CoinsValue.net logo CoinsValue.net logo
BitcoinSistemi 2025-12-04 21:08:08

Android Phone Users Beware: Security Vulnerability Detected for Cryptocurrencies

The Donjon research team at cryptocurrency security firm Ledger has discovered a critical vulnerability in a smartphone processor widely used in the Android ecosystem. The vulnerability puts users, particularly those using software-based Web3 wallets, at risk of having their digital assets compromised if their devices are physically compromised. Ledger researchers, conducting research on the MediaTek Dimensity 7300 chip manufactured by TSMC, have demonstrated that the processor's secure boot process can be bypassed using electromagnetic fault injection (EMFI). The vulnerability allows attackers to gain full control over the processor by disabling the earliest security checks in the device's boot ROM. Related News: Anticipated Survey Arrived: What Decision Will the FED Make Next Week Regarding Interest Rates? The Top 100 Economists Responded Using open-source tools, the team fired electromagnetic pulses at the precise moment to access the boot ROM's operating system. The chip's write command filtering mechanism was then bypassed, altering the return address in the ROM stack. This method allowed arbitrary code execution at EL3, the processor's highest privilege level. According to Ledger, the attack can be replicated within minutes. The company emphasized that this finding doesn't affect Ledger hardware wallets, arguing that “even the most advanced smartphone chips are vulnerable to physical attacks.” Ledger stated that smartphones used as hot wallets are not suitable for storing private keys, and that true security can be achieved with hardware wallets that include secure elements. *This is not investment advice. Continue Reading: Android Phone Users Beware: Security Vulnerability Detected for Cryptocurrencies

阅读免责声明 : 此处提供的所有内容我们的网站,超链接网站,相关应用程序,论坛,博客,社交媒体帐户和其他平台(“网站”)仅供您提供一般信息,从第三方采购。 我们不对与我们的内容有任何形式的保证,包括但不限于准确性和更新性。 我们提供的内容中没有任何内容构成财务建议,法律建议或任何其他形式的建议,以满足您对任何目的的特定依赖。 任何使用或依赖我们的内容完全由您自行承担风险和自由裁量权。 在依赖它们之前,您应该进行自己的研究,审查,分析和验证我们的内容。 交易是一项高风险的活动,可能导致重大损失,因此请在做出任何决定之前咨询您的财务顾问。 我们网站上的任何内容均不构成招揽或要约