Ledger has revealed a critical and unfixable vulnerability in a popular smartphone chip used in devices such as the crypto-focused Solana Seeker, raising serious concerns about the security of private keys stored on mobile phones.
According to Ledger’s technical report, the MediaTek Dimensity 7300 (MT6878) chip can be compromised through electromagnetic fault injection, allowing attackers to gain “full and absolute control” over a device during its initial boot sequence. Ledger engineers Charles Christen and Léo Benito demonstrated that by applying electromagnetic pulses at the right moment, they were able to bypass the chip’s security protections and take complete control of the system.
Because many crypto users store their private keys on their phones, this flaw poses a severe risk. Once an attacker gains access to the device, private keys can be extracted—enabling theft from connected crypto wallets. “There is simply no way to safely store and use one’s private keys on those devices,” Ledger warned.
The vulnerability cannot be fixed with any software update or security patch, since the flaw is embedded directly in the chip’s silicon design. Even though the attack’s success rate is low—between 0.1% and 1%—Ledger notes that an attacker can retry every second, making successful exploitation possible within minutes.
MediaTek responded that such electromagnetic attacks are “out of scope” for the MT6878, emphasizing that the chip is intended for consumer products, not financial applications or hardware security modules. Ledger reported the issue to MediaTek in early May, after confirming the exploit in tests conducted between February and May.
The discovery highlights growing concerns around relying on mobile devices for securing crypto assets, especially as crypto-friendly smartphones become more mainstream.
Submit Your Comments
(Replying)
Please keep in mind to avoid offensive keywords and also fake information.
Be the first one to comment.