The post Ledger found a security flaw in common Android chip appeared on BitcoinEthereumNews.com. A team of security researchers discovered an unpatchable security flaw in a common Android chip that could allow attackers to gain complete access to devices, putting crypto users at risk, according to a recent report by Ledger. The problem exists in a particular chip made by MediaTek, a company based in Taiwan. The chip in question is the Dimensity 7300, also called MT6878, which can be found in numerous Android smartphones currently on the market, including the Solana Seeker. What makes this security issue particularly serious is where it sits. The weakness is located in the chip’s boot ROM, which is the very first part of the phone that starts up when you turn it on. Because this code is permanently built into the physical chip itself, there is no way to fix it through regular software updates or security patches. Ledger’s research division, known as the Donjon team, studied how the chip operates. They discovered that by sending carefully timed electromagnetic pulses to the chip right as it boots up, they could trick it into giving them the highest level of access possible. In technical terms, they reached what’s called EL3, which is the most powerful privilege level in ARM chip design. Ledger warned about the serious implications of this discovery “From malware that users could be tricked into installing on their machines, to fully remote, zero-click exploits commonly used by government-backed entities, there is simply no way to safely store and use one’s private keys on those devices,” they wrote. Ledger’s fault injection setup. Source: Ledger This news arrives during a period when attacks targeting people who own cryptocurrency are becoming more frequent. A study released in July by Chainalysis showed that more than $2.17 billion has already been stolen from crypto services in 2025. That amount exceeds… The post Ledger found a security flaw in common Android chip appeared on BitcoinEthereumNews.com. A team of security researchers discovered an unpatchable security flaw in a common Android chip that could allow attackers to gain complete access to devices, putting crypto users at risk, according to a recent report by Ledger. The problem exists in a particular chip made by MediaTek, a company based in Taiwan. The chip in question is the Dimensity 7300, also called MT6878, which can be found in numerous Android smartphones currently on the market, including the Solana Seeker. What makes this security issue particularly serious is where it sits. The weakness is located in the chip’s boot ROM, which is the very first part of the phone that starts up when you turn it on. Because this code is permanently built into the physical chip itself, there is no way to fix it through regular software updates or security patches. Ledger’s research division, known as the Donjon team, studied how the chip operates. They discovered that by sending carefully timed electromagnetic pulses to the chip right as it boots up, they could trick it into giving them the highest level of access possible. In technical terms, they reached what’s called EL3, which is the most powerful privilege level in ARM chip design. Ledger warned about the serious implications of this discovery “From malware that users could be tricked into installing on their machines, to fully remote, zero-click exploits commonly used by government-backed entities, there is simply no way to safely store and use one’s private keys on those devices,” they wrote. Ledger’s fault injection setup. Source: Ledger This news arrives during a period when attacks targeting people who own cryptocurrency are becoming more frequent. A study released in July by Chainalysis showed that more than $2.17 billion has already been stolen from crypto services in 2025. That amount exceeds…

Ledger found a security flaw in common Android chip

For feedback or concerns regarding this content, please contact us at [email protected]

A team of security researchers discovered an unpatchable security flaw in a common Android chip that could allow attackers to gain complete access to devices, putting crypto users at risk, according to a recent report by Ledger.

The problem exists in a particular chip made by MediaTek, a company based in Taiwan. The chip in question is the Dimensity 7300, also called MT6878, which can be found in numerous Android smartphones currently on the market, including the Solana Seeker.

What makes this security issue particularly serious is where it sits. The weakness is located in the chip’s boot ROM, which is the very first part of the phone that starts up when you turn it on. Because this code is permanently built into the physical chip itself, there is no way to fix it through regular software updates or security patches.

Ledger’s research division, known as the Donjon team, studied how the chip operates. They discovered that by sending carefully timed electromagnetic pulses to the chip right as it boots up, they could trick it into giving them the highest level of access possible. In technical terms, they reached what’s called EL3, which is the most powerful privilege level in ARM chip design.

Ledger warned about the serious implications of this discovery

“From malware that users could be tricked into installing on their machines, to fully remote, zero-click exploits commonly used by government-backed entities, there is simply no way to safely store and use one’s private keys on those devices,” they wrote.

Ledger’s fault injection setup. Source: Ledger

This news arrives during a period when attacks targeting people who own cryptocurrency are becoming more frequent. A study released in July by Chainalysis showed that more than $2.17 billion has already been stolen from crypto services in 2025. That amount exceeds everything that was stolen throughout all of 2024.

Most cryptocurrency thefts happen through online methods like phishing schemes and fraudulent operations, rather than physical attacks. However, the research shows that physical vulnerabilities do exist.

The Donjon researchers found that once they figured out the exact moment to send the electromagnetic pulse, each try took roughly one second. Their success rate ranged from 0.1% to 1% per attempt, which meant they could completely take over a device within just a few minutes when working in laboratory settings.

Ledger, which makes the well-known Nano hardware wallets, stopped short of telling people to completely avoid using wallets on smartphones. However, the findings do point to a new way that both software creators and regular users could be targeted.

A cryptocurrency wallet is a program that holds a person’s public and private keys, allowing them to send, receive, and keep track of their digital money. Hardware wallets, sometimes called “cold wallets,” keep these private keys completely offline on a separate physical device that’s disconnected from the internet, protecting them from attacks that can reach phones or computers.

Software wallets, also known as “hot wallets,” are applications that let people store their digital money on different devices, but this leaves users vulnerable to hacking attempts and phishing operations.

MediaTek says Ledger’s fault-injection test is out of scope

MediaTek had responded to the discovery in a statement that Ledger included in their report. The company said that electromagnetic fault-injection attacks were considered “out of scope” for the MT6878 chip because it was built as a regular consumer product, not as a high-security component meant for financial systems or sensitive information.

“For products with higher hardware security requirements, such as hardware crypto wallets, we believe that they should be designed with appropriate countermeasures against EMFI attacks,” MediaTek stated.

Ledger emphasized that devices using the MT6878 chip will continue to have this vulnerability because the flaw exists in the unchangeable silicon material itself. The company stressed that secure-element chips remain essential for anyone who manages their own cryptocurrency or handles other sensitive security operations, as these specialized components are specifically built to resist both hardware and software attacks.

“Smartphones’ threat model, just like any piece of technology that can be lost or stolen, cannot reasonably exclude hardware attacks,” Ledger wrote. “But the SoCs they use are no more exempt from the effects of fault injection than microcontrollers are, and security should really ultimately rely on Secure Elements, especially for self-custody.”

Want your project in front of crypto’s top minds? Feature it in our next industry report, where data meets impact.

Source: https://www.cryptopolitan.com/crypto-users-risk-android-security-flaw/

Market Opportunity
Common Protocol Logo
Common Protocol Price(COMMON)
$0.0003028
$0.0003028$0.0003028
+0.23%
USD
Common Protocol (COMMON) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

China Launches Cross-Border QR Code Payment Trial

China Launches Cross-Border QR Code Payment Trial

The post China Launches Cross-Border QR Code Payment Trial appeared on BitcoinEthereumNews.com. Key Points: Main event involves China initiating a cross-border QR code payment trial. Alipay and Ant International are key participants. Impact on financial security and regulatory focus on illicit finance. China’s central bank, led by Deputy Governor Lu Lei, initiated a trial of a unified cross-border QR code payment gateway with Alipay and Ant International as participants. This pilot addresses cross-border fund risks, aiming to enhance financial security amid rising money laundering through digital channels, despite muted crypto market reactions. China’s Cross-Border Payment Gateway Trial with Alipay The trial operation of a unified cross-border QR code payment gateway marks a milestone in China’s financial landscape. Prominent entities such as Alipay and Ant International are at the forefront, participating as the initial institutions in this venture. Lu Lei, Deputy Governor of the People’s Bank of China, highlighted the systemic risks posed by increased cross-border fund flows. Changes are expected in the dynamics of digital transactions, potentially enhancing transaction efficiency while tightening regulations around illicit finance. The initiative underscores China’s commitment to bolstering financial security amidst growing global fund movements. “The scale of cross-border fund flows is expanding, and the frequency is accelerating, providing opportunities for risks such as cross-border money laundering and terrorist financing. Some overseas illegal platforms transfer funds through channels such as virtual currencies and underground banks, creating a ‘resonance’ of risks at home and abroad, posing a challenge to China’s foreign exchange management and financial security.” — Lu Lei, Deputy Governor, People’s Bank of China Bitcoin and Impact of China’s Financial Initiatives Did you know? China’s latest initiative echoes the Payment Connect project of June 2025, furthering real-time cross-boundary remittances and expanding its influence on global financial systems. As of September 17, 2025, Bitcoin (BTC) stands at $115,748.72 with a market cap of $2.31 trillion, showing a 0.97%…
Share
BitcoinEthereumNews2025/09/18 05:28
Bank of England keeps interest rate steady at 4% as expected

Bank of England keeps interest rate steady at 4% as expected

The post Bank of England keeps interest rate steady at 4% as expected appeared on BitcoinEthereumNews.com. The Bank of England (BoE) left its benchmark interest rate unchanged at 4%, following the conclusion of the September monetary policy meeting on Thursday. The rate decision aligned with the market expectations. The voting composition showed the expected 7-2 split on the Monetary Policy Committee (MPC), with two members, Dhingra and Taylor, voting in favor of a 25 basis points (bps) cut. Follow our live coverage of the BoE policy announcements and the market reaction. Key takeaways from BoE Monetary Policy Statement BoE policymaker Pill voted to maintain QT pace at 100 bln Pound Sterling (stg). BoE policymakers vote 7-2 to slow quantitative tightening pace to 70 bln stg a year from 100 bln stg. BoE policymaker Mann voted to slow QT pace to 62 bln stg. To hold two 775 mln stg short-dated gilt auctions, two 750 mln stg medium-dated gilt auctions and one 550 mln stg long-dated gilts auction in Q4 2025. 2025/26 gilt sales will be split 40:40:20 between short-, medium- and long-maturity buckets in initial proceed terms (2024/25 had equal split) “We’re not out of the woods yet so any future rate cuts will need to be made gradually and carefully” New AT target means MPC can continue to reduce size of balance sheet while continuing to minimise impact on gilt market “A gradual and careful approach to the further withdrawal of monetary policy restraint remains appropriate”. Keeps phrase: monetary policy not on pre-set path. UK CPI forecast to peak at 4% in September 2025 (August forecast to peak at 4% in Sept). Staff forecast Q3 GDP to increase by around 0.4% QoQ (August forecast: Q3 +0.3%). Rise in firms’ social security contributions appears to be delaying the reduction in total labour costs growth until 2026. Impact of US tariff rates on the world economy could…
Share
BitcoinEthereumNews2025/09/18 23:20
XAU/USD declines sharply to near $4,400 as Middle East fears revive

XAU/USD declines sharply to near $4,400 as Middle East fears revive

The post XAU/USD declines sharply to near $4,400 as Middle East fears revive appeared on BitcoinEthereumNews.com. Gold price (XAU/USD) is down 2% to near $4,410
Share
BitcoinEthereumNews2026/03/26 19:16