technology

Serious mediatek chipset flaw exposes 875 million android phones to pin theft in minutes

A newly discovered security vulnerability in certain MediaTek chipsets threatens the privacy and security of hundreds of millions of androiddevices worldwide.

Mediatek

Mediatek's flaw allows pin theft, data extraction in under 3 minutes

Researchers at Ledger's Donjon Hacker Lab have uncovered an extreme weakness in multiple chipsets designed by the Taiwanese semiconductor giant, MediaTek. The flaw, assigned the CVE number 2026-20435, can be exploited to steal a phone's PIN and root keys even when the device is powered off under specific conditions.

According to the experts, an attacker only needs to physically connect the vulnerable phone to a computer via USB while it's being powered on to gain unauthorized access to sensitive data, including encrypted files and crypto wallet seed phrases, in a matter of seconds.

MediaTek has already patched the issue in January, but due to android's notorious fragmentation problem, not all affected devices will receive the update in time. This means millions of phones remain exposed to this serious security risk.

The impacted chipsets include the MT6700/MT6800/MT6900 series, as well as the MT8100/MT8600/MT8700 series. Specific models from Oppo, Realme, Vivo, and Xiaomi that use these processors are also vulnerable.

If you suspect your android phone is powered by a flawed MediaTek chipset, ensure you've installed the March security update. For those whose devices have lost support for software updates, it's strongly advised not to store sensitive information, such as crypto wallets, on those devices and consider upgrading to a new, secure phone as soon as possible.