Close Menu
Trader News
  • Markets
    • Stocks
    • Futures
    • Forex
    • Commodities
    • OTC
    • QB
    • QX
    • PINK
    • Crypto
    • Options
    • Bonds
  • Crypto
    • Market
    • BTC
    • NFTs
    • DeFi
  • Technology
    • Web3
    • FinTech
    • EdTech
    • AI
  • Startups
  • Real Estate
  • Personal Finance
    • Retirement
    • Investing
  • More
    • Market Data
    • Glossary
    • Crypto Heatmap
    • Newsletter
    • Submit News
    • Exchanges, Brokerage and Savings Platforms
X (Twitter)
X (Twitter) TikTok YouTube RSS
Trader News
  • Markets
    1. Stocks
    2. Futures
    3. Forex
    4. Commodities
    5. OTC
    6. QB
    7. QX
    8. PINK
    9. Crypto
    10. Options
    11. Bonds
    Featured

    TikTok Approves Thumzup App for Official API Access, Unlocking New Potential in Social Media Advertising – Thumzup Media (NASDAQ:TZUP)

    By News RoomOct 14, 2025 8:27 pm EDT0
    Recent

    TikTok Approves Thumzup App for Official API Access, Unlocking New Potential in Social Media Advertising – Thumzup Media (NASDAQ:TZUP)

    Oct 14, 2025 8:27 pm EDT

    $100 Invested In L3Harris Technologies 10 Years Ago Would Be Worth This Much Today – L3Harris Technologies (NYSE:LHX)

    Oct 14, 2025 8:26 pm EDT

    Did JPMorgan ‘Fix’ Silver Prices? The Truth Behind The Conspiracy – iShares Silver Trust (ARCA:SLV)

    Oct 14, 2025 8:24 pm EDT
  • Crypto
    1. Market
    2. BTC
    3. NFTs
    4. DeFi
    Featured

    Exclusively obtained orderbook data reveals details about USDE crash

    By News RoomOct 14, 2025 7:35 pm EDT0
    Recent

    Exclusively obtained orderbook data reveals details about USDE crash

    Oct 14, 2025 7:35 pm EDT

    TradFi, Whales Buy Sub-$200 SOL Ahead Of ETF Decision

    Oct 14, 2025 5:22 pm EDT

    SOL Funding Negative Yet Price Has No Traction

    Oct 14, 2025 4:16 pm EDT
  • Technology
    1. Web3
    2. FinTech
    3. EdTech
    4. AI
    Featured

    Naughty or Nice? ChatGPT to Allow Erotica in December, Says Sam Altman

    By News RoomOct 14, 2025 6:12 pm EDT0
    Recent

    Naughty or Nice? ChatGPT to Allow Erotica in December, Says Sam Altman

    Oct 14, 2025 6:12 pm EDT

    Taiwan Semiconductor Manufacturing Q3 Preview: With Stock Near 52-Week Highs, Here’s What To Watch – Taiwan Semiconductor (NYSE:TSM)

    Oct 14, 2025 6:08 pm EDT

    Walmart teams with OpenAI to let shoppers buy products through ChatGPT

    Oct 14, 2025 3:49 pm EDT
  • Startups
  • Real Estate
  • Personal Finance
    1. Retirement
    2. Investing
    Featured

    Wall Street can’t seem to shake off volatility. How to generate some safe returns into year-end

    By News RoomOct 14, 2025 7:00 pm EDT0
    Recent

    Wall Street can’t seem to shake off volatility. How to generate some safe returns into year-end

    Oct 14, 2025 7:00 pm EDT

    Berkshire’s Japanese stock positions top $30 billion

    Oct 14, 2025 4:46 pm EDT

    How much you can make in 2026 and still pay 0% capital gains

    Oct 14, 2025 3:45 pm EDT
  • More
    • Market Data
    • Glossary
    • Crypto Heatmap
    • Newsletter
    • Submit News
    • Exchanges, Brokerage and Savings Platforms
Login
Trader News
You are at:Home » Android Vulnerability Endangers Recovery Phrases, 2FA Codes
DeFi

Android Vulnerability Endangers Recovery Phrases, 2FA Codes

News RoomNews RoomOct 14, 2025 1:00 pm EDT1 ViewsNo Comments4 Mins Read
Facebook Twitter Telegram WhatsApp Pinterest LinkedIn Tumblr Email Reddit
Share
Facebook Twitter LinkedIn Pinterest Email

A freshly found Android vulnerability makes it possible for harmful applications to gain access to material shown by other apps, possibly jeopardizing crypto wallet healing expressions, two-factor authentication (2FA) codes and more.

According to a current term paper, the “Pixnapping” attack “bypasses all web browser mitigations and can even take tricks from non-browser apps.” This is possible by leveraging Android application shows user interfaces (API) to compute the material of a particular pixel shown by a various application.

This is not as easy as the harmful application asking for and accessing the screen material of another application. Rather, it layers a stack of attacker-controlled, semi-transparent activities to mask all however a selected pixel, then controls that pixel so its color controls the frame.

By duplicating this procedure and timing frame renders, the malware presumes those pixels to rebuild on-screen tricks. This, thankfully, takes some time and restricts the attack’s effectiveness versus material that is not shown for more than a couple of seconds.

Pixnapping graph. Source: Pixnapping term paper

Seed expressions in threat

One sort of especially delicate info that tends to remain on screen for a lot longer than a couple of seconds is crypto wallet healing expressions. Those expressions, which enable complete, unattended access to the linked crypto wallets, need users to compose them down for safekeeping. The paper evaluated the attack on 2FA codes on Google Pixel gadgets:

” Our attack properly recuperates the complete 6-digit 2FA code in 73%, 53%, 29%, and 53% of the trials on the Pixel 6, 7, 8, and 9, respectively. The typical time to recuperate each 2FA code is 14.3, 25.8, 24.9, and 25.3 seconds for the Pixel 6, Pixel 7, Pixel 8, and Pixel 9, respectively.”

While a complete 12-word healing expression would take a lot longer to record, the attack stays practical if the user leaves the expression noticeable while composing it down.

Related: UK restores Apple iCloud backdoor push, threatening crypto wallet security

Google’s action

The vulnerability was evaluated on 5 gadgets running Android variations 13 to 16: the Google Pixel 6, Google Pixel 7, Google Pixel 8, Google Pixel 9 and the Samsung Galaxy S25. The scientists stated the very same attack might deal with other Android gadgets because the made use of APIs are extensively readily available.

Google at first tried to spot the defect by restricting the number of activities an app can blur at the same time. Nevertheless, the scientists stated they discovered a workaround that still makes it possible for Pixnapping to operate.

” Since October 13, we are still collaborating with Google and Samsung concerning disclosure timelines and mitigations.”

According to the paper, Google ranked the problem as high seriousness and dedicated to granting the scientists a bug bounty. The group likewise connected to Samsung to alert that “Google’s spot was inadequate to safeguard Samsung gadgets.”

Related: Finest crypto hardware wallets for 2025

Hardware wallets use safe security

The most apparent option to the problem is to prevent showing healing expressions or any other especially delicate material on Android gadgets. Even much better would be to prevent showing healing info on any internet-capable gadget.

An easy option to attain simply that is to utilize a hardware wallet. A hardware wallet is a devoted crucial management gadget that signs deals externally to a computer system or mobile phone without ever exposing the personal secret or healing expression. As danger scientist Vladimir S put it in an X post on the topic:

” Just do not utilize your phone to protect your crypto. Utilize a hardware wallet!”

Publication: ‘ Assist! My robotic vac is taking my Bitcoin’: When wise gadgets attack

Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Articles

Exclusively obtained orderbook data reveals details about USDE crash

DeFi Oct 14, 2025 7:35 pm EDT

The Oracle Problem Isn’t Just Technical; It’s Political

DeFi Oct 14, 2025 11:55 am EDT

How CZ’s Memecoin Mention Sparked a 650x Flip

DeFi Oct 14, 2025 10:48 am EDT

From $10 to $10,000: Dollar-Cost Averaging in Crypto

DeFi Oct 14, 2025 9:41 am EDT

Scammers Exploit Telegram Ads To Mimic Monad Claim Portal

DeFi Oct 14, 2025 7:32 am EDT

$19B Crypto Market Crash: ‘Controlled Deleveraging’ Not ‘Cascade’

DeFi Oct 14, 2025 6:20 am EDT
Add A Comment
Leave A Reply Cancel Reply

You must be logged in to post a comment.

Latest News

$100 Invested In L3Harris Technologies 10 Years Ago Would Be Worth This Much Today – L3Harris Technologies (NYSE:LHX)

Oct 14, 2025 8:26 pm EDT

Did JPMorgan ‘Fix’ Silver Prices? The Truth Behind The Conspiracy – iShares Silver Trust (ARCA:SLV)

Oct 14, 2025 8:24 pm EDT

Exclusively obtained orderbook data reveals details about USDE crash

Oct 14, 2025 7:35 pm EDT

P/E Ratio Insights for Bank Bradesco – Bank Bradesco (NYSE:BBD)

Oct 14, 2025 7:19 pm EDT

If You Invested $1000 In Lumentum Holdings Stock 10 Years Ago, You Would Have This Much Today – Lumentum Holdings (NASDAQ:LITE)

Oct 14, 2025 7:18 pm EDT

Subscribe to Updates

Get the latest markets news and updates directly to your inbox.

[newsletter_form]

Top News

Commodities

CMS Energy to Announce 2025 Third Quarter Results on October 30 – CMS Energy (NYSE:CMS)

By News RoomOct 14, 2025 7:15 pm EDT0

JACKSON, Mich., Oct. 14, 2025/ PRNewswire/– CMS Energy revealed today it will supply 2025 3rd…

A Closer Look at Grab Holdings’s Options Market Dynamics – Grab Holdings (NASDAQ:GRAB)

Oct 14, 2025 7:14 pm EDT

Wall Street can’t seem to shake off volatility. How to generate some safe returns into year-end

Oct 14, 2025 7:00 pm EDT

Naughty or Nice? ChatGPT to Allow Erotica in December, Says Sam Altman

Oct 14, 2025 6:12 pm EDT
About
About

Trader News is the only source for the latest news and updates about the market, finance, crypto and real estate. Follow us to get the only news that matters.
We're social, connect with us:

X (Twitter) YouTube TikTok
Popular News

Where Is S&P 500 Headed In 2024?

Dec 3, 2023 6:16 pm EST

Ethereum Foundation Launches New Cluster Focused on Privacy

Oct 9, 2025 11:13 am EDT

Here’s How Much You Would Have Made Owning Dell Technologies Stock In The Last 5 Years – Dell Technologies (NYSE:DELL)

Sep 16, 2025 11:49 pm EDT

Subscribe to Updates

Get the latest markets news and updates directly to your inbox.

[newsletter_form]
Copyright © 2025. TraderNews. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Press Release
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?