Hackers can steal Android PINs and crypto wallet data even when phones are turned off, exposing millions of people around the world.


  • Ledger’s Dungeon team exploited MediaTek phones, recovering crypto wallet PINs and seed phrases
  • Attackers can extract root cryptographic keys from powered off Android devices via USB
  • Trustonic Secure Execution Environment Fails to Prevent Attacks on a Quarter of Android Devices

Ledger’s hacking team, Donjon, has discovered a vulnerability in MediaTek-powered Android smartphones that allows attackers to access sensitive data in less than a minute.

Using a Nothing CMF Phone 1, the Dungeon completely bypassed the Android operating system, retrieved the PIN, decrypted the storage, and extracted seed phrases from multiple crypto wallets.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top