TLDR Pixnapping steals on-screen data by reading pixel colors on Android devices. Attack recovered 2FA codes on Pixel 6 to 9 in up to 73% of tests. Google rated the issue high severity and is working on a full patch. Hardware wallets remain the safest way to store crypto recovery phrases. A new Android security [...] The post Pixnapping Android flaw lets hackers steal crypto wallet seed phrases appeared first on CoinCentral.TLDR Pixnapping steals on-screen data by reading pixel colors on Android devices. Attack recovered 2FA codes on Pixel 6 to 9 in up to 73% of tests. Google rated the issue high severity and is working on a full patch. Hardware wallets remain the safest way to store crypto recovery phrases. A new Android security [...] The post Pixnapping Android flaw lets hackers steal crypto wallet seed phrases appeared first on CoinCentral.

Pixnapping Android flaw lets hackers steal crypto wallet seed phrases

TLDR

  • Pixnapping steals on-screen data by reading pixel colors on Android devices.
  • Attack recovered 2FA codes on Pixel 6 to 9 in up to 73% of tests.
  • Google rated the issue high severity and is working on a full patch.
  • Hardware wallets remain the safest way to store crypto recovery phrases.

A new Android security flaw has raised concerns among users of crypto wallets and authentication apps. Researchers have identified an attack method called “Pixnapping,” which allows malicious applications to reconstruct sensitive on-screen data such as recovery phrases and two-factor authentication (2FA) codes. The discovery indicates that even trusted devices could be at risk of revealing private information through manipulated screen pixels.

How the Pixnapping Attack Works

The Pixnapping method uses Android’s application programming interfaces (APIs) to calculate the color of individual pixels displayed by other applications. Unlike conventional screen capture attacks, the malicious app does not directly access another app’s display. 

Instead, it layers semi-transparent activities over the target app, masking all but a chosen pixel. By manipulating that pixel repeatedly, attackers can infer its color and reconstruct visual content from the screen.

Researchers explained that this process involves timing frame renders and scanning one pixel at a time, which enables the malware to rebuild what was shown on screen. Although the attack is slow, it is still capable of capturing information that remains visible for more than a few seconds, such as recovery phrases or long authentication codes.

Risk to Crypto Wallet Recovery Phrases

The research team warned that Pixnapping poses a particular danger to crypto wallet users. Recovery phrases, which provide full access to digital wallets, often stay visible while users write them down. According to the study, the attack successfully retrieved full 6-digit 2FA codes in several tests on Google Pixel devices.

The success rate reached 73% on the Pixel 6, 53% on the Pixel 7, 29% on the Pixel 8, and 53% on the Pixel 9. The average time to recover each 2FA code ranged from 14 to 26 seconds, depending on the device model. While recovering a full 12-word seed phrase would take much longer, the researchers confirmed that it remains possible if the phrase stays displayed.

Google’s Response and Ongoing Coordination

The vulnerability was tested on several devices running Android 13 to 16, including the Google Pixel 6 through Pixel 9 and the Samsung Galaxy S25. Since the attack relies on widely available APIs, the team warned that other Android devices could also be affected.

Google responded by limiting how many activities an app can blur at once. However, the researchers found a workaround that allowed Pixnapping to continue functioning. As of October 13, the researchers said they were still coordinating with Google and Samsung regarding disclosure timelines and security patches.

Google classified the issue as high severity and awarded a bug bounty to the research team. The team also informed Samsung that Google’s initial fix did not fully protect Samsung devices.

Hardware Wallets as a Safer Option

Experts advise users to avoid displaying recovery phrases or sensitive data on Android devices until a complete fix is available. Keeping recovery information offline or using a hardware wallet offers stronger protection.

A hardware wallet is a dedicated device that stores private keys securely and signs transactions without exposing them to connected smartphones or computers. Security researcher Vladimir S emphasized this in a post on X, stating, “Simply don’t use your phone to secure your crypto. Use a hardware wallet!”

Until Android patches the vulnerability, users are urged to exercise caution and avoid keeping recovery or authentication data visible on their screens for extended periods.

The post Pixnapping Android flaw lets hackers steal crypto wallet seed phrases appeared first on CoinCentral.

Market Opportunity
Ambire Wallet Logo
Ambire Wallet Price(WALLET)
$0,01546
$0,01546$0,01546
+5,52%
USD
Ambire Wallet (WALLET) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

BlackRock boosts AI and US equity exposure in $185 billion models

BlackRock boosts AI and US equity exposure in $185 billion models

The post BlackRock boosts AI and US equity exposure in $185 billion models appeared on BitcoinEthereumNews.com. BlackRock is steering $185 billion worth of model portfolios deeper into US stocks and artificial intelligence. The decision came this week as the asset manager adjusted its entire model suite, increasing its equity allocation and dumping exposure to international developed markets. The firm now sits 2% overweight on stocks, after money moved between several of its biggest exchange-traded funds. This wasn’t a slow shuffle. Billions flowed across multiple ETFs on Tuesday as BlackRock executed the realignment. The iShares S&P 100 ETF (OEF) alone brought in $3.4 billion, the largest single-day haul in its history. The iShares Core S&P 500 ETF (IVV) collected $2.3 billion, while the iShares US Equity Factor Rotation Active ETF (DYNF) added nearly $2 billion. The rebalancing triggered swift inflows and outflows that realigned investor exposure on the back of performance data and macroeconomic outlooks. BlackRock raises equities on strong US earnings The model updates come as BlackRock backs the rally in American stocks, fueled by strong earnings and optimism around rate cuts. In an investment letter obtained by Bloomberg, the firm said US companies have delivered 11% earnings growth since the third quarter of 2024. Meanwhile, earnings across other developed markets barely touched 2%. That gap helped push the decision to drop international holdings in favor of American ones. Michael Gates, lead portfolio manager for BlackRock’s Target Allocation ETF model portfolio suite, said the US market is the only one showing consistency in sales growth, profit delivery, and revisions in analyst forecasts. “The US equity market continues to stand alone in terms of earnings delivery, sales growth and sustainable trends in analyst estimates and revisions,” Michael wrote. He added that non-US developed markets lagged far behind, especially when it came to sales. This week’s changes reflect that position. The move was made ahead of the Federal…
Share
BitcoinEthereumNews2025/09/18 01:44
SICAK GELİŞME: Binance, Üç Altcoini Vadeli İşlemlerde Listeliyor!

SICAK GELİŞME: Binance, Üç Altcoini Vadeli İşlemlerde Listeliyor!

Kripto para borsası Binance, ZKP, GUA ve IR tokenlerini vadeli işlemler platformunda listeleyeceğini açıkladı. *Yatırım tavsiyesi değildir. Kaynak: Bitcoinsistemi
Share
Coinstats2025/12/21 16:41
USDC Treasury mints 250 million new USDC on Solana

USDC Treasury mints 250 million new USDC on Solana

PANews reported on September 17 that according to Whale Alert , at 23:48 Beijing time, USDC Treasury minted 250 million new USDC (approximately US$250 million) on the Solana blockchain .
Share
PANews2025/09/17 23:51