Security researchers have uncovered a serious Android vulnerability that could expose cryptocurrency wallet seed phrases and two-factor authentication codes.Security researchers have uncovered a serious Android vulnerability that could expose cryptocurrency wallet seed phrases and two-factor authentication codes.

New Android Attack ‘Pixnapping’ Threatens Crypto Wallet Security

New Android Attack 'Pixnapping' Threatens Crypto Wallet Security

The attack, named Pixnapping, works by reading what’s displayed on your screen—pixel by pixel—without needing any special permissions.

How the Attack Works

Pixnapping exploits weaknesses in how Android displays information on your screen. A research team from UC Berkeley, Carnegie Mellon, and other universities discovered that malicious apps can reconstruct sensitive data by measuring tiny timing differences in how pixels are rendered.

The attack happens in three steps. First, a malicious app triggers another app (like Google Authenticator) to display sensitive information. Second, it overlays semi-transparent windows and uses Android’s blur API to manipulate individual pixels. Third, it measures rendering times through a hardware weakness called GPU.zip to steal pixel values one at a time.

How the Attack Works

Source: pixnapping.com

Think of it like taking a screenshot, but instead of capturing the whole screen at once, the attacker reconstructs the image pixel by pixel by measuring how long each one takes to draw. The malicious app doesn’t need screen recording permissions or notification access—it simply exploits standard Android features that most apps can use.

Real-World Testing Results

Researchers tested Pixnapping on five devices: Google Pixel 6, 7, 8, and 9, plus Samsung Galaxy S25. All ran Android versions 13 through 16. The results were concerning for Pixel owners. On Pixel devices, the attack successfully recovered full six-digit 2FA codes in 73% of attempts on Pixel 6, 53% on Pixel 7 and 9, and 29% on Pixel 8. Recovery times ranged from 14 to 26 seconds—well within the 30-second window that most authentication codes remain valid.

Interestingly, the Samsung Galaxy S25 proved more resistant. Researchers were unable to recover codes within 30 seconds on this device due to noise in its graphics hardware. The team demonstrated successful data theft from popular apps including Google Authenticator, Signal, Venmo, Gmail, and Google Maps. Any information visible on screen becomes vulnerable, from private messages to location data.

Critical Threat to Crypto Wallets

For cryptocurrency holders, this vulnerability poses a major risk. Wallet seed phrases—the 12 or 24 words that grant complete access to your crypto—are especially vulnerable because users typically leave them displayed while writing them down for backup.

While stealing a full 12-word phrase takes longer than grabbing a 2FA code, the attack remains effective if the phrase stays visible. Once attackers have your seed phrase, they control your entire wallet. No additional passwords or security measures can stop them from draining your funds.

Hardware wallets remain the safest option because they never display seed phrases on internet-connected devices. The private keys stay isolated in the hardware device, signing transactions without exposing sensitive information to your phone or computer.

Current Patch Status

Google learned about Pixnapping in February 2025 and assigned it CVE-2025-48561, rating it high severity. The company released a partial fix in September 2025 by limiting how many times apps can use blur effects—a key component of the attack.

However, researchers found a workaround that bypasses Google’s first patch. Google confirmed it will release another update in the December 2025 security bulletin to address remaining vulnerabilities.

The good news: Google reports no evidence of real-world attacks using Pixnapping. Their Play Store security systems haven’t detected any malicious apps exploiting this vulnerability. But the attack remains possible on unpatched devices.

Samsung devices also received the September patch. Researchers notified Samsung that Google’s initial patch was insufficient to protect Samsung devices from the original attack. Both companies continue coordinating on additional protections.

Protecting Your Assets

No special mitigation exists yet for individual apps to defend against Pixnapping. The fixes must come from Google and Samsung at the system level. Meanwhile, several steps can reduce your risk:

Install security updates immediately when they arrive. The December patch should significantly improve protection for compatible devices.

Download apps only from Google Play Store, avoiding unknown APK files from websites or third parties. Review what permissions your apps request—though Pixnapping doesn’t need special permissions, limiting app access still improves overall security.

Never display crypto wallet seed phrases on any internet-connected device if possible. Write them down on paper immediately rather than leaving them on screen. Better yet, use a hardware wallet for storing significant cryptocurrency holdings.

Consider the broader security landscape. This year has seen major crypto theft, with billions lost to various attacks. Mobile security represents just one vulnerability among many.

The Bigger Picture

Pixnapping reveals fundamental weaknesses in how Android handles window layering and graphics rendering. The attack exploits data compression in Mali GPUs used by Pixel phones—compression creates timing variations that leak information about pixel values.

Other Android phone manufacturers likely face similar risks since the necessary mechanisms exist across the Android ecosystem. The research team hasn’t tested all brands yet, but the core APIs enabling the attack are standard Android features.

The underlying GPU.zip hardware vulnerability remains unpatched. No GPU manufacturers have committed to fixing the compression timing leak that makes Pixnapping possible.

Researchers will release their proof-of-concept code on GitHub once patches are widely available.

Bottom Line

Pixnapping demonstrates that even apps without suspicious permissions can pose serious threats. For crypto users, the message is clear: keep seed phrases off your phone. Use hardware wallets for serious holdings. Install updates promptly. And remember that convenience often conflicts with security—protecting your crypto requires taking extra steps that might feel inconvenient but could save you from total loss.

Market Opportunity
Ambire Wallet Logo
Ambire Wallet Price(WALLET)
$0.0139
$0.0139$0.0139
-10.20%
USD
Ambire Wallet (WALLET) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Japan-Based Bitcoin Treasury Company Metaplanet Completes $1.4 Billion IPO! Will It Buy Bitcoin? Here Are the Details

Japan-Based Bitcoin Treasury Company Metaplanet Completes $1.4 Billion IPO! Will It Buy Bitcoin? Here Are the Details

The post Japan-Based Bitcoin Treasury Company Metaplanet Completes $1.4 Billion IPO! Will It Buy Bitcoin? Here Are the Details appeared on BitcoinEthereumNews.com. Japan-based Bitcoin treasury company Metaplanet announced today that it has successfully completed its public offering process. Metaplanet Grows Bitcoin Treasury with $1.4 Billion IPO The company’s CEO, Simon Gerovich, stated in a post on the X platform that a large number of institutional investors participated in the process. Among the investors, mutual funds, sovereign wealth funds, and hedge funds were notable. According to Gerovich, approximately 100 institutional investors participated in roadshows held prior to the IPO. Ultimately, over 70 investors participated in Metaplanet’s capital raising. Previously disclosed information indicated that the company had raised approximately $1.4 billion through the IPO. This funding will accelerate Metaplanet’s growth plans and, in particular, allow the company to increase its balance sheet Bitcoin holdings. Gerovich emphasized that this step will propel Metaplanet to its next stage of development and strengthen the company’s global Bitcoin strategy. Metaplanet has recently become one of the leading companies in Japan in promoting digital asset adoption. The company has previously stated that it views Bitcoin as a long-term store of value. This large-scale IPO is considered a significant step in not only strengthening Metaplanet’s capital but also consolidating Japan’s role in the global crypto finance market. *This is not investment advice. Follow our Telegram and Twitter account now for exclusive news, analytics and on-chain data! Source: https://en.bitcoinsistemi.com/japan-based-bitcoin-treasury-company-metaplanet-completes-1-4-billion-ipo-will-it-buy-bitcoin-here-are-the-details/
Share
BitcoinEthereumNews2025/09/18 08:42
CME Group to Launch Solana and XRP Futures Options

CME Group to Launch Solana and XRP Futures Options

The post CME Group to Launch Solana and XRP Futures Options appeared on BitcoinEthereumNews.com. An announcement was made by CME Group, the largest derivatives exchanger worldwide, revealed that it would introduce options for Solana and XRP futures. It is the latest addition to CME crypto derivatives as institutions and retail investors increase their demand for Solana and XRP. CME Expands Crypto Offerings With Solana and XRP Options Launch According to a press release, the launch is scheduled for October 13, 2025, pending regulatory approval. The new products will allow traders to access options on Solana, Micro Solana, XRP, and Micro XRP futures. Expiries will be offered on business days on a monthly, and quarterly basis to provide more flexibility to market players. CME Group said the contracts are designed to meet demand from institutions, hedge funds, and active retail traders. According to Giovanni Vicioso, the launch reflects high liquidity in Solana and XRP futures. Vicioso is the Global Head of Cryptocurrency Products for the CME Group. He noted that the new contracts will provide additional tools for risk management and exposure strategies. Recently, CME XRP futures registered record open interest amid ETF approval optimism, reinforcing confidence in contract demand. Cumberland, one of the leading liquidity providers, welcomed the development and said it highlights the shift beyond Bitcoin and Ethereum. FalconX, another trading firm, added that rising digital asset treasuries are increasing the need for hedging tools on alternative tokens like Solana and XRP. High Record Trading Volumes Demand Solana and XRP Futures Solana futures and XRP continue to gain popularity since their launch earlier this year. According to CME official records, many have bought and sold more than 540,000 Solana futures contracts since March. A value that amounts to over $22 billion dollars. Solana contracts hit a record 9,000 contracts in August, worth $437 million. Open interest also set a record at 12,500 contracts.…
Share
BitcoinEthereumNews2025/09/18 01:39
Why the Testing Method Developers Prefer Is Rarely Ever the One That Finds the Most Bugs

Why the Testing Method Developers Prefer Is Rarely Ever the One That Finds the Most Bugs

A replicated controlled study confirms that developers’ perceptions, preferences, and opinions about software testing techniques do not reliably predict actual
Share
Hackernoon2025/12/18 05:00