MediaTek fixes chipset flaw that let attackers steal crypto wallet seeds in 45 seconds

Mobile chipmaker MediaTek patched a vulnerability in its chipsets on Jan. 5 that, according to Ledger's Donjon security team, allowed attackers with physical access and a USB connection to extract sensitive data from some Android phones. The flaw in the secure boot chain could be used to recover PINs, decrypt storage and steal seed phrases from major software wallets on devices using MediaTek processors and the Trustonic TEE. Ledger has urged users of affected Android phones to install the latest security updates, even as it does not expect the issue to persist.