Over Two Years

Fortune reported that North Korea used laptop farms inside the United States, generating about $2.8 billion in revenue over two years to support nuclear weapons; annual tribute is $250–600 million. The U.S. citizen suspects Kejia Wang and Zhenxing Wang were each sentenced to 7.5 years and 9 years, respectively, for involvement exceeding 100 companies and 80 cases of identity theft. North Korea operated in the U.S. using U.S. identities and fixed devices, with funds mostly being converted via cryptocurrencies. Experts warn that an accomplice network still exists inside the country, and companies must strengthen identity verification, address tracking, and time zone/IP analysis.

ChainNewsAbmedia7h ago

Hong Kong Police Warn of Surge in Crypto Scams; Two Women Lose $1.24M in Recent Weeks

Gate News message, April 25 — Two Hong Kong women lost a combined HK$9.7 million (US$1.24 million) to crypto scammers over recent weeks, prompting local police to issue a public warning. Hong Kong police reported more than 80 fraud cases in a single week, with total losses exceeding HK$80 million (U

GateNews8h ago

Aave Proposes 25,000 ETH for Kelp DAO Exploit Relief Fund

Aave service providers put forth a governance proposal on Friday that would contribute 25,000 ETH worth nearly $58 million from the protocol's DAO to DeFi United, a coordinated relief effort to restore backing for rsETH following the Kelp DAO exploit. The proposed contribution aims to close the rema

CryptoFrontier8h ago

Android Malware Families Target 800+ Banking, Crypto Apps With Near-Zero Detection Rates: Zimperium

Gate News message, April 25 — Cybersecurity firm Zimperium has identified four active malware families—RecruitRat, SaferRat, Astrinox and Massiv—targeting over 800 applications across banking, cryptocurrency and social media sectors. The campaigns employ advanced anti-analysis techniques and

GateNews10h ago

TRADOOR Token Crashes 90% in 30 Minutes Amid Suspected Price Manipulation and Wash Trading

Gate News message, April 25 — TRADOOR token experienced a sharp 90% price crash over 30 minutes at 2:00 AM today, according to on-chain analyst Specter. The token had surged as much as 900% since March 2026 before the sudden collapse, raising suspicions of price manipulation and coordinated

GateNews12h ago
Comment
0/400
No comments