
A permanent vulnerability in a widely used smartphone chip developed by the Taiwanese company MediaTek allowed experts to take full control of the device through a highly synchronized electromagnetic attack, according to new analyses released on Wednesday by Ledger, a cryptocurrency wallet company.
The problem is located in the chip's boot ROM — the first stage of the boot — and, because it is directly written into the silicon, it cannot be fixed via software update.
The Donjon team from Ledger investigated the MediaTek Dimensity 7300 (MT6878), a 4-nanometer SoC present in various models of Android smartphones. During testing, precisely applied electromagnetic pulses during the initial boot phase allowed bypassing memory checks and reaching the EL3 privilege level, the highest in the ARM architecture.
According to researchers, this makes it impossible to guarantee the security of private keys of digital wallets on such devices, as they are exposed to both malware and sophisticated remote exploits.
After identifying the exact moment of vulnerability, each attack attempt took about one second, with a success rate between 0.1% and 1%, enabling complete invasions in a few minutes in a lab environment.
Although Ledger is known for its Nano physical wallets, the report does not explicitly recommend avoiding wallets on smartphones but warns of a new risk vector affecting software developers and users.
The study arises amid a rise in attacks against cryptocurrency investors. Data from Chainalysis shows that by July 2025, over $2.17 billion had already been stolen from services in the sector — surpassing the entire amount for 2024. Despite the growth of physical attacks, most crimes still occur through phishing and digital scams.
Cryptocurrency wallets
- Hardware wallets (cold): store private keys on physical devices disconnected from the internet, offering greater protection against invasions.
- Software wallets (hot): applications that allow users to store digital assets on mobile phones or computers but expose users to online attack risks.
In response, MediaTek stated that electromagnetic injection attacks were not anticipated within the scope of the MT6878, as the chip was designed for use in consumer products and not in high-security financial systems. The company emphasized that devices aimed at critical operations should include specific countermeasures against this type of attack.
Ledger reiterated that devices with the MT6878 remain vulnerable since the flaw is embedded in the silicon itself. For sensitive operations like self-custody of cryptocurrencies, the company recommends using secure element chips designed to withstand both physical and digital attacks.
According to Ledger, smartphones — being easily lost or stolen — cannot be considered immune to hardware attacks. Security, therefore, must rely on secure elements, especially when it comes to protecting private keys.