TLDR Pixnapping steals on-screen data by reading pixel colors on Android devices. Attack recovered 2FA codes on Pixel 6 to 9 in up to 73% of tests. Google rated the issue high severity and is working on a full patch. Hardware wallets remain the safest way to store crypto recovery phrases. A new Android security [...] The post Pixnapping Android flaw lets hackers steal crypto wallet seed phrases appeared first on CoinCentral.TLDR Pixnapping steals on-screen data by reading pixel colors on Android devices. Attack recovered 2FA codes on Pixel 6 to 9 in up to 73% of tests. Google rated the issue high severity and is working on a full patch. Hardware wallets remain the safest way to store crypto recovery phrases. A new Android security [...] The post Pixnapping Android flaw lets hackers steal crypto wallet seed phrases appeared first on CoinCentral.

Pixnapping Android flaw lets hackers steal crypto wallet seed phrases

2025/10/15 14:07

TLDR

  • Pixnapping steals on-screen data by reading pixel colors on Android devices.
  • Attack recovered 2FA codes on Pixel 6 to 9 in up to 73% of tests.
  • Google rated the issue high severity and is working on a full patch.
  • Hardware wallets remain the safest way to store crypto recovery phrases.

A new Android security flaw has raised concerns among users of crypto wallets and authentication apps. Researchers have identified an attack method called “Pixnapping,” which allows malicious applications to reconstruct sensitive on-screen data such as recovery phrases and two-factor authentication (2FA) codes. The discovery indicates that even trusted devices could be at risk of revealing private information through manipulated screen pixels.

How the Pixnapping Attack Works

The Pixnapping method uses Android’s application programming interfaces (APIs) to calculate the color of individual pixels displayed by other applications. Unlike conventional screen capture attacks, the malicious app does not directly access another app’s display. 

Instead, it layers semi-transparent activities over the target app, masking all but a chosen pixel. By manipulating that pixel repeatedly, attackers can infer its color and reconstruct visual content from the screen.

Researchers explained that this process involves timing frame renders and scanning one pixel at a time, which enables the malware to rebuild what was shown on screen. Although the attack is slow, it is still capable of capturing information that remains visible for more than a few seconds, such as recovery phrases or long authentication codes.

Risk to Crypto Wallet Recovery Phrases

The research team warned that Pixnapping poses a particular danger to crypto wallet users. Recovery phrases, which provide full access to digital wallets, often stay visible while users write them down. According to the study, the attack successfully retrieved full 6-digit 2FA codes in several tests on Google Pixel devices.

The success rate reached 73% on the Pixel 6, 53% on the Pixel 7, 29% on the Pixel 8, and 53% on the Pixel 9. The average time to recover each 2FA code ranged from 14 to 26 seconds, depending on the device model. While recovering a full 12-word seed phrase would take much longer, the researchers confirmed that it remains possible if the phrase stays displayed.

Google’s Response and Ongoing Coordination

The vulnerability was tested on several devices running Android 13 to 16, including the Google Pixel 6 through Pixel 9 and the Samsung Galaxy S25. Since the attack relies on widely available APIs, the team warned that other Android devices could also be affected.

Google responded by limiting how many activities an app can blur at once. However, the researchers found a workaround that allowed Pixnapping to continue functioning. As of October 13, the researchers said they were still coordinating with Google and Samsung regarding disclosure timelines and security patches.

Google classified the issue as high severity and awarded a bug bounty to the research team. The team also informed Samsung that Google’s initial fix did not fully protect Samsung devices.

Hardware Wallets as a Safer Option

Experts advise users to avoid displaying recovery phrases or sensitive data on Android devices until a complete fix is available. Keeping recovery information offline or using a hardware wallet offers stronger protection.

A hardware wallet is a dedicated device that stores private keys securely and signs transactions without exposing them to connected smartphones or computers. Security researcher Vladimir S emphasized this in a post on X, stating, “Simply don’t use your phone to secure your crypto. Use a hardware wallet!”

Until Android patches the vulnerability, users are urged to exercise caution and avoid keeping recovery or authentication data visible on their screens for extended periods.

The post Pixnapping Android flaw lets hackers steal crypto wallet seed phrases appeared first on CoinCentral.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Share Insights

You May Also Like

American Bitcoin’s $5B Nasdaq Debut Puts Trump-Backed Miner in Crypto Spotlight

American Bitcoin’s $5B Nasdaq Debut Puts Trump-Backed Miner in Crypto Spotlight

The post American Bitcoin’s $5B Nasdaq Debut Puts Trump-Backed Miner in Crypto Spotlight appeared on BitcoinEthereumNews.com. Key Takeaways: American Bitcoin (ABTC) surged nearly 85% on its Nasdaq debut, briefly reaching a $5B valuation. The Trump family, alongside Hut 8 Mining, controls 98% of the newly merged crypto-mining entity. Eric Trump called Bitcoin “modern-day gold,” predicting it could reach $1 million per coin. American Bitcoin, a fast-rising crypto mining firm with strong political and institutional backing, has officially entered Wall Street. After merging with Gryphon Digital Mining, the company made its Nasdaq debut under the ticker ABTC, instantly drawing global attention to both its stock performance and its bold vision for Bitcoin’s future. Read More: Trump-Backed Crypto Firm Eyes Asia for Bold Bitcoin Expansion Nasdaq Debut: An Explosive First Day ABTC’s first day of trading proved as dramatic as expected. Shares surged almost 85% at the open, touching a peak of $14 before settling at lower levels by the close. That initial spike valued the company around $5 billion, positioning it as one of 2025’s most-watched listings. At the last session, ABTC has been trading at $7.28 per share, which is a small positive 2.97% per day. Although the price has decelerated since opening highs, analysts note that the company has been off to a strong start and early investor activity is a hard-to-find feat in a newly-launched crypto mining business. According to market watchers, the listing comes at a time of new momentum in the digital asset markets. With Bitcoin trading above $110,000 this quarter, American Bitcoin’s entry comes at a time when both institutional investors and retail traders are showing heightened interest in exposure to Bitcoin-linked equities. Ownership Structure: Trump Family and Hut 8 at the Helm Its management and ownership set up has increased the visibility of the company. The Trump family and the Canadian mining giant Hut 8 Mining jointly own 98 percent…
Share
2025/09/18 01:33
Ranking the “XRP Killers”: Why Digitap ($TAP) Takes the #1 Spot for 2025

Ranking the “XRP Killers”: Why Digitap ($TAP) Takes the #1 Spot for 2025

The post Ranking the “XRP Killers”: Why Digitap ($TAP) Takes the #1 Spot for 2025 appeared on BitcoinEthereumNews.com. XRP opted for the banks-first approach with a long list of impressive partnerships. But a decade later, and no meaningful volume executed has seen a new cohort rise up. Consumers-first is how the new projects are positioning themselves. Stablecoins own the cross-border narrative, and Ripple is being pushed out of the spotlight.  The project that turns these digital dollars into everyday money will take the crown. Here’s the 2025 ranking for ‘XRP Killers’—and why Digitap ($TAP) sits on top. 1. Digitap ($TAP)—The world’s first omni-bank with Visa, Apple Pay, and Google Pay live.2. Stellar (XLM)—A cross-border network with steady enterprise integrations. 3. Remittix (RTX)—A remittance-focused newcomer aiming to bring stablecoin flows into everyday payouts.  Why XRP Never Worked XRP always targeted correspondent banking, not consumers. The story sounded incredible a decade ago, but stablecoins have changed the game. Dollar-pegged assets that run on faster rails than the XRP ledger with broader distribution. XRP’s vision has failed, but the cross-border payment disruption trade is still very much open. But in 2025, adoption matters, and the products that make digital dollars usable in ordinary life will be the biggest winners.  1) Digitap ($TAP): World’s First Omni-Bank with Growing Distribution Digitap is built to make every form of money behave the same. No more siloes, no more juggling multiple accounts, just all forms of value together on a single interface. Fiat, stablecoins, and crypto sit inside a single balance, and thousands of users have downloaded the app today and are using it to send funds.  In many ways, Digitap is an interoperability layer that stitches money together. Blockchain networks and established legacy banking systems are included in the multi-rail design, meaning money can truly travel on any system. Digitaps’ AI system optimizes for speed and cost whenever a user presses send, swap, or…
Share
2025/10/26 05:21
Solana Faces Market Challenges as Digitap Aims to Revolutionize Payments

Solana Faces Market Challenges as Digitap Aims to Revolutionize Payments

The post Solana Faces Market Challenges as Digitap Aims to Revolutionize Payments appeared on BitcoinEthereumNews.com. Lawrence Jengar Oct 24, 2025 12:51 Solana’s price struggles below $200 while Digitap emerges as a potential leader in digital payments, leveraging AI and stablecoins for seamless transactions. Solana (SOL), a prominent blockchain platform known for its high throughput and low transaction costs, is currently experiencing market challenges as its price hovers below the $200 mark. Meanwhile, the cryptocurrency industry is turning its attention toward the payments sector, with stablecoins and new entrants like Digitap leading the charge, according to CoinMarketCap. Stablecoins and Payments in Focus The market’s interest in stablecoins and digital payment solutions has been amplified by recent developments. Federal Reserve Governor Christopher Waller’s proposal for ‘skinny’ Fed accounts could potentially allow institutions and stablecoin issuers to bank directly with the Federal Reserve. This move is poised to bring payments to the forefront of the financial innovation landscape. Solana’s Market Position Despite its technological advancements, Solana is facing resistance in maintaining its price above $200. The platform’s current market position highlights the shifting focus of investors towards projects that are integrating stablecoins and offering innovative payment solutions. These projects are seen as the next major growth drivers in the crypto sphere. Digitap’s Innovative Approach Digitap is emerging as a promising player in the digital payments sector. The company aims to unite banking, stablecoins, and cryptocurrencies into a single consumer app. By utilizing artificial intelligence for routing transactions and offering a Visa card for seamless payments, Digitap is positioned to make digital transactions more accessible and efficient. The integration of AI and stablecoin technology in consumer apps represents a significant evolution in how digital payments are conducted, promising enhanced user experiences and broader adoption of cryptocurrency-based transactions. As the market continues to evolve, the advancements in payment technologies and the growing…
Share
2025/10/26 05:24