Skip to main content
See every side of every news story
Published loading...Updated

MediaTek Vulnerability Enabled Researchers to Break a Nothing CMF Phone’s Security in Mere 45 Seconds

It seems MediaTek chipset-powered phones, including the Nothing CMF, have a serious security vulnerability. Security researchers from Ledger’s hardware security team, Donjon, have managed to expose a vulnerability affecting millions of MediaTek chip-powered Android devices. As a proof-of-concept demonstration, the team managed to completely bypass the security of a Nothing CMF Phone 1 model in just 45 seconds. It is a critical boot chain vulnera…

7 Articles

Lean Right

The breach, discovered by the teams of "ethical hackers" of the French company of Ledger cryptocurrency wallets, comes from a chip model that many brands use.

·Paris, France
Read Full Article

Ledger's hacker lab team announced the discovery of a critical flaw on MediaTek processors widely used in Android phones. The flaw can potentially allow the theft of private data, messages, photos and information. "In a concept proof test, Ledger's team of ethical hackers, Ledger Donjon, connected a Nothing CMF Phone 1 to a laptop and compromised the foundation of phone security in 45 seconds.

A critical gap in MediaTek processors endangers millions of Android smartphones. Security researchers demonstrated how PINs and crypto keys can be extracted in just under a minute - even when devices are switched off. (Continue reading)

A simple USB cable, less than a minute and a phone turned off: this is all it takes to siphon the best kept secrets of a quarter of Android smartphones in circulation.

What to remember: The Ledger Donjon has discovered a vulnerability to steal an Android PIN in 45 seconds without turning on the phone. The flaw, referenced CVE-2025-20435, affects devices combining MediaTek chips and Trustonic secure environment, which is about 25% of the world's Androids. A patch was sent to manufacturers on January 5, 2026: installing the latest system updates is imperative. In 45 seconds, without turning on the phone, Ledger'…

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources lean Right
100% Right

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

Cryptoast broke the news in on Thursday, March 12, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal