Connect with us

Crypto World

Ledger Uncovers Security Vulnerability That Could Affect 25% of Android Phones

Published

on

Ledger Uncovers Security Vulnerability That Could Affect 25% of Android Phones

The chip vulnerability makes it possible for hackers to decrypt affected Android smartphones, and steal data — including crypto wallet private keys.

Ledger said on Wednesday, March 11, that it has discovered a vulnerability that could affect as much as 25% of Android phones, letting hackers steal users’ private keys, according to a press release shared with The Defiant.

The hardware wallet company’s in-house white-hat security team, the Donjon, has disclosed a critical vulnerability in Android smartphones powered by MediaTek chips that allows an attacker to extract user data — including wallet seed phrases and PINs — in under a minute, even when the phone is off.

In a proof-of-concept test, the Donjon plugged a Nothing CMF Phone 1 into a laptop and, within 45 seconds, was able to recover the device’s PIN, decrypt its storage, and extract seed phrases from six major crypto wallet apps: Trust Wallet, Base, Kraken Wallet, Rabby, tangem, and Phantom.

Advertisement

Before the operating system of the MediaTek-powered Android device even loads, Ledger’s security team found that an attacker can connect over USB and steal the root cryptographic keys that ensure the phone’s full-disk encryption, per the release. The phone’s data can than be fully decrypted offline.

The vulnerability could affects phones using Trustonic’s Trusted Execution Environment (TEE), the release said, including the Solana Seeker phone.

“Smartphones were never designed to be vaults,” said Charles Guillemet, Ledger’s CTO, adding:

“If your crypto sits on a phone, it’s only as safe as the weakest link in that phone’s hardware, firmware, or software.”

Following the standard 90-day responsible disclosure process, Ledger said it reported the flaw to both MediaTek and Trustonic. MediaTek confirmed it delivered a fix to affected original equipment manufacturers in January.

Advertisement

Ledger advised users of potentially affected Androids to install the latest security updates immediately.

The news comes crypto-related theft has been on the rise. As The Defiant reported, 2025 was a record year for crypto crime, with North Korea alone stealing roughly $2 billion — including the $1.5 billion Bybit hack, the largest hack on record.

But the threat isn’t limited to centralized exchanges. In December, Trust Wallet confirmed $7 million was stolen via a malicious Chrome extension update that harvested seed phrases directly from users’ browsers. Hackers have also reportedly been increasingly using AI tools and phishing-as-a-service infrastructure to increase the number of attacks.

This article was written with the assistance of AI workflows. All our stories are curated, edited and fact-checked by a human.

Advertisement

Source link

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Crypto World

Foundry to Launch Institutional-Grade Zcash Mining Pool in April 2026

Published

on

Privacy, Bitcoin Mining, United States, Zcash

Digital asset infrastructure company Foundry Digital plans to launch a mining pool for Zcash in April 2026, expanding beyond Bitcoin mining infrastructure. The company said the pool will be designed for institutional and publicly traded miners seeking compliance-focused mining services.

The new pool will be based in the United States and built on the same infrastructure used by Foundry USA Pool, which is operated by the company. Foundry said the service will include reporting tools and payout systems intended to meet the operational requirements of institutional miners.

Zcash is a privacy-focused cryptocurrency which features an encrypted ledger using zero-knowledge proofs. A mining pool is a service that allows multiple miners to combine computing power and share block rewards, increasing the chances of earning consistent payouts.

Advertisement

A spokesperson for Foundry told Cointelegraph that the company decided to build a the new mining pool because “Zcash addresses something we believe is genuinely important: the idea that financial privacy is foundational to economic freedom, and that privacy and compliance can coexist.” They added: 

When institutional and public miners can mine Zcash through infrastructure built to their standards, it brings new hashrate to the network and strengthens its security.

Foundry Digital was founded in 2019 and provides mining infrastructure and related services for digital asset companies. Its Foundry USA Pool is one of the largest Bitcoin mining pools by hashrate share. Foundry said it expects the Zcash pool to begin operations in April 2026.

The announcement comes days after developers who previously worked at Electric Coin Company raised more than $25 million to continue developing a privacy-focused wallet for Zcash. 

Related: Dash Evolution chain integrates Zcash Orchard privacy pool

Advertisement

Zcash garners attention amid price volatility

Zcash, launched in 2016, allows users to send transactions without publicly revealing details such as wallet addresses or transaction amounts. The network is based on Bitcoin’s codebase but uses zero-knowledge proofs, known as zk-SNARKs, to enable optional “shielded” transactions alongside standard transparent ones.

In 2025, Zcash became one of the most widely discussed privacy-focused assets in crypto, with comments from industry figures, including Arthur Hayes, Naval Ravikant and Mert Mumtaz, helping drive interest in the network and its native token, ZEC (ZEC).

The rally pushed Zcash up nearly 600% over the past year, climbing from below $35 in March 2025 to as high as $698.87 on Nov. 16, 2025, according to CoinGecko data. The token has since pulled back, falling 58.7% year-to-date from about $512 on Jan. 1 to roughly $212 at the time of writing.

Privacy, Bitcoin Mining, United States, Zcash
Zcash price over one year. Source: CoinGecko

Even with the renewed attention, the network’s mining activity remains concentrated among a small number of pools.

Data from Poolbay shows ViaBTC controlling about 31.7% of total hashrate, followed by F2Pool at roughly 15.8%, with smaller shares distributed across pools such as 2Miners and Antpool.

Advertisement

Magazine: All 21 million Bitcoin is at risk from quantum computers