Ledger’s internal security lab has disclosed a zero-day vulnerability in Android’s WebView component that allows malicious background applications to extract a Ledger’s internal security lab has disclosed a zero-day vulnerability in Android’s WebView component that allows malicious background applications to extract a

Critical Android Vulnerability Can Steal Your Crypto Seed Phrase in 3 Seconds

2026/03/12 10:30
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Ledger’s internal security lab has disclosed a zero-day vulnerability in Android’s WebView component that allows malicious background applications to extract a 24-word recovery seed from software wallets in under three seconds.

How the Attack Works

The vulnerability, named Memory-Mirror by Ledger Donjon researchers, exploits a bug in Android System WebView, the component that renders web content inside applications. A malicious app running in the background can trigger a memory leak that mirrors the contents of a wallet application’s private memory space into a shared cache accessible outside the normal sandbox boundary.

Android’s sandboxing architecture is designed to isolate each application’s memory from every other application on the device. Memory-Mirror bypasses that isolation under specific conditions that are not difficult to create. If a user enters their seed phrase into any software wallet while a compromised application is running in the background, the seed is extractable from the shared cache within three seconds of entry. The user sees nothing unusual. The wallet application behaves normally. The seed is gone.

The attack requires a malicious application to already be installed on the device, which lowers the barrier considerably given the volume of fraudulent applications that pass through app store review processes and the prevalence of sideloaded APK files in the crypto community.

The Scope of Exposure

Ledger Donjon estimates that over 70% of Android devices running versions 12 through 15 remain vulnerable without the March 2026 security patch. Google began rolling out the fix to Pixel devices on March 5. Samsung and Xiaomi patches are expected by late March. Every Android device that has not received a build version ending in .0326 is currently susceptible.

The CoinGecko hot wallet ranking published earlier today placed Trust Wallet at number one and MetaMask at number two globally. Both wallets have temporarily disabled the Import via Seed feature on Android until device patch status can be verified. Phantom at number four on the same list is similarly affected. The three most popular non-custodial mobile wallets in the world have suspended seed import functionality on the platform that the majority of their users access them through.

Vivek Ramaswamy’s Strive Just Passed Tesla on the Bitcoin Treasury Leaderboard

What to Do Immediately

Android users holding crypto in any software wallet should check for the March 2026 security update immediately. Navigate to Settings, then Security or System, then Software Update, and verify the build version ends in .0326. If the update is not yet available from the device manufacturer, treat the device as compromised for seed entry purposes until it is.

Ledger’s recommendations extend beyond patching. Entering a recovery seed into any mobile keyboard on any software wallet carries inherent risk that exists independently of Memory-Mirror. The keyboard itself, clipboard managers, and screen recording applications all represent potential extraction vectors that hardware wallets eliminate by design. The Ledger Nano and Stax devices are unaffected by Memory-Mirror because the seed phrase never leaves the device’s Secure Element chip and is never exposed to the Android operating system at any point.

The Trust Wallet address poisoning protection feature covered in this publication yesterday defended users against one attack vector at the transaction layer. Memory-Mirror operates at a fundamentally deeper level, targeting the seed itself rather than a single transaction. A compromised seed compromises every wallet, every chain, and every asset derived from it permanently.

Update the device. Do not enter seed phrases on mobile until the patch is confirmed installed.

The post Critical Android Vulnerability Can Steal Your Crypto Seed Phrase in 3 Seconds appeared first on ETHNews.

Market Opportunity
LAB Logo
LAB Price(LAB)
$0.17303
$0.17303$0.17303
+1.18%
USD
LAB (LAB) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

The Channel Factories We’ve Been Waiting For

The Channel Factories We’ve Been Waiting For

The post The Channel Factories We’ve Been Waiting For appeared on BitcoinEthereumNews.com. Visions of future technology are often prescient about the broad strokes while flubbing the details. The tablets in “2001: A Space Odyssey” do indeed look like iPads, but you never see the astronauts paying for subscriptions or wasting hours on Candy Crush.  Channel factories are one vision that arose early in the history of the Lightning Network to address some challenges that Lightning has faced from the beginning. Despite having grown to become Bitcoin’s most successful layer-2 scaling solution, with instant and low-fee payments, Lightning’s scale is limited by its reliance on payment channels. Although Lightning shifts most transactions off-chain, each payment channel still requires an on-chain transaction to open and (usually) another to close. As adoption grows, pressure on the blockchain grows with it. The need for a more scalable approach to managing channels is clear. Channel factories were supposed to meet this need, but where are they? In 2025, subnetworks are emerging that revive the impetus of channel factories with some new details that vastly increase their potential. They are natively interoperable with Lightning and achieve greater scale by allowing a group of participants to open a shared multisig UTXO and create multiple bilateral channels, which reduces the number of on-chain transactions and improves capital efficiency. Achieving greater scale by reducing complexity, Ark and Spark perform the same function as traditional channel factories with new designs and additional capabilities based on shared UTXOs.  Channel Factories 101 Channel factories have been around since the inception of Lightning. A factory is a multiparty contract where multiple users (not just two, as in a Dryja-Poon channel) cooperatively lock funds in a single multisig UTXO. They can open, close and update channels off-chain without updating the blockchain for each operation. Only when participants leave or the factory dissolves is an on-chain transaction…
Share
BitcoinEthereumNews2025/09/18 00:09
U.S. inflation expectations diverge across March surveys

U.S. inflation expectations diverge across March surveys

The post U.S. inflation expectations diverge across March surveys appeared on BitcoinEthereumNews.com. No official source confirms 3.4% to 3.7% March shift Claims
Share
BitcoinEthereumNews2026/03/14 01:49
XRP Price Prediction Surges as Investment Products Climb 508% to $3.7 Billion in AUM Outpacing Bitcoin Ethereum and Solana While Pepeto Captures Every Institutional Dollar That XRP’s Dominance Attracts

XRP Price Prediction Surges as Investment Products Climb 508% to $3.7 Billion in AUM Outpacing Bitcoin Ethereum and Solana While Pepeto Captures Every Institutional Dollar That XRP’s Dominance Attracts

XRP investment products surged 508% in 2025 to $3.7 billion in assets under management. This outpaced inflows into Bitcoin, Ethereum, and Solana products during
Share
Techbullion2026/03/14 02:38