A critical hardware flaw has been discovered in a smartphone chip, potentially exposing crypto holders to complete device takeover and private key theftA critical hardware flaw has been discovered in a smartphone chip, potentially exposing crypto holders to complete device takeover and private key theft

Ledger Says Smartphones Aren’t Safe for Private Keys After Chip Test

A critical hardware flaw has been discovered in a smartphone chip, potentially exposing crypto holders to complete device takeover and private key theft, according to a new report from Ledger.

Key Takeaways:

  • Ledger found an unfixable flaw in the MediaTek Dimensity 7300 chip that can lead to full device takeover and private key theft.
  • The attack targets the phone’s boot process, allowing hackers with physical access to bypass security controls in minutes.
  • No software update can fix the issue, as the vulnerability is built into the chip’s hardware.

In findings published Wednesday, researchers at the hardware wallet maker said they successfully compromised the MediaTek Dimensity 7300, bypassing built-in protections and gaining what they described as “full and absolute control” of an affected handset.

The vulnerability, they warned, allows attackers with physical access to extract sensitive data, including cryptographic keys used to secure digital assets.

Smartphone Chips Exposed by Boot-Phase Attack, Ledger Finds

The chip powers a range of smartphones. Ledger security engineers Charles Christen and Léo Benito said the exploit hinges on electromagnetic fault injection during the chip’s earliest boot phase.

By carefully disrupting that process, the team was able to circumvent memory protections and overwrite security controls inside the system-on-chip.

“The result is total compromise,” the researchers said, adding that once the attack is successful, there is no technical barrier left to prevent access to data stored on the device.

Most importantly for crypto users, the vulnerability cannot be resolved through updates or software patches.

The weakness is embedded in the silicon itself, making it permanent for all devices built on the affected chipset. “Users remain exposed even after disclosure,” the researchers wrote.

While the chance of success in a single attempt is relatively low, estimated between 0.1% and 1%, the attack can be executed repeatedly in quick succession.

Ledger estimates that with enough attempts, compromise can occur in a matter of minutes.

MediaTek told Ledger the issue lies outside the design scope of the Dimensity 7300.

In a statement, the company said the chip was developed for consumer smartphones, not for environments requiring secure enclaves comparable to financial infrastructure or hardware security modules.

“For products handling sensitive cryptographic material, manufacturers should implement specific protections against physical attacks,” MediaTek said.

Ledger disclosed the flaw to MediaTek in early May after beginning tests in February. The chipmaker subsequently notified device vendors believed to be affected.

Solana Mobile to Launch SKR Governance Token in 2026

Solana Mobile plans to launch SKR, a native token tied to its Seeker phone, at the start of 2026, positioning it as the governance token for its mobile ecosystem.

The token will have a total supply of 10 billion, with 30% earmarked for airdrops and 25% set aside for growth and partnerships.

The remaining allocation includes 10% for liquidity, 10% for a community treasury, 15% for Solana Mobile, and 10% for Solana Labs.

The company says SKR is meant to give Seeker owners “actual ownership in the platform” and will feature linear inflation to reward early stakers.

More details are expected to be revealed at Solana Breakpoint Conference from Dec. 11–13.

Market Opportunity
Core DAO Logo
Core DAO Price(CORE)
$0.1331
$0.1331$0.1331
+5.21%
USD
Core DAO (CORE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Yarm Explained: Turning Trust and Tweets into Yield

Yarm Explained: Turning Trust and Tweets into Yield

tl;dr: Yarm is a new platform by Mitosis and Kaito AI that turns social influence into onchain yield. Yappers earn Mindshare by posting…Continue reading on Coinmonks »
Share
Medium2025/09/18 14:43
Crossmint Partners with MoneyGram for USDC Remittances in Colombia

Crossmint Partners with MoneyGram for USDC Remittances in Colombia

TLDR Crossmint enables MoneyGram’s new stablecoin payment app for cross-border transfers. The new app allows USDC transfers from the US to Colombia, boosting financial inclusion. MoneyGram offers USDC savings and Visa-linked spending for Colombian users. The collaboration simplifies cross-border payments with enterprise-grade blockchain tech. MoneyGram, a global leader in remittance services, launched its stablecoin-powered cross-border [...] The post Crossmint Partners with MoneyGram for USDC Remittances in Colombia appeared first on CoinCentral.
Share
Coincentral2025/09/18 21:02
US SEC suspends trading in shares of digital asset treasury firms QMMM and Smart Digital

US SEC suspends trading in shares of digital asset treasury firms QMMM and Smart Digital

PANews reported on September 30th that the U.S. Securities and Exchange Commission (SEC) has suspended trading in QMMM Holdings Ltd.'s stock after its share price surged nearly 1,000% in less than three weeks, according to Bloomberg. The SEC stated on Monday that recommendations to buy QMMM stock posted on social media by "unidentified individuals" may have manipulated its share price. Since QMMM announced earlier this month that it would establish a "diversified cryptocurrency treasury" with an initial investment of $100 million, targeting investments in Bitcoin, Ethereum, and Solana, its share price has surged 959%. The SEC stated that the trading suspension is a temporary measure and will end at 11:59 PM EST on October 10th. On Monday, the SEC also suspended trading in Smart Digital Group Ltd.'s shares for similar reasons. The suspension will also expire at 11:59 PM ET on October 10. The company announced last week that it would establish a "diversified cryptocurrency asset pool," focusing on digital assets like Bitcoin and Ethereum. Since the announcement, its stock price has fallen significantly.
Share
PANews2025/09/30 08:32