Critical MediaTek Vulnerability Lets Attackers Steal Android Phone PINs in 45 Seconds
A vulnerability has been identified in the MediaTek Dimensity 7300 chipset, allowing attackers to extract device PINs, decrypt on-device storage, and access cryptocurrency wallet seed phrases in approximately 45 seconds. This issue affects around 25% of…
A vulnerability has been identified in the MediaTek Dimensity 7300 chipset, allowing attackers to extract device PINs, decrypt on-device storage, and access cryptocurrency wallet seed phrases in approximately 45 seconds. This issue affects around 25% of Android users with devices utilizing this chip.
The vulnerability, discovered by Ledger's Donjon security research team, is located in the Boot ROM of the MediaTek Dimensity 7300 (MT6878) chip. This flaw exists in the processor's silicon and cannot be resolved through software updates.
Researchers exploited this vulnerability using Electromagnetic Fault Injection (EMFI), a technique involving electromagnetic pulses to corrupt the chip's execution flow during boot-up. By connecting to the device via USB and triggering repeated boot cycles while injecting faults, attackers can bypass security layers and execute arbitrary code without launching the Android operating system.
Ledger demonstrated the attack on a Nothing CMF Phone 1 connected to a laptop. The team breached the phone's security within 45 seconds, recovering the device PIN, decrypting storage, and extracting seed phrases from software crypto wallets. Affected applications include Trust Wallet, Kraken Wallet, Phantom, Base, Rabby, and Tangem's Mobile Wallet.
This issue affects around 25% of Android users with devices utilizing this chip.
The attack can be automated and repeated until successful, though the per-attempt success rate is low. Ledger's research, initiated in February 2025, achieved arbitrary code execution by early May 2025, followed by responsible disclosure to MediaTek.
The vulnerability affects Android devices using the MediaTek Dimensity 7300 chip and Trustonic Trusted Execution Environment (TEE), impacting approximately 25% of global Android devices. Affected brands include Realme, Motorola, Oppo, Vivo, Nothing, and Tecno, as well as the Solana Seeker smartphone.
Following disclosure, MediaTek released a security patch in January 2026, notifying all affected OEM vendors. However, as the flaw is hardware-based, the patch mitigates exploitation pathways but does not eliminate the underlying vulnerability. MediaTek has noted that EMFI attacks are out of scope for the MT6878 chipset's intended use.
Ledger's CTO, Charles Guillemet, advises users to apply security patches and transfer sensitive cryptocurrency assets to dedicated hardware wallets with certified security features, emphasizing that smartphones are not designed to function as secure vaults for sensitive information.
Based on reporting by Cyber Security News.
