Gate News: On March 11, security research team Donjon, a subsidiary of crypto wallet Ledger, discovered a vulnerability in the MediaTek processor secure boot chain. Attackers can physically connect to the phone via USB before the operating system loads to extract encryption keys, decrypt device storage, and obtain the device PIN and encrypted wallet seed phrase within approximately 45 seconds. In a proof-of-concept test, the vulnerability successfully extracted sensitive data from Trust Wallet, a certain exchange wallet, and Phantom wallet applications. Researchers stated that this vulnerability could affect about 25% of Android phones, specifically models using MediaTek chips and Trustonic Trusted Execution Environment. Ledger’s Chief Technology Officer Charles Guillemet said that smartphones were never designed to be vaults. While the vulnerability can be fixed with a patch, it highlights the inherent risks of storing keys on non-secure devices, and users are advised to update security patches as soon as possible.