• About
  • FAQ
  • Landing Page
Newsletter
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Business
  • Guide
  • Contact Us
No Result
View All Result
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Business
  • Guide
  • Contact Us
No Result
View All Result
No Result
View All Result
Home Business

Ledger Finds Popular Smartphone Chip Vulnerable to Unpatchable Attacks

admin by admin
December 4, 2025
in Business
0
Ledger Finds Popular Smartphone Chip Vulnerable to Unpatchable Attacks
191
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter



In brief

  • Ledger’s Donjon lab gained full control of a Mediatek smartphone chip using electromagnetic faults.
  • The flaw sits in the chip’s boot ROM, which cannot be patched once manufactured.
  • Ledger says the findings reinforce why hardware wallets rely on secure, tamper-resistant chips, although the company did not recommend against using software wallets.

An unpatchable flaw in a widely used smartphone chip developed by Taiwan-based MediaTek allowed researchers to take full control of the device through a precisely timed electromagnetic attack, according to new findings published on Wednesday by crypto wallet provider Ledger.

The vulnerable code sits in the chip’s boot ROM, the earliest stage of the startup process, meaning it cannot be corrected with a software update.

Related articles

How Florida’s Stablecoin Bill Mirrors ‘Big Brother’ Tools Outlawed Under Ron DeSantis’ CDBC Ban

How Florida’s Stablecoin Bill Mirrors ‘Big Brother’ Tools Outlawed Under Ron DeSantis’ CDBC Ban

March 15, 2026
Judge Rejects RICO Claims in Lawsuit Over Pastor-Led Crypto Ponzi Scheme

Judge Rejects RICO Claims in Lawsuit Over Pastor-Led Crypto Ponzi Scheme

March 14, 2026

Ledger’s Donjon team examined the MediaTek Dimensity 7300 (MT6878), a 4-nanometer system-on-chip found in many Android phones.

By applying carefully timed electromagnetic pulses during the chip’s initial boot sequence, the researchers were able to bypass memory-access checks and escalate into EL3, the highest privilege level in the ARM architecture.

“From malware that users could be tricked into installing on their machines, to fully remote, zero-click exploits commonly used by government-backed entities, there is simply no way to safely store and use one’s private keys on those devices,” they wrote.

The report comes at a time when attacks targeting cryptocurrency holders are on the rise.

A July report by Chainalysis said over $2.17 billion has been stolen from cryptocurrency services so far in 2025; more than the entirety of 2024.

While physical attacks are growing, the majority of crypto-related thefts are perpetrated by hackers through phishing attacks or scams.

Once they identified the precise timing window, each attempt by the Donjon team took about a second and had a success rate of 0.1%-1%, allowing a full compromise within minutes under lab conditions.

While Ledger is best known for its popular Nano hardware wallets, it did not outright say not to use smartphone-based wallets. The report suggests a new threat vector targeting software developers and users.

Ledger did not immediately respond to requests for comment by Decrypt.

Hardware and software crypto wallets

A cryptocurrency wallet is software that stores a user’s public and private keys and lets them send, receive, and monitor digital assets.

Hardware wallets or “cold wallets” go a step further by keeping those private keys offline on a separate physical device, detached from the internet and shielded from attacks that can reach phones or computers.

Software wallets or “hot wallets” are apps that allow users to store their digital assets on a variety of devices, but leave the user open to hacks and phishing attacks.

MediaTek, in a statement included in Ledger’s report, said electromagnetic fault-injection attacks were “out of scope” for the MT6878 because the chipset was designed as a consumer-grade component rather than as a high-security module for financial or sensitive systems.

“For products with higher hardware security requirements, such as hardware crypto wallets, we believe that they should be designed with appropriate countermeasures against EMFI attacks,” they wrote.

Ledger said devices built on the MT6878 remain exposed because the flaw resides in unchangeable silicon.

Secure-element chips, the company added, remain necessary for users who rely on self-custody or handle other sensitive cryptographic operations, since those components are designed specifically to withstand both hardware and software attacks.

“Smartphones’ threat model, just like any piece of technology that can be lost or stolen, cannot reasonably exclude hardware attacks,” Ledger wrote. “But the SoCs they use are no more exempt from the effects of fault injection than microcontrollers are, and security should really ultimately rely on Secure Elements, especially for self-custody.”

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



Source link

Share76Tweet48

Related Posts

How Florida’s Stablecoin Bill Mirrors ‘Big Brother’ Tools Outlawed Under Ron DeSantis’ CDBC Ban

How Florida’s Stablecoin Bill Mirrors ‘Big Brother’ Tools Outlawed Under Ron DeSantis’ CDBC Ban

by admin
March 15, 2026
0

In brief Florida Gov. Ron DeSantis, a vocal critic of government surveillance via CBDCs, could sign a bill that gives...

Judge Rejects RICO Claims in Lawsuit Over Pastor-Led Crypto Ponzi Scheme

Judge Rejects RICO Claims in Lawsuit Over Pastor-Led Crypto Ponzi Scheme

by admin
March 14, 2026
0

In brief RICO claims in a class-action lawsuit against a pastor were rejected by a federal judge. The pastor in...

PIP Labs Sheds Staff as Story Protocol Leans Into AI

PIP Labs Sheds Staff as Story Protocol Leans Into AI

by admin
March 13, 2026
0

In brief Story Protocol developer PIP Labs has let go of several employees and contractors. The reductions come as the...

Tether Backs Ark Labs’ $5.2 Million Bet on Bitcoin’s Stablecoin Revival

Tether Backs Ark Labs’ $5.2 Million Bet on Bitcoin’s Stablecoin Revival

by admin
March 12, 2026
0

In brief Ark Labs secured backing from Tether and Anchorage Digital. The firm plans to advance stablecoins and real-world assets...

Top Bitcoin Mining Pool Operator Foundry Is Getting Into Zcash

Top Bitcoin Mining Pool Operator Foundry Is Getting Into Zcash

by admin
March 11, 2026
0

In brief Foundry Digital is establishing a mining pool for Zcash, the privacy-focused cryptocurrency, which has surged more than 600%...

Load More
  • Trending
  • Comments
  • Latest
XRP price holds firm amid 30% volume spike

XRP price holds firm amid 30% volume spike

December 26, 2025
Lido DAO’s LDO price spikes as Arthur Hayes acquires 1.85M tokens

Lido DAO’s LDO price spikes as Arthur Hayes acquires 1.85M tokens

December 26, 2025
Solana Pullback Finds Purpose As Strong Hands Eye Accumulation Below $160

Solana Pullback Finds Purpose As Strong Hands Eye Accumulation Below $160

November 6, 2025
Bitcoin hashprice sinks to 2-year low as AI pivots split miners

Bitcoin hashprice sinks to 2-year low as AI pivots split miners

November 5, 2025

US Commodities Regulator Beefs Up Bitcoin Futures Review

0

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0

Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: $425.55

0
OpenAI GPT-5.4 vs xAI Grok 4.20: Which AI Chatbot Is Best for You?

What Is AGI? The AI Goal Everyone Talks About But No One Can Clearly Define

March 15, 2026
How Florida’s Stablecoin Bill Mirrors ‘Big Brother’ Tools Outlawed Under Ron DeSantis’ CDBC Ban

How Florida’s Stablecoin Bill Mirrors ‘Big Brother’ Tools Outlawed Under Ron DeSantis’ CDBC Ban

March 15, 2026
Bitcoin Turns Up the Heat on Lost Support for Its Latest Weekly Close

Bitcoin Turns Up the Heat on Lost Support for Its Latest Weekly Close

March 15, 2026
TRUMP meme coin retraces sharply as team moves 5 million tokens

TRUMP meme coin retraces sharply as team moves 5 million tokens

March 15, 2026

Recent News

OpenAI GPT-5.4 vs xAI Grok 4.20: Which AI Chatbot Is Best for You?

What Is AGI? The AI Goal Everyone Talks About But No One Can Clearly Define

March 15, 2026
How Florida’s Stablecoin Bill Mirrors ‘Big Brother’ Tools Outlawed Under Ron DeSantis’ CDBC Ban

How Florida’s Stablecoin Bill Mirrors ‘Big Brother’ Tools Outlawed Under Ron DeSantis’ CDBC Ban

March 15, 2026

Categories

  • Bitcoin
  • Blockchain
  • Business
  • Ethereum
  • Guide
  • Market
  • Regulation
  • Ripple
  • Uncategorized
  • About
  • FAQ
  • Support Forum
  • Landing Page
  • Contact Us

© Copyright 2025 All Rights Reserved.

No Result
View All Result
  • Contact Us
  • Homepages
  • Business
  • Guide

© Copyright 2025 All Rights Reserved.