TLDR Pixnapping steals on-screen data by reading pixel colors on Android devices. Attack recovered 2FA codes on Pixel 6 to 9 in up to 73% of tests. Google rated the issue high severity and is working on a full patch. Hardware wallets remain the safest way to store crypto recovery phrases. A new Android security [...] The post Pixnapping Android flaw lets hackers steal crypto wallet seed phrases appeared first on CoinCentral.TLDR Pixnapping steals on-screen data by reading pixel colors on Android devices. Attack recovered 2FA codes on Pixel 6 to 9 in up to 73% of tests. Google rated the issue high severity and is working on a full patch. Hardware wallets remain the safest way to store crypto recovery phrases. A new Android security [...] The post Pixnapping Android flaw lets hackers steal crypto wallet seed phrases appeared first on CoinCentral.

Pixnapping Android flaw lets hackers steal crypto wallet seed phrases

TLDR

  • Pixnapping steals on-screen data by reading pixel colors on Android devices.
  • Attack recovered 2FA codes on Pixel 6 to 9 in up to 73% of tests.
  • Google rated the issue high severity and is working on a full patch.
  • Hardware wallets remain the safest way to store crypto recovery phrases.

A new Android security flaw has raised concerns among users of crypto wallets and authentication apps. Researchers have identified an attack method called “Pixnapping,” which allows malicious applications to reconstruct sensitive on-screen data such as recovery phrases and two-factor authentication (2FA) codes. The discovery indicates that even trusted devices could be at risk of revealing private information through manipulated screen pixels.

How the Pixnapping Attack Works

The Pixnapping method uses Android’s application programming interfaces (APIs) to calculate the color of individual pixels displayed by other applications. Unlike conventional screen capture attacks, the malicious app does not directly access another app’s display. 

Instead, it layers semi-transparent activities over the target app, masking all but a chosen pixel. By manipulating that pixel repeatedly, attackers can infer its color and reconstruct visual content from the screen.

Researchers explained that this process involves timing frame renders and scanning one pixel at a time, which enables the malware to rebuild what was shown on screen. Although the attack is slow, it is still capable of capturing information that remains visible for more than a few seconds, such as recovery phrases or long authentication codes.

Risk to Crypto Wallet Recovery Phrases

The research team warned that Pixnapping poses a particular danger to crypto wallet users. Recovery phrases, which provide full access to digital wallets, often stay visible while users write them down. According to the study, the attack successfully retrieved full 6-digit 2FA codes in several tests on Google Pixel devices.

The success rate reached 73% on the Pixel 6, 53% on the Pixel 7, 29% on the Pixel 8, and 53% on the Pixel 9. The average time to recover each 2FA code ranged from 14 to 26 seconds, depending on the device model. While recovering a full 12-word seed phrase would take much longer, the researchers confirmed that it remains possible if the phrase stays displayed.

Google’s Response and Ongoing Coordination

The vulnerability was tested on several devices running Android 13 to 16, including the Google Pixel 6 through Pixel 9 and the Samsung Galaxy S25. Since the attack relies on widely available APIs, the team warned that other Android devices could also be affected.

Google responded by limiting how many activities an app can blur at once. However, the researchers found a workaround that allowed Pixnapping to continue functioning. As of October 13, the researchers said they were still coordinating with Google and Samsung regarding disclosure timelines and security patches.

Google classified the issue as high severity and awarded a bug bounty to the research team. The team also informed Samsung that Google’s initial fix did not fully protect Samsung devices.

Hardware Wallets as a Safer Option

Experts advise users to avoid displaying recovery phrases or sensitive data on Android devices until a complete fix is available. Keeping recovery information offline or using a hardware wallet offers stronger protection.

A hardware wallet is a dedicated device that stores private keys securely and signs transactions without exposing them to connected smartphones or computers. Security researcher Vladimir S emphasized this in a post on X, stating, “Simply don’t use your phone to secure your crypto. Use a hardware wallet!”

Until Android patches the vulnerability, users are urged to exercise caution and avoid keeping recovery or authentication data visible on their screens for extended periods.

The post Pixnapping Android flaw lets hackers steal crypto wallet seed phrases appeared first on CoinCentral.

Market Opportunity
Ambire Wallet Logo
Ambire Wallet Price(WALLET)
$0.0187
$0.0187$0.0187
+2.57%
USD
Ambire Wallet (WALLET) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Bitcoin Has Taken Gold’s Role In Today’s World, Eric Trump Says

Bitcoin Has Taken Gold’s Role In Today’s World, Eric Trump Says

Eric Trump on Tuesday described Bitcoin as a “modern-day gold,” calling it a liquid store of value that can act as a hedge to real estate and other assets. Related Reading: XRP’s Biggest Rally Yet? Analyst Projects $20+ In October 2025 According to reports, the remark came during a TV appearance on CNBC’s Squawk Box, tied to the launch of American Bitcoin, the mining and treasury firm he helped start. Company Holdings And Strategy Based on public filings and company summaries, American Bitcoin has accumulated 2,443 BTC on its balance sheet. That stash has been valued in the low hundreds of millions of dollars at recent spot prices. The firm mixes large-scale mining with the goal of holding Bitcoin as a strategic reserve, which it says will help it grow both production and asset holdings over time. Eric Trump’s comments were direct. He told viewers that institutions are treating Bitcoin more like a store of value than a fringe idea, and he warned firms that resist blockchain adoption. The tone was strong at times, and the line about Bitcoin being a modern equivalent of gold was used to frame American Bitcoin’s role as both miner and holder.   Eric Trump has said: bitcoin is modern-day gold — unusual_whales (@unusual_whales) September 16, 2025 How The Company Went Public American Bitcoin moved toward a public listing via an all-stock merger with Gryphon Digital Mining earlier this year, a deal that kept most of the original shareholders in control and positioned the new entity for a Nasdaq debut. Reports show that mining partner Hut 8 holds a large ownership stake, leaving the Trump family and other backers with a minority share. The listing brought fresh attention and capital to the firm as it began trading under the ticker ABTC. Market watchers say the firm’s public debut highlights two trends: mining companies are trying to grow by both producing and holding Bitcoin, and political ties are bringing more headlines to crypto firms. Some analysts point out that holding large amounts of Bitcoin on the balance sheet exposes a company to price swings, while supporters argue it aligns incentives between miners and investors. Related Reading: Ethereum Bulls Target $8,500 With Big Money Backing The Move – Details Reaction And Possible Risks Based on coverage of the launch, investors have reacted with both enthusiasm and caution. Supporters praise the prospect of a US-based miner that aims to be transparent and aggressive about building a reserve. Critics point to governance questions, possible conflicts tied to high-profile backers, and the usual risks of a volatile asset being held on corporate balance sheets. Eric Trump’s remark that Bitcoin has taken gold’s role in today’s world reflects both his belief in its value and American Bitcoin’s strategy of mining and holding. Whether that view sticks will depend on how investors and institutions respond in the months ahead. Featured image from Meta, chart from TradingView
Share
NewsBTC2025/09/18 06:00
UK Looks to US to Adopt More Crypto-Friendly Approach

UK Looks to US to Adopt More Crypto-Friendly Approach

The post UK Looks to US to Adopt More Crypto-Friendly Approach appeared on BitcoinEthereumNews.com. The UK and US are reportedly preparing to deepen cooperation on digital assets, with Britain looking to copy the Trump administration’s crypto-friendly stance in a bid to boost innovation.  UK Chancellor Rachel Reeves and US Treasury Secretary Scott Bessent discussed on Tuesday how the two nations could strengthen their coordination on crypto, the Financial Times reported on Tuesday, citing people familiar with the matter.  The discussions also involved representatives from crypto companies, including Coinbase, Circle Internet Group and Ripple, with executives from the Bank of America, Barclays and Citi also attending, according to the report. The agreement was made “last-minute” after crypto advocacy groups urged the UK government on Thursday to adopt a more open stance toward the industry, claiming its cautious approach to the sector has left the country lagging in innovation and policy.  Source: Rachel Reeves Deal to include stablecoins, look to unlock adoption Any deal between the countries is likely to include stablecoins, the Financial Times reported, an area of crypto that US President Donald Trump made a policy priority and in which his family has significant business interests. The Financial Times reported on Monday that UK crypto advocacy groups also slammed the Bank of England’s proposal to limit individual stablecoin holdings to between 10,000 British pounds ($13,650) and 20,000 pounds ($27,300), claiming it would be difficult and expensive to implement. UK banks appear to have slowed adoption too, with around 40% of 2,000 recently surveyed crypto investors saying that their banks had either blocked or delayed a payment to a crypto provider.  Many of these actions have been linked to concerns over volatility, fraud and scams. The UK has made some progress on crypto regulation recently, proposing a framework in May that would see crypto exchanges, dealers, and agents treated similarly to traditional finance firms, with…
Share
BitcoinEthereumNews2025/09/18 02:21
Tokyo Fashion Brand Expands Into Bitcoin and AI

Tokyo Fashion Brand Expands Into Bitcoin and AI

The post Tokyo Fashion Brand Expands Into Bitcoin and AI appeared on BitcoinEthereumNews.com. On Wednesday, Japanese casual apparel retailer Mac House announced that shareholders approved a name change to Gyet Co., Ltd., signaling a strategic shift into crypto and digital assets. The move highlights a broader corporate plan centered on cryptocurrency, blockchain, and artificial intelligence. It reflects the company’s ambition to launch a global Bitcoin treasury program, drawing attention from both domestic and international observers. “Yet” and Its Global Significance Gyet’s amended corporate charter introduces wide-ranging digital initiatives, adding cryptocurrency acquisition, trading, management, and payment services. The new objectives also cover crypto mining, staking, lending, and yield farming, as well as blockchain system development, NFT-related projects, and research in generative AI and data center operations. These changes indicate a clear intent to diversify beyond apparel and position the company within global technology and finance sectors. Sponsored Sponsored The rebranding reflects Gyet’s aim to operate with a broader international outlook. Its new name conveys three concepts: “Growth Yet,” “Global Yet,” and “Generation Yet,” signaling a desire to create technology-driven value for future generations while expanding beyond Japan’s domestic market. Bitcoin Purchasing and Mining Gyet declared its digital asset ambitions in June 2025 and in July signed a basic cooperation agreement with mining firm Zerofield. The company has since begun a $11.6 million Bitcoin acquisition program and is testing mining operations in US states such as Texas and Georgia, where electricity costs are relatively low. Its goal of holding more than 1,000 BTC is modest globally, but the model—funding purchases and mining with retail cash flow—remains unusual for an apparel business. Within Japan, Gyet follows companies such as Hotta Marusho and Kitabo, which have also diversified into cryptocurrency activities distinct from their original operations. This move may accelerate corporate Bitcoin holdings as a financial strategy, attract interest in overseas mining ventures by Japanese firms, and…
Share
BitcoinEthereumNews2025/09/18 11:13