Close Menu
Trader News
  • Markets
    • Stocks
    • Futures
    • Forex
    • Commodities
    • OTC
    • QB
    • QX
    • PINK
    • Crypto
    • Options
    • Bonds
  • Crypto
    • Market
    • BTC
    • NFTs
    • DeFi
  • Technology
    • Web3
    • FinTech
    • EdTech
    • AI
  • Startups
  • Real Estate
  • Personal Finance
    • Retirement
    • Investing
  • More
    • Market Data
    • Glossary
    • Crypto Heatmap
    • Newsletter
    • Submit News
    • Exchanges, Brokerage and Savings Platforms
X (Twitter)
X (Twitter) TikTok YouTube RSS
Trader News
  • Markets
    1. Stocks
    2. Futures
    3. Forex
    4. Commodities
    5. OTC
    6. QB
    7. QX
    8. PINK
    9. Crypto
    10. Options
    11. Bonds
    Featured

    Why Silver Doesn’t Have The Same Mojo As Gold – iShares Silver Trust (ARCA:SLV)

    By News RoomOct 14, 2025 12:47 pm EDT0
    Recent

    Why Silver Doesn’t Have The Same Mojo As Gold – iShares Silver Trust (ARCA:SLV)

    Oct 14, 2025 12:47 pm EDT

    4 Tech Stocks Showing Strong Momentum Signals This Week – Richardson Electronics (NASDAQ:RELL), Nvni Group (NASDAQ:NVNI)

    Oct 14, 2025 12:45 pm EDT

    Media Advisory: Housing Enabling Infrastructure Announcement in Tracadie

    Oct 14, 2025 12:43 pm EDT
  • Crypto
    1. Market
    2. BTC
    3. NFTs
    4. DeFi
    Featured

    Android Vulnerability Endangers Recovery Phrases, 2FA Codes

    By News RoomOct 14, 2025 1:00 pm EDT0
    Recent

    Android Vulnerability Endangers Recovery Phrases, 2FA Codes

    Oct 14, 2025 1:00 pm EDT

    Bitcoin Whale Adds Short Exposure as BTC Dips Under $110,000

    Oct 14, 2025 11:58 am EDT

    The Oracle Problem Isn’t Just Technical; It’s Political

    Oct 14, 2025 11:55 am EDT
  • Technology
    1. Web3
    2. FinTech
    3. EdTech
    4. AI
    Featured

    India difficult playground for Revolut but playbook promising: Expert

    By News RoomOct 14, 2025 8:11 am EDT0
    Recent

    India difficult playground for Revolut but playbook promising: Expert

    Oct 14, 2025 8:11 am EDT

    UK moves to allow tokenisation of investment funds

    Oct 14, 2025 7:29 am EDT

    OpenAI’s hyperscaler ambitions are being put to the test with its latest megadeals

    Oct 14, 2025 7:04 am EDT
  • Startups
  • Real Estate
  • Personal Finance
    1. Retirement
    2. Investing
    Featured

    Social Security COLA for 2026: Agency confirms when to expect announcement

    By News RoomOct 14, 2025 1:38 pm EDT0
    Recent

    Social Security COLA for 2026: Agency confirms when to expect announcement

    Oct 14, 2025 1:38 pm EDT

    JPMorgan loves this new e-commerce play with an AI focus, sees 30% gain from here

    Oct 14, 2025 12:31 pm EDT

    Home Depot has been in a steep downturn since mid-September. How to use options to bet on a bounce

    Oct 14, 2025 11:24 am EDT
  • More
    • Market Data
    • Glossary
    • Crypto Heatmap
    • Newsletter
    • Submit News
    • Exchanges, Brokerage and Savings Platforms
Login
Trader News
You are at:Home » Android Vulnerability Endangers Recovery Phrases, 2FA Codes
DeFi

Android Vulnerability Endangers Recovery Phrases, 2FA Codes

News RoomNews RoomOct 14, 2025 1:00 pm EDT0 ViewsNo Comments4 Mins Read
Facebook Twitter Telegram WhatsApp Pinterest LinkedIn Tumblr Email Reddit
Share
Facebook Twitter LinkedIn Pinterest Email

A freshly found Android vulnerability makes it possible for harmful applications to gain access to material shown by other apps, possibly jeopardizing crypto wallet healing expressions, two-factor authentication (2FA) codes and more.

According to a current term paper, the “Pixnapping” attack “bypasses all web browser mitigations and can even take tricks from non-browser apps.” This is possible by leveraging Android application shows user interfaces (API) to compute the material of a particular pixel shown by a various application.

This is not as easy as the harmful application asking for and accessing the screen material of another application. Rather, it layers a stack of attacker-controlled, semi-transparent activities to mask all however a selected pixel, then controls that pixel so its color controls the frame.

By duplicating this procedure and timing frame renders, the malware presumes those pixels to rebuild on-screen tricks. This, thankfully, takes some time and restricts the attack’s effectiveness versus material that is not shown for more than a couple of seconds.

Pixnapping graph. Source: Pixnapping term paper

Seed expressions in threat

One sort of especially delicate info that tends to remain on screen for a lot longer than a couple of seconds is crypto wallet healing expressions. Those expressions, which enable complete, unattended access to the linked crypto wallets, need users to compose them down for safekeeping. The paper evaluated the attack on 2FA codes on Google Pixel gadgets:

” Our attack properly recuperates the complete 6-digit 2FA code in 73%, 53%, 29%, and 53% of the trials on the Pixel 6, 7, 8, and 9, respectively. The typical time to recuperate each 2FA code is 14.3, 25.8, 24.9, and 25.3 seconds for the Pixel 6, Pixel 7, Pixel 8, and Pixel 9, respectively.”

While a complete 12-word healing expression would take a lot longer to record, the attack stays practical if the user leaves the expression noticeable while composing it down.

Related: UK restores Apple iCloud backdoor push, threatening crypto wallet security

Google’s action

The vulnerability was evaluated on 5 gadgets running Android variations 13 to 16: the Google Pixel 6, Google Pixel 7, Google Pixel 8, Google Pixel 9 and the Samsung Galaxy S25. The scientists stated the very same attack might deal with other Android gadgets because the made use of APIs are extensively readily available.

Google at first tried to spot the defect by restricting the number of activities an app can blur at the same time. Nevertheless, the scientists stated they discovered a workaround that still makes it possible for Pixnapping to operate.

” Since October 13, we are still collaborating with Google and Samsung concerning disclosure timelines and mitigations.”

According to the paper, Google ranked the problem as high seriousness and dedicated to granting the scientists a bug bounty. The group likewise connected to Samsung to alert that “Google’s spot was inadequate to safeguard Samsung gadgets.”

Related: Finest crypto hardware wallets for 2025

Hardware wallets use safe security

The most apparent option to the problem is to prevent showing healing expressions or any other especially delicate material on Android gadgets. Even much better would be to prevent showing healing info on any internet-capable gadget.

An easy option to attain simply that is to utilize a hardware wallet. A hardware wallet is a devoted crucial management gadget that signs deals externally to a computer system or mobile phone without ever exposing the personal secret or healing expression. As danger scientist Vladimir S put it in an X post on the topic:

” Just do not utilize your phone to protect your crypto. Utilize a hardware wallet!”

Publication: ‘ Assist! My robotic vac is taking my Bitcoin’: When wise gadgets attack

Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Articles

The Oracle Problem Isn’t Just Technical; It’s Political

DeFi Oct 14, 2025 11:55 am EDT

How CZ’s Memecoin Mention Sparked a 650x Flip

DeFi Oct 14, 2025 10:48 am EDT

From $10 to $10,000: Dollar-Cost Averaging in Crypto

DeFi Oct 14, 2025 9:41 am EDT

Scammers Exploit Telegram Ads To Mimic Monad Claim Portal

DeFi Oct 14, 2025 7:32 am EDT

$19B Crypto Market Crash: ‘Controlled Deleveraging’ Not ‘Cascade’

DeFi Oct 14, 2025 6:20 am EDT

BNB Hits Record High As Traders Blame Binance For Crypto Market Crash

DeFi Oct 13, 2025 12:01 pm EDT
Add A Comment
Leave A Reply Cancel Reply

You must be logged in to post a comment.

Latest News

Android Vulnerability Endangers Recovery Phrases, 2FA Codes

Oct 14, 2025 1:00 pm EDT

Why Silver Doesn’t Have The Same Mojo As Gold – iShares Silver Trust (ARCA:SLV)

Oct 14, 2025 12:47 pm EDT

4 Tech Stocks Showing Strong Momentum Signals This Week – Richardson Electronics (NASDAQ:RELL), Nvni Group (NASDAQ:NVNI)

Oct 14, 2025 12:45 pm EDT

Media Advisory: Housing Enabling Infrastructure Announcement in Tracadie

Oct 14, 2025 12:43 pm EDT

EchoStar Options Trading: A Deep Dive into Market Sentiment – EchoStar (NASDAQ:SATS)

Oct 14, 2025 12:41 pm EDT

Subscribe to Updates

Get the latest markets news and updates directly to your inbox.

[newsletter_form]

Top News

Investing

JPMorgan loves this new e-commerce play with an AI focus, sees 30% gain from here

By News RoomOct 14, 2025 12:31 pm EDT0

JPMorgan sees a brilliant future ahead for the current Amazon-affiliated e-commerce stock to go public.…

Bitcoin Whale Adds Short Exposure as BTC Dips Under $110,000

Oct 14, 2025 11:58 am EDT

The Oracle Problem Isn’t Just Technical; It’s Political

Oct 14, 2025 11:55 am EDT

Trump Vs. China: Wall Street Scores Win Vs. Beijing’s Tech Titans – Invesco QQQ Trust, Series 1 (NASDAQ:QQQ)

Oct 14, 2025 11:42 am EDT
About
About

Trader News is the only source for the latest news and updates about the market, finance, crypto and real estate. Follow us to get the only news that matters.
We're social, connect with us:

X (Twitter) YouTube TikTok
Popular News

Where Is S&P 500 Headed In 2024?

Dec 3, 2023 6:16 pm EST

Goldman Sachs says this AI-powered software stock that’s up 50% since IPO is poised for more gains

Dec 11, 2024 8:35 am EST

Bitcoin Minted 70,000 New Millionaires — Here’s Where They’re Investing Their Profits

Oct 9, 2025 8:58 am EDT

Subscribe to Updates

Get the latest markets news and updates directly to your inbox.

[newsletter_form]
Copyright © 2025. TraderNews. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Press Release
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?