Ledger’s internal security lab has disclosed a zero-day vulnerability in Android’s WebView component that allows malicious background applications to extract a Ledger’s internal security lab has disclosed a zero-day vulnerability in Android’s WebView component that allows malicious background applications to extract a

Critical Android Vulnerability Can Steal Your Crypto Seed Phrase in 3 Seconds

2026/03/12 10:30
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Ledger’s internal security lab has disclosed a zero-day vulnerability in Android’s WebView component that allows malicious background applications to extract a 24-word recovery seed from software wallets in under three seconds.

How the Attack Works

The vulnerability, named Memory-Mirror by Ledger Donjon researchers, exploits a bug in Android System WebView, the component that renders web content inside applications. A malicious app running in the background can trigger a memory leak that mirrors the contents of a wallet application’s private memory space into a shared cache accessible outside the normal sandbox boundary.

Android’s sandboxing architecture is designed to isolate each application’s memory from every other application on the device. Memory-Mirror bypasses that isolation under specific conditions that are not difficult to create. If a user enters their seed phrase into any software wallet while a compromised application is running in the background, the seed is extractable from the shared cache within three seconds of entry. The user sees nothing unusual. The wallet application behaves normally. The seed is gone.

The attack requires a malicious application to already be installed on the device, which lowers the barrier considerably given the volume of fraudulent applications that pass through app store review processes and the prevalence of sideloaded APK files in the crypto community.

The Scope of Exposure

Ledger Donjon estimates that over 70% of Android devices running versions 12 through 15 remain vulnerable without the March 2026 security patch. Google began rolling out the fix to Pixel devices on March 5. Samsung and Xiaomi patches are expected by late March. Every Android device that has not received a build version ending in .0326 is currently susceptible.

The CoinGecko hot wallet ranking published earlier today placed Trust Wallet at number one and MetaMask at number two globally. Both wallets have temporarily disabled the Import via Seed feature on Android until device patch status can be verified. Phantom at number four on the same list is similarly affected. The three most popular non-custodial mobile wallets in the world have suspended seed import functionality on the platform that the majority of their users access them through.

Vivek Ramaswamy’s Strive Just Passed Tesla on the Bitcoin Treasury Leaderboard

What to Do Immediately

Android users holding crypto in any software wallet should check for the March 2026 security update immediately. Navigate to Settings, then Security or System, then Software Update, and verify the build version ends in .0326. If the update is not yet available from the device manufacturer, treat the device as compromised for seed entry purposes until it is.

Ledger’s recommendations extend beyond patching. Entering a recovery seed into any mobile keyboard on any software wallet carries inherent risk that exists independently of Memory-Mirror. The keyboard itself, clipboard managers, and screen recording applications all represent potential extraction vectors that hardware wallets eliminate by design. The Ledger Nano and Stax devices are unaffected by Memory-Mirror because the seed phrase never leaves the device’s Secure Element chip and is never exposed to the Android operating system at any point.

The Trust Wallet address poisoning protection feature covered in this publication yesterday defended users against one attack vector at the transaction layer. Memory-Mirror operates at a fundamentally deeper level, targeting the seed itself rather than a single transaction. A compromised seed compromises every wallet, every chain, and every asset derived from it permanently.

Update the device. Do not enter seed phrases on mobile until the patch is confirmed installed.

The post Critical Android Vulnerability Can Steal Your Crypto Seed Phrase in 3 Seconds appeared first on ETHNews.

Market Opportunity
LAB Logo
LAB Price(LAB)
$0.15032
$0.15032$0.15032
+4.43%
USD
LAB (LAB) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Top Solana Treasury Firm Forward Industries Unveils $4 Billion Capital Raise To Buy More SOL ⋆ ZyCrypto

Top Solana Treasury Firm Forward Industries Unveils $4 Billion Capital Raise To Buy More SOL ⋆ ZyCrypto

The post Top Solana Treasury Firm Forward Industries Unveils $4 Billion Capital Raise To Buy More SOL ⋆ ZyCrypto appeared on BitcoinEthereumNews.com. Advertisement &nbsp &nbsp Forward Industries, the largest publicly traded Solana treasury company, has filed a $4 billion at-the-market (ATM) equity offering program with the U.S. SEC  to raise more capital for additional SOL accumulation. Forward Strategies Doubles Down On Solana Strategy In a Wednesday press release, Forward Industries revealed that the 4 billion ATM equity offering program will allow the company to issue and sell common stock via Cantor Fitzgerald under a sales agreement dated Sept. 16, 2025. Forward said proceeds will go toward “general corporate purposes,” including the pursuit of its Solana balance sheet and purchases of income-generating assets. The sales of the shares are covered by an automatic shelf registration statement filed with the US Securities and Exchange Commission that is already effective – meaning the shares will be tradable once they’re sold. An automatic shelf registration allows certain publicly listed companies to raise capital with flexibility swiftly.  Kyle Samani, Forward’s chairman, astutely described the ATM offering as “a flexible and efficient mechanism” to raise and deploy capital for the company’s Solana strategy and bolster its balance sheet.  Advertisement &nbsp Though the maximum amount is listed as $4 billion, the firm indicated that sales may or may not occur depending on existing market conditions. “The ATM Program enhances our ability to continue scaling that position, strengthen our balance sheet, and pursue growth initiatives in alignment with our long-term vision,” Samani said. Forward Industries kicked off its Solana treasury strategy on Sept. 8. The Wednesday S-3 form follows Forward’s $1.65 billion private investment in public equity that closed last week, led by crypto heavyweights like Galaxy Digital, Jump Crypto, and Multicoin Capital. The company started deploying that capital this week, announcing it snatched up 6.8 million SOL for approximately $1.58 billion at an average price of $232…
Share
BitcoinEthereumNews2025/09/18 03:42
Tokenized Securities remain securities under SEC Howey test

Tokenized Securities remain securities under SEC Howey test

The post Tokenized Securities remain securities under SEC Howey test appeared on BitcoinEthereumNews.com. SEC: tokenized securities remain securities under U.S.
Share
BitcoinEthereumNews2026/03/12 11:45
BitMine’s $11B Ethereum Bet — Smart Move or Risky Gamble Before the Next Bull Run?

BitMine’s $11B Ethereum Bet — Smart Move or Risky Gamble Before the Next Bull Run?

BitMine's massive $11 billion investment in Ethereum has raised eyebrows in the crypto world. As the market eagerly awaits the next bull run, this bold move has sparked debates and curiosity. Is it a clever strategy or a high-stakes risk? Explore which coins are poised for growth in this fluctuating landscape. Ethereum Poised for Growth Amid Steady Movement Source: tradingview  Ethereum's price is steady, moving between approximately $4335 and $4825. The crypto giant is showing promise, with a week's growth of over four percent. This follows a half-year surge of nearly 127 percent. Although the current pace is slower, the potential for breaking above the $5040 resistance level is strong. If it breaches this point, Ethereum could aim for the next resistance at $5530. Such a move would be a noticeable increase from today's range, suggesting this crypto could continue its climb. The market indicators point to a balanced phase, meaning Ethereum might be setting the stage for further growth. Keep an eye on those key levels! Conclusion BitMine’s move has sparked debate. If ETH rises, the valuation could be substantial. However, market trends can change quickly. Timing and strategy will be key. BitMine’s decision shows confidence in ETH, but only time will tell if it pays off. The sector awaits the next market movement with interest. Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.
Share
Coinstats2025/09/18 00:44