875 Million android phones vulnerable to pin steal – even when off
A chilling discovery has exposed a critical security flaw impacting a quarter of all active Android devices, leaving a staggering 875 million handsets vulnerable to PIN theft in under a minute. The vulnerability, assigned CVE 2026-20435, is particularly alarming because it can be exploited even when the phone is powered off – a seemingly safe state.
The shocking details: how hackers can bypass biometrics
Researchers at Ledger’s Donjon Hacker Lab unearthed the flaw within MediaTek-designed chipsets. The method is surprisingly straightforward: a physical USB connection while powering on the device allows attackers to extract sensitive data, including PINs and root keys that safeguard encrypted content. This bypasses biometric security measures – fingerprint scanners and facial recognition – rendering them effectively useless. The implications are profound; your most sensitive data, from passwords to cryptocurrency wallets, is potentially at risk.
Imagine this: a hacker gains access to your phone’s Master Key, allowing them to “unwrap” encrypted files offline and read every detail. Notes apps, banking information, and even crypto wallet seed phrases are exposed in plain text. The vulnerability is so severe it could even allow an attacker to spoof biometric authentication, granting them unauthorized access to your device.

The fragmentation problem – will you get the patch?
MediaTek addressed the vulnerability with a patch released in January, a glimmer of hope in this unsettling situation. However, the fragmented nature of the Android ecosystem presents a significant obstacle. The delay between Google releasing an Android update and its availability on your specific device is notorious, and many users may never receive the necessary fix.
The list of affected chipsets is extensive, spanning the MediaTek MT6700/MT6800/MT6900 and MT8100/MT8600/MT8700 series. Common brands affected include Oppo, Realme, Vivo, and Xiaomi, particularly their mid-range models. If you recognize the chipset powering your device in this list, it’s critical to check for the March Android security update. Those whose phones have already abandoned support for updates should seriously consider safeguarding their data and perhaps even purchasing a new phone.
Charles Guillemet, Ledger's Chief Technology Officer, succinctly put it:
