• bitcoinBitcoin (BTC) $ 112,870.00
  • ethereumEthereum (ETH) $ 4,105.46
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 1,216.18
  • xrpXRP (XRP) $ 2.49
  • solanaSolana (SOL) $ 199.83
  • usd-coinUSDC (USDC) $ 0.999905
  • staked-etherLido Staked Ether (STETH) $ 4,107.41
  • dogecoinDogecoin (DOGE) $ 0.203615
  • tronTRON (TRX) $ 0.316043
  • cardanoCardano (ADA) $ 0.694704
  • wrapped-stethWrapped stETH (WSTETH) $ 4,994.36
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,423.01
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 112,787.00
  • chainlinkChainlink (LINK) $ 18.96
  • figure-helocFigure Heloc (FIGR_HELOC) $ 0.991161
  • ethena-usdeEthena USDe (USDE) $ 0.999757
  • wrapped-eethWrapped eETH (WEETH) $ 4,434.34
  • stellarStellar (XLM) $ 0.334553
  • bitcoin-cashBitcoin Cash (BCH) $ 535.17
  • hyperliquidHyperliquid (HYPE) $ 39.30
  • suiSui (SUI) $ 2.81
  • avalanche-2Avalanche (AVAX) $ 22.69
  • wethWETH (WETH) $ 4,108.27
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999935
  • leo-tokenLEO Token (LEO) $ 9.63
  • usdsUSDS (USDS) $ 0.999815
  • hedera-hashgraphHedera (HBAR) $ 0.186121
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 112,845.00
  • litecoinLitecoin (LTC) $ 97.70
  • usdt0USDT0 (USDT0) $ 1.00
  • mantleMantle (MNT) $ 2.00
  • shiba-inuShiba Inu (SHIB) $ 0.000011
  • whitebitWhiteBIT Coin (WBT) $ 42.90
  • the-open-networkToncoin (TON) $ 2.29
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • crypto-com-chainCronos (CRO) $ 0.163047
  • moneroMonero (XMR) $ 308.22
  • polkadotPolkadot (DOT) $ 3.24
  • daiDai (DAI) $ 0.997853
  • bittensorBittensor (TAO) $ 454.06
  • uniswapUniswap (UNI) $ 6.76
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.144259
  • zcashZcash (ZEC) $ 239.50
  • aaveAave (AAVE) $ 252.67
  • okbOKB (OKB) $ 179.99
  • memecoreMemeCore (M) $ 2.03
  • bitget-tokenBitget Token (BGB) $ 4.85
  • pepePepe (PEPE) $ 0.000007
  • ethenaEthena (ENA) $ 0.434852
  • nearNEAR Protocol (NEAR) $ 2.45
  • aster-2Aster (ASTER) $ 1.47
  • jito-staked-solJito Staked SOL (JITOSOL) $ 247.40
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • usd1-wlfiUSD1 (USD1) $ 0.999755
  • susdssUSDS (SUSDS) $ 1.07
  • aptosAptos (APT) $ 3.67
  • ethereum-classicEthereum Classic (ETC) $ 16.88
  • paypal-usdPayPal USD (PYUSD) $ 0.999823
  • c1usdCurrency One USD (C1USD) $ 1.00
  • ondo-financeOndo (ONDO) $ 0.792163
  • binance-peg-wethBinance-Peg WETH (WETH) $ 4,108.44
  • falcon-financeFalcon USD (USDF) $ 0.996195
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 5.58
  • story-2Story (IP) $ 6.60
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.200810
  • worldcoin-wldWorldcoin (WLD) $ 0.953096
  • binance-staked-solBinance Staked SOL (BNSOL) $ 214.76
  • gatechain-tokenGate (GT) $ 16.13
  • internet-computerInternet Computer (ICP) $ 3.54
  • htx-daoHTX DAO (HTX) $ 0.000002
  • kucoin-sharesKuCoin (KCS) $ 14.31
  • arbitrumArbitrum (ARB) $ 0.341561
  • rocket-pool-ethRocket Pool ETH (RETH) $ 4,707.20
  • usdtbUSDtb (USDTB) $ 0.999411
  • algorandAlgorand (ALGO) $ 0.204386
  • chainopera-aiChainOpera AI (COAI) $ 9.14
  • pi-networkPi Network (PI) $ 0.215165
  • hash-2Provenance Blockchain (HASH) $ 0.035461
  • bfusdBFUSD (BFUSD) $ 1.00
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 4,335.84
  • vechainVeChain (VET) $ 0.019115
  • cosmosCosmos Hub (ATOM) $ 3.47
  • wbnbWrapped BNB (WBNB) $ 1,216.51
  • kaspaKaspa (KAS) $ 0.060432
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 4,333.51
  • tether-goldTether Gold (XAUT) $ 4,142.87
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.024527
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 39.29
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 4,451.42
  • render-tokenRender (RENDER) $ 2.83
  • skySky (SKY) $ 0.062342
  • flare-networksFlare (FLR) $ 0.019137
  • pump-funPump.fun (PUMP) $ 0.004092
  • sei-networkSei (SEI) $ 0.224868
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 112,908.00
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 4,356.42
  • quant-networkQuant (QNT) $ 89.48
  • pax-goldPAX Gold (PAXG) $ 4,155.03
  • official-trumpOfficial Trump (TRUMP) $ 6.29
  • bonkBonk (BONK) $ 0.000016
  • nexoNEXO (NEXO) $ 1.22
  • pancakeswap-tokenPancakeSwap (CAKE) $ 3.49
  • jupiter-exchange-solanaJupiter (JUP) $ 0.373746
  • filecoinFilecoin (FIL) $ 1.67
  • syrupusdcSyrup USDC (SYRUPUSDC) $ 1.13
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999721
  • spx6900SPX6900 (SPX) $ 1.21
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 112,908.00
  • immutable-xImmutable (IMX) $ 0.573327
  • xdce-crowd-saleXDC Network (XDC) $ 0.060269
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998882
  • mantle-staked-etherMantle Staked Ether (METH) $ 4,428.01
  • morphoMorpho (MORPHO) $ 1.93
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 228.96
  • doublezeroDoubleZero (2Z) $ 0.283793
  • celestiaCelestia (TIA) $ 1.15
  • injective-protocolInjective (INJ) $ 9.52
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 112,921.00
  • clbtcclBTC (CLBTC) $ 116,256.00
  • solmevSolMev (SN116) $ 2,398.72
  • fasttokenFasttoken (FTN) $ 2.02
  • lido-daoLido DAO (LDO) $ 0.959603
  • optimismOptimism (OP) $ 0.481287
  • blockstackStacks (STX) $ 0.467891
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • msolMarinade Staked SOL (MSOL) $ 266.06
  • curve-dao-tokenCurve DAO (CRV) $ 0.586070
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.313606
  • plasmaPlasma (XPL) $ 0.450529
  • aerodrome-financeAerodrome Finance (AERO) $ 0.884523
  • ousgOUSG (OUSG) $ 112.93
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 3,926.87
  • sonic-3Sonic (S) $ 0.199391
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 4,122.71
  • the-graphThe Graph (GRT) $ 0.069720
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.85
  • global-dollarGlobal Dollar (USDG) $ 0.999940
  • flokiFLOKI (FLOKI) $ 0.000074
  • pyth-networkPyth Network (PYTH) $ 0.123503
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.10
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.998350
  • havvenSynthetix (SNX) $ 1.97
  • saros-financeSaros (SAROS) $ 0.257887
  • tezosTezos (XTZ) $ 0.623052
  • tbtctBTC (TBTC) $ 112,394.00
  • kaiaKaia (KAIA) $ 0.112447
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 4,104.17
  • ether-fiEther.fi (ETHFI) $ 1.23
  • gtethGTETH (GTETH) $ 4,119.12
  • stader-ethxStader ETHx (ETHX) $ 4,400.78
  • aethirAethir (ATH) $ 0.043895
  • newton-projectAB (AB) $ 0.007598
  • pendlePendle (PENDLE) $ 3.63
  • iotaIOTA (IOTA) $ 0.150580
  • conflux-tokenConflux (CFX) $ 0.116701
  • usdaiUSDai (USDAI) $ 1.03
  • myx-financeMYX Finance (MYX) $ 3.11
  • beldexBeldex (BDX) $ 0.079079
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.41
  • dogwifcoindogwifhat (WIF) $ 0.578703
  • theta-tokenTheta Network (THETA) $ 0.572580
  • dashDash (DASH) $ 44.94
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 4,533.01
  • ethereum-name-serviceEthereum Name Service (ENS) $ 16.90
  • galaGALA (GALA) $ 0.012003
  • the-sandboxThe Sandbox (SAND) $ 0.225627
  • usual-usdUsual USD (USD0) $ 0.997541
  • swethSwell Ethereum (SWETH) $ 4,506.46
  • starknetStarknet (STRK) $ 0.126639
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.822130
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 4,423.56
  • raydiumRaydium (RAY) $ 2.00
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 112,936.00
  • jasmycoinJasmyCoin (JASMY) $ 0.010809
  • rna-2RNA (SN117) $ 4,708.96
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.203608
  • decentralandDecentraland (MANA) $ 0.270640
  • bittorrentBitTorrent (BTT) $ 0.00000052
  • eigenlayerEigenCloud (prev. EigenLayer) (EIGEN) $ 1.33
  • swissborgSwissBorg (BORG) $ 0.523675
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 0.999019
  • vaultaVaulta (A) $ 0.313796
  • astherus-staked-bnbAster Staked BNB (ASBNB) $ 1,284.60
  • true-usdTrueUSD (TUSD) $ 0.999503
  • arbitrum-bridged-wrapped-eethArbitrum Bridged Wrapped eETH (Arbitrum) (WEETH) $ 4,425.23
  • syrupMaple Finance (SYRUP) $ 0.436539
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.10
  • usddUSDD (USDD) $ 1.00
  • flowFlow (FLOW) $ 0.296013
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999902
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999882
  • zero-gravity0G (0G) $ 2.19
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 4,100.53
  • sun-tokenSun Token (SUN) $ 0.024127
  • ai-companionsAI Companions (AIC) $ 0.460212
  • bitcoin-svBitcoin SV (BSV) $ 22.63
  • jito-governance-tokenJito (JTO) $ 1.16
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 4,115.11
  • frax-etherFrax Ether (FRXETH) $ 4,068.14

‘Pixnapping’ Android attack could expose crypto wallet seed phrases

0 3

‘Pixnapping’ Android attack could expose crypto wallet seed phrases

A newly discovered Android vulnerability enables malicious applications to access content displayed by other apps, potentially compromising crypto wallet recovery phrases, two-factor authentication (2FA) codes and more.

According to a recent research paper, the “Pixnapping” attack “bypasses all browser mitigations and can even steal secrets from non-browser apps.” This is possible by leveraging Android application programming interfaces (API) to calculate the content of a specific pixel displayed by a different application.

This is not as simple as the malicious application requesting and accessing the display content of another application. Instead, it layers a stack of attacker-controlled, semi-transparent activities to mask all but a chosen pixel, then manipulates that pixel so its color dominates the frame.

By repeating this process and timing frame renders, the malware infers those pixels to reconstruct on-screen secrets. This, fortunately, takes time and limits the attack’s usefulness against content that is not displayed for more than a few seconds.

‘Pixnapping’ Android attack could expose crypto wallet seed phrases

Pixnapping visual representation. Source: Pixnapping research paper

Seed phrases in danger

One kind of particularly sensitive information that tends to stay on screen for much longer than a few seconds is crypto wallet recovery phrases. Those phrases, which allow full, unchecked access to the connected crypto wallets, require users to write them down for safekeeping. The paper tested the attack on 2FA codes on Google Pixel devices:

“Our attack correctly recovers the full 6-digit 2FA code in 73%, 53%, 29%, and 53% of the trials on the Pixel 6, 7, 8, and 9, respectively. The average time to recover each 2FA code is 14.3, 25.8, 24.9, and 25.3 seconds for the Pixel 6, Pixel 7, Pixel 8, and Pixel 9, respectively.“

While a full 12-word recovery phrase would take much longer to capture, the attack remains viable if the user leaves the phrase visible while writing it down.

Related: UK renews Apple iCloud backdoor push, threatening crypto wallet security

Google’s response

The vulnerability was tested on five devices running Android versions 13 to 16: the Google Pixel 6, Google Pixel 7, Google Pixel 8, Google Pixel 9 and the Samsung Galaxy S25. The researchers believe the same attack could work on other Android devices since the exploited APIs are widely available.

Google initially attempted to patch the flaw by limiting how many activities an app can blur at once. However, the researchers said they found a workaround that still enables Pixnapping to function.

“As of October 13, we are still coordinating with Google and Samsung regarding disclosure timelines and mitigations.“

According to the paper, Google rated the issue as high severity and committed to awarding the researchers a bug bounty. The team also reached out to Samsung to warn that “Google’s patch was insufficient to protect Samsung devices.”

Related: Best crypto hardware wallets for 2025

Hardware wallets offer safe protection

The most obvious solution to the issue is to avoid displaying recovery phrases or any other particularly sensitive content on Android devices. Even better would be to avoid displaying recovery information on any internet-capable device altogether.

A simple solution to achieve just that is to use a hardware wallet. A hardware wallet is a dedicated key management device that signs transactions externally to a computer or smartphone without ever exposing the private key or recovery phrase. As threat researcher Vladimir S put it in an X post on the subject:

“Simply don’t use your phone to secure your crypto. Use a hardware wallet!“

Magazine: ‘Help! My robot vac is stealing my Bitcoin’: When smart devices attack

Source

Leave A Reply

Your email address will not be published.