Security researchers have uncovered a serious Android vulnerability that could expose cryptocurrency wallet seed phrases and two-factor authentication codes.Security researchers have uncovered a serious Android vulnerability that could expose cryptocurrency wallet seed phrases and two-factor authentication codes.

New Android Attack ‘Pixnapping’ Threatens Crypto Wallet Security

2025/10/15 04:41
5 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com
New Android Attack 'Pixnapping' Threatens Crypto Wallet Security

The attack, named Pixnapping, works by reading what’s displayed on your screen—pixel by pixel—without needing any special permissions.

How the Attack Works

Pixnapping exploits weaknesses in how Android displays information on your screen. A research team from UC Berkeley, Carnegie Mellon, and other universities discovered that malicious apps can reconstruct sensitive data by measuring tiny timing differences in how pixels are rendered.

The attack happens in three steps. First, a malicious app triggers another app (like Google Authenticator) to display sensitive information. Second, it overlays semi-transparent windows and uses Android’s blur API to manipulate individual pixels. Third, it measures rendering times through a hardware weakness called GPU.zip to steal pixel values one at a time.

How the Attack Works

Source: pixnapping.com

Think of it like taking a screenshot, but instead of capturing the whole screen at once, the attacker reconstructs the image pixel by pixel by measuring how long each one takes to draw. The malicious app doesn’t need screen recording permissions or notification access—it simply exploits standard Android features that most apps can use.

Real-World Testing Results

Researchers tested Pixnapping on five devices: Google Pixel 6, 7, 8, and 9, plus Samsung Galaxy S25. All ran Android versions 13 through 16. The results were concerning for Pixel owners. On Pixel devices, the attack successfully recovered full six-digit 2FA codes in 73% of attempts on Pixel 6, 53% on Pixel 7 and 9, and 29% on Pixel 8. Recovery times ranged from 14 to 26 seconds—well within the 30-second window that most authentication codes remain valid.

Interestingly, the Samsung Galaxy S25 proved more resistant. Researchers were unable to recover codes within 30 seconds on this device due to noise in its graphics hardware. The team demonstrated successful data theft from popular apps including Google Authenticator, Signal, Venmo, Gmail, and Google Maps. Any information visible on screen becomes vulnerable, from private messages to location data.

Critical Threat to Crypto Wallets

For cryptocurrency holders, this vulnerability poses a major risk. Wallet seed phrases—the 12 or 24 words that grant complete access to your crypto—are especially vulnerable because users typically leave them displayed while writing them down for backup.

While stealing a full 12-word phrase takes longer than grabbing a 2FA code, the attack remains effective if the phrase stays visible. Once attackers have your seed phrase, they control your entire wallet. No additional passwords or security measures can stop them from draining your funds.

Hardware wallets remain the safest option because they never display seed phrases on internet-connected devices. The private keys stay isolated in the hardware device, signing transactions without exposing sensitive information to your phone or computer.

Current Patch Status

Google learned about Pixnapping in February 2025 and assigned it CVE-2025-48561, rating it high severity. The company released a partial fix in September 2025 by limiting how many times apps can use blur effects—a key component of the attack.

However, researchers found a workaround that bypasses Google’s first patch. Google confirmed it will release another update in the December 2025 security bulletin to address remaining vulnerabilities.

The good news: Google reports no evidence of real-world attacks using Pixnapping. Their Play Store security systems haven’t detected any malicious apps exploiting this vulnerability. But the attack remains possible on unpatched devices.

Samsung devices also received the September patch. Researchers notified Samsung that Google’s initial patch was insufficient to protect Samsung devices from the original attack. Both companies continue coordinating on additional protections.

Protecting Your Assets

No special mitigation exists yet for individual apps to defend against Pixnapping. The fixes must come from Google and Samsung at the system level. Meanwhile, several steps can reduce your risk:

Install security updates immediately when they arrive. The December patch should significantly improve protection for compatible devices.

Download apps only from Google Play Store, avoiding unknown APK files from websites or third parties. Review what permissions your apps request—though Pixnapping doesn’t need special permissions, limiting app access still improves overall security.

Never display crypto wallet seed phrases on any internet-connected device if possible. Write them down on paper immediately rather than leaving them on screen. Better yet, use a hardware wallet for storing significant cryptocurrency holdings.

Consider the broader security landscape. This year has seen major crypto theft, with billions lost to various attacks. Mobile security represents just one vulnerability among many.

The Bigger Picture

Pixnapping reveals fundamental weaknesses in how Android handles window layering and graphics rendering. The attack exploits data compression in Mali GPUs used by Pixel phones—compression creates timing variations that leak information about pixel values.

Other Android phone manufacturers likely face similar risks since the necessary mechanisms exist across the Android ecosystem. The research team hasn’t tested all brands yet, but the core APIs enabling the attack are standard Android features.

The underlying GPU.zip hardware vulnerability remains unpatched. No GPU manufacturers have committed to fixing the compression timing leak that makes Pixnapping possible.

Researchers will release their proof-of-concept code on GitHub once patches are widely available.

Bottom Line

Pixnapping demonstrates that even apps without suspicious permissions can pose serious threats. For crypto users, the message is clear: keep seed phrases off your phone. Use hardware wallets for serious holdings. Install updates promptly. And remember that convenience often conflicts with security—protecting your crypto requires taking extra steps that might feel inconvenient but could save you from total loss.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Vitalik Buterin to Ethereum Developers: Build It Like It Has to Last Without You

Vitalik Buterin to Ethereum Developers: Build It Like It Has to Last Without You

Key Takeaways Vitalik Buterin wants Ethereum apps built to survive without developers, corporate servers, or trusted third parties Two major […] The post Vitalik
Share
Coindoo2026/03/07 15:49
Non-Opioid Painkillers Have Struggled–Cannabis Drugs Might Be The Solution

Non-Opioid Painkillers Have Struggled–Cannabis Drugs Might Be The Solution

The post Non-Opioid Painkillers Have Struggled–Cannabis Drugs Might Be The Solution appeared on BitcoinEthereumNews.com. In this week’s edition of InnovationRx, we look at possible pain treatments from cannabis, risks of new vaccine restrictions, virtual clinical trials at the Mayo Clinic, GSK’s $30 billion U.S. manufacturing commitment, and more. To get it in your inbox, subscribe here. Despite their addictive nature, opioids continue to be a major treatment for pain due to a lack of effective alternatives. In an effort to boost new drugs, the FDA released new guidelines for non-opioid painkillers last week. But making these drugs hasn’t been easy. Vertex Pharmaceuticals received FDA approval for its non-opioid Journavx in January, then abandoned a next generation drug after a failed clinical trial earlier this summer. Acadia similarly abandoned a promising candidate after a failed trial in 2022. One possible basis for non-opioids might be cannabis. Earlier this year, researchers at Washington University at St. Louis and Stanford published a study showing that a cannabis-derived compound successfully eased pain in mice with minimal side effects. Munich-based pharmaceutical company Vertanical is perhaps the furthest along in this quest. It is developing a cannabinoid-based extract to treat chronic pain it hopes will soon become an approved medicine, first in the European Union and eventually in the United States. The drug, currently called Ver-01, packs enough low levels of cannabinoids (including THC) to relieve pain, but not so much that patients get high. Founder Clemens Fischer, a 50-year-old medical doctor and serial pharmaceutical and supplement entrepreneur, hopes it will become the first cannabis-based painkiller prescribed by physicians and covered by insurance. Fischer founded Vertanical, with his business partner Madlena Hohlefelder, in 2017, and has invested more than $250 million of his own money in it. With a cannabis cultivation site and drug manufacturing plant in Denmark, Vertanical has successfully passed phase III clinical trials in Germany and expects…
Share
BitcoinEthereumNews2025/09/18 05:26
Short-term profit-taking pushes Bitcoin back below key $70K level – What next?

Short-term profit-taking pushes Bitcoin back below key $70K level – What next?

The post Short-term profit-taking pushes Bitcoin back below key $70K level – What next? appeared on BitcoinEthereumNews.com. Bitcoin [BTC] rallied as high as $74
Share
BitcoinEthereumNews2026/03/07 16:09