Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Critical MediaTek Vulnerability Lets Attackers Steal Android Phone PINs in 45 Seconds

A vulnerability has been identified in the MediaTek Dimensity 7300 chipset, allowing attackers to extract device PINs, decrypt on-device storage, and access cryptocurrency wallet seed phrases in approximately 45 seconds. This issue affects around 25% of…

A vulnerability has been identified in the MediaTek Dimensity 7300 chipset, allowing attackers to extract device PINs, decrypt on-device storage, and access cryptocurrency wallet seed phrases in approximately 45 seconds. This issue affects around 25% of Android users with devices utilizing this chip.

The vulnerability, discovered by Ledger's Donjon security research team, is located in the Boot ROM of the MediaTek Dimensity 7300 (MT6878) chip. This flaw exists in the processor's silicon and cannot be resolved through software updates.

Researchers exploited this vulnerability using Electromagnetic Fault Injection (EMFI), a technique involving electromagnetic pulses to corrupt the chip's execution flow during boot-up. By connecting to the device via USB and triggering repeated boot cycles while injecting faults, attackers can bypass security layers and execute arbitrary code without launching the Android operating system.

Ledger demonstrated the attack on a Nothing CMF Phone 1 connected to a laptop. The team breached the phone's security within 45 seconds, recovering the device PIN, decrypting storage, and extracting seed phrases from software crypto wallets. Affected applications include Trust Wallet, Kraken Wallet, Phantom, Base, Rabby, and Tangem's Mobile Wallet.

This issue affects around 25% of Android users with devices utilizing this chip.
Hazel Caldwell · Thehackingpost

The attack can be automated and repeated until successful, though the per-attempt success rate is low. Ledger's research, initiated in February 2025, achieved arbitrary code execution by early May 2025, followed by responsible disclosure to MediaTek.

The vulnerability affects Android devices using the MediaTek Dimensity 7300 chip and Trustonic Trusted Execution Environment (TEE), impacting approximately 25% of global Android devices. Affected brands include Realme, Motorola, Oppo, Vivo, Nothing, and Tecno, as well as the Solana Seeker smartphone.

Following disclosure, MediaTek released a security patch in January 2026, notifying all affected OEM vendors. However, as the flaw is hardware-based, the patch mitigates exploitation pathways but does not eliminate the underlying vulnerability. MediaTek has noted that EMFI attacks are out of scope for the MT6878 chipset's intended use.

Advertisement

Ledger's CTO, Charles Guillemet, advises users to apply security patches and transfer sensitive cryptocurrency assets to dedicated hardware wallets with certified security features, emphasizing that smartphones are not designed to function as secure vaults for sensitive information.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories