One in four android phones hides a chip-level skeleton key—power off won’t save you

Your phone can be cold, black, and supposedly dead—yet in under a minute a stranger with a laptop and a USB cable can suck out your banking PIN, photo roll, and crypto seed. That isn’t hype; it’s the quiet reality for 875 million Androids whose MediaTek brains harbor CVE-2026-20435, a flaw so low-level that off is just another word for vulnerable.

The attack that wakes a corpse

Ledger’s Donjon lab demonstrated the trick on a powered-down Nothing CMF Phone 1. The moment the cable clicks in and the power button is nudged, the bootloader—built on MediaTek’s boot ROM—hands over the master key before android even considers waking up. No lock screen, no biometric gate, no green robot logo. Just silence and a 56-kB dump that contains your disk encryption keys, your SIM unlock code, and every six-digit PIN you ever mistyped.

The list of affected silicon reads like a MediaTek greatest-hits album: MT6739 through MT6993, plus a handful of tablet and TV chips starting with 8. Budget Galaxy, Redmi Note, Oppo A-series, half the Realme catalog—if it cost under €300 in the last three years, odds are the chip is on the sheet. MediaTek patched the boot ROM in January, but the patch has to be baked into each vendor’s firmware image, then flight-tested by fifty-odd carriers. Translation: most owners will wait months, if they ever see it.

Fragmentation is the real exploit

Fragmentation is the real exploit

Google pushes monthly bulletins; MediaTek pushes source drops; Samsung, Xiaomi, Oppo push marketing calendars. The result is a Byzantine supply chain where the weakest link is always the smallest OEM still polishing last year’s skin. Ledger’s CTO Charles Guillemet puts it bluntly: “Smartphones were never designed to be vaults.” He’s right—our pockets hold retirement funds on hardware that can’t even vote on its own updates.

Immediate triage: open Settings> About> Kernel version; if you spot an MT prefix, cross-check against the list and demand the March update today. If your vendor orphaned the model, treat the handset like a burner. Move seeds to a cold wallet, retire the banking app, and recycle the corpse properly. The clock is literal: Donjon’s rig averaged 37 seconds from handshake to plaintext.

The bigger picture is darker. As phones swallow wallets, passports, and car keys, the attack surface sinks deeper into silicon we can’t patch ourselves. MediaTek’s bug is patched; the next one may not be. Until regulators force signed, auditable boot ROMs and until buyers start treating “supported lifetime” as a spec, the only real defense is to assume every mid-range android is already pwned—just waiting for the cable that wakes it.