TLDR Pixnapping steals on-screen data by reading pixel colors on Android devices. Attack recovered 2FA codes on Pixel 6 to 9 in up to 73% of tests. Google rated the issue high severity and is working on a full patch. Hardware wallets remain the safest way to store crypto recovery phrases. A new Android security [...] The post Pixnapping Android flaw lets hackers steal crypto wallet seed phrases appeared first on CoinCentral.TLDR Pixnapping steals on-screen data by reading pixel colors on Android devices. Attack recovered 2FA codes on Pixel 6 to 9 in up to 73% of tests. Google rated the issue high severity and is working on a full patch. Hardware wallets remain the safest way to store crypto recovery phrases. A new Android security [...] The post Pixnapping Android flaw lets hackers steal crypto wallet seed phrases appeared first on CoinCentral.

Pixnapping Android flaw lets hackers steal crypto wallet seed phrases

TLDR

  • Pixnapping steals on-screen data by reading pixel colors on Android devices.
  • Attack recovered 2FA codes on Pixel 6 to 9 in up to 73% of tests.
  • Google rated the issue high severity and is working on a full patch.
  • Hardware wallets remain the safest way to store crypto recovery phrases.

A new Android security flaw has raised concerns among users of crypto wallets and authentication apps. Researchers have identified an attack method called “Pixnapping,” which allows malicious applications to reconstruct sensitive on-screen data such as recovery phrases and two-factor authentication (2FA) codes. The discovery indicates that even trusted devices could be at risk of revealing private information through manipulated screen pixels.

How the Pixnapping Attack Works

The Pixnapping method uses Android’s application programming interfaces (APIs) to calculate the color of individual pixels displayed by other applications. Unlike conventional screen capture attacks, the malicious app does not directly access another app’s display. 

Instead, it layers semi-transparent activities over the target app, masking all but a chosen pixel. By manipulating that pixel repeatedly, attackers can infer its color and reconstruct visual content from the screen.

Researchers explained that this process involves timing frame renders and scanning one pixel at a time, which enables the malware to rebuild what was shown on screen. Although the attack is slow, it is still capable of capturing information that remains visible for more than a few seconds, such as recovery phrases or long authentication codes.

Risk to Crypto Wallet Recovery Phrases

The research team warned that Pixnapping poses a particular danger to crypto wallet users. Recovery phrases, which provide full access to digital wallets, often stay visible while users write them down. According to the study, the attack successfully retrieved full 6-digit 2FA codes in several tests on Google Pixel devices.

The success rate reached 73% on the Pixel 6, 53% on the Pixel 7, 29% on the Pixel 8, and 53% on the Pixel 9. The average time to recover each 2FA code ranged from 14 to 26 seconds, depending on the device model. While recovering a full 12-word seed phrase would take much longer, the researchers confirmed that it remains possible if the phrase stays displayed.

Google’s Response and Ongoing Coordination

The vulnerability was tested on several devices running Android 13 to 16, including the Google Pixel 6 through Pixel 9 and the Samsung Galaxy S25. Since the attack relies on widely available APIs, the team warned that other Android devices could also be affected.

Google responded by limiting how many activities an app can blur at once. However, the researchers found a workaround that allowed Pixnapping to continue functioning. As of October 13, the researchers said they were still coordinating with Google and Samsung regarding disclosure timelines and security patches.

Google classified the issue as high severity and awarded a bug bounty to the research team. The team also informed Samsung that Google’s initial fix did not fully protect Samsung devices.

Hardware Wallets as a Safer Option

Experts advise users to avoid displaying recovery phrases or sensitive data on Android devices until a complete fix is available. Keeping recovery information offline or using a hardware wallet offers stronger protection.

A hardware wallet is a dedicated device that stores private keys securely and signs transactions without exposing them to connected smartphones or computers. Security researcher Vladimir S emphasized this in a post on X, stating, “Simply don’t use your phone to secure your crypto. Use a hardware wallet!”

Until Android patches the vulnerability, users are urged to exercise caution and avoid keeping recovery or authentication data visible on their screens for extended periods.

The post Pixnapping Android flaw lets hackers steal crypto wallet seed phrases appeared first on CoinCentral.

Market Opportunity
Ambire Wallet Logo
Ambire Wallet Price(WALLET)
$0.01632
$0.01632$0.01632
+5.49%
USD
Ambire Wallet (WALLET) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Japan’s Rate Hike Puts Bitcoin on Edge

Japan’s Rate Hike Puts Bitcoin on Edge

Japan's rate hike ends ultra-loose policies, impacting Bitcoin prices and global markets.
Share
CoinLive2025/12/22 07:43
How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings

How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings

The post How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings appeared on BitcoinEthereumNews.com. contributor Posted: September 17, 2025 As digital assets continue to reshape global finance, cloud mining has become one of the most effective ways for investors to generate stable passive income. Addressing the growing demand for simplicity, security, and profitability, IeByte has officially upgraded its fully automated cloud mining platform, empowering both beginners and experienced investors to earn Bitcoin, Dogecoin, and other mainstream cryptocurrencies without the need for hardware or technical expertise. Why cloud mining in 2025? Traditional crypto mining requires expensive hardware, high electricity costs, and constant maintenance. In 2025, with blockchain networks becoming more competitive, these barriers have grown even higher. Cloud mining solves this by allowing users to lease professional mining power remotely, eliminating the upfront costs and complexity. IeByte stands at the forefront of this transformation, offering investors a transparent and seamless path to daily earnings. IeByte’s upgraded auto-cloud mining platform With its latest upgrade, IeByte introduces: Full Automation: Mining contracts can be activated in just one click, with all processes handled by IeByte’s servers. Enhanced Security: Bank-grade encryption, cold wallets, and real-time monitoring protect every transaction. Scalable Options: From starter packages to high-level investment contracts, investors can choose the plan that matches their goals. Global Reach: Already trusted by users in over 100 countries. Mining contracts for 2025 IeByte offers a wide range of contracts tailored for every investor level. From entry-level plans with daily returns to premium high-yield packages, the platform ensures maximum accessibility. Contract Type Duration Price Daily Reward Total Earnings (Principal + Profit) Starter Contract 1 Day $200 $6 $200 + $6 + $10 bonus Bronze Basic Contract 2 Days $500 $13.5 $500 + $27 Bronze Basic Contract 3 Days $1,200 $36 $1,200 + $108 Silver Advanced Contract 1 Day $5,000 $175 $5,000 + $175 Silver Advanced Contract 2 Days $8,000 $320 $8,000 + $640 Silver…
Share
BitcoinEthereumNews2025/09/17 23:48
Stablecoins Get A Break? US Lawmakers Propose Tax Relief

Stablecoins Get A Break? US Lawmakers Propose Tax Relief

Lawmakers in the US have put forward a discussion draft that would ease tax reporting for small stablecoin payments and let some crypto earners delay taxes on staking
Share
Bitcoinist2025/12/22 07:00