Skip to content

Crypto Wallets Exposed by Pixnapping Attack

New Android Vulnerability Poses Risk to Crypto Wallet Security

  • A new Android vulnerability, termed the “Pixnapping” attack, allows malicious apps to access content from other applications.
  • The attack can potentially compromise sensitive information such as crypto wallet recovery phrases and two-factor authentication (2FA) codes.
  • Tests showed a success rate of recovering full six-digit 2FA codes at rates of up to 73% on Google Pixel devices.
  • Google has acknowledged the issue as high severity and is working on mitigation strategies, including a bug bounty for researchers.
  • Using hardware wallets is recommended as a secure alternative to safeguard sensitive crypto information from this vulnerability.

The Pixnapping vulnerability exploits Android APIs, allowing attackers to infer pixel data from other apps, which can lead to serious security breaches for users displaying sensitive information like wallet recovery phrases on their screens.

With an average recovery time of over fourteen seconds for 2FA codes on some devices, users are strongly advised to avoid displaying critical security information on their phones. (Source)

Share