875 Million androids can be cracked in 60 seconds—while switched off

Your phone is off, locked, and in your pocket. That’s still not enough. A dormant MediaTek boot-ROM bug lets a laptop and a USB cable extract your PIN, biometric templates, and hardware-rooted encryption keys in under a minute. Ledger’s Donjon team timed it: 52 seconds from cold boot to plaintext secrets.

The chip that never truly sleeps

The flaw lives in the on-chip ROM that wakes up before the operating system—think of it as the chip’s reptile brain. Because the code is baked into silicon, it can’t be field-replaced; the patch has to ride in every downstream firmware blob that OEMs eventually ship. MediaTek issued the fix in January, but the company doesn’t push updates to end users. That job falls to Samsung, Xiaomi, Oppo, Vivo, Realme, Nothing and a hundred smaller brands, each with its own QA calendar. Translation: most owners will wait months, if they get it at all.

Attack surface is tiny—physical access, USB, custom bootloader—but the payoff is maximal. Once the root key is leaked, the attacker can unwrap the file-based encryption master key offline, rendering android’s AES-256-XTS layer as useful as tissue paper. Password caches, crypto seeds, even photos you deleted last year stream out in raw form.

How to know if you’re carrying the vulnerability

How to know if you’re carrying the vulnerability

Check the application processor under Settings> About> (SoC). If the string starts with MT67, MT68, MT69, MT81, MT86, MT87 or MT2737, you’re in the club—one in four android devices sold between 2019 and 2024. Flagship killers from OnePlus Nord to Samsung’s A-series share the same ROM entry point. The quickest tell: if your phone launched with android 11 or 12 and cost under €400, odds are high.

No rooting required for exploitation; the phone just has to accept an over-voltage signal on the USB data line while the CPU is coming out of reset. Researcher Charles Guillemet calls it «a skeleton key hidden in plain silicon.» MediaTek downplays the drama, noting the attacker must already have the device, but that’s cold comfort for travelers crossing borders or anyone whose handset spends time in a repair shop.

Fragmentation is the real exploit

Fragmentation is the real exploit

Google’s March security bulletin tags the bug CVE-2026-20435, yet the patch is optional for vendors. OEMs that already ended support—looking at you, early Realme Narzo and Vivo Y-series—won’t retrofit anything. Devices stuck on android 12 are essentially frozen in a broken state. Secondary-market and emerging-market phones, where MediaTek dominance tops 60 %, will stay exposed the longest.

If updates dried up, treat the handset like a burner: wipe it, sell it, or relegate it to streaming duty—just don’t park wallets, 2FA seeds, or corporate mail on it. For everyone else, pull the March update now, not when the notification feels convenient. The 52-second hack doesn’t care about your schedule.