Crypto Boost News

Crypto Boost News

Android Security Flaw Puts Crypto Wallet Recovery Phrases at Risk

Published: October 15th. 2025, Updated: August 8th. 2026

News & Events

Researchers Identify Android Vulnerability Threatening Crypto Security

Security researchers have identified an Android vulnerability that enables malicious applications to extract content from other apps, specifically putting sensitive crypto wallet recovery phrases at risk. The attack, called 'Pixnapping,' demonstrates a new vector for stealing secrets from both browser and non-browser applications.

How the Pixnapping Attack Works

Unlike conventional attacks that seek direct access to screen content, Pixnapping layers multiple semi-transparent activities controlled by the attacker on top of a targeted app. By masking all but a single chosen pixel and manipulating display colors, the malicious app can infer the pixel's value. Through repeated sampling and timing, it gradually reconstructs information displayed on the screen.

This process is time-consuming, meaning quickly displayed content is less vulnerable. However, information that remains visible for longer durations�such as crypto wallet recovery phrases�faces increased risk.

Tests and Scope of the Vulnerability

The researchers tested the exploit on five devices: Google Pixel 6, 7, 8, 9, and Samsung Galaxy S25, all running Android versions 13 to 16. Their analysis suggests that the underlying application programming interfaces (APIs) used in the attack are widely available, making other Android devices potentially susceptible as well.

Google responded by attempting to patch the flaw, primarily by limiting how many activities an app can blur at once. However, researchers found a workaround that continues to enable the attack, prompting further concern for user security. The issue was assigned a high-severity rating, and Google awarded a bug bounty to the discovering team. Samsung was also notified that the initial patch does not sufficiently protect its devices.

Implications for Crypto Users

Wallet recovery phrases allow attackers to gain full access to users' crypto assets. Typically, these phrases are displayed on screen for extended periods as users write them down, increasing the window of vulnerability. Experts recommend that users avoid displaying recovery phrases or other critical information on internet-connected devices when possible.

One robust solution is to use hardware wallets, which generate and store recovery phrases offline. They sign transactions electronically without exposing recovery details to mobile or computer screens, reducing vulnerability to such exploits.

Security Recommendations

  • Avoid displaying crypto wallet recovery phrases on Android or internet-connected devices.
  • Consider securing assets with a hardware wallet for enhanced protection.
  • Keep Android devices updated as manufacturers address security weaknesses.

The Pixnapping discovery highlights ongoing risks in mobile environments, prompting renewed focus on best practices for safeguarding crypto assets.

Related content

Want to get 100 USD with Binance?
Loading...
x