logo

Soft Spots in Hard Tech: Mobile Security Challenges in Web3

ID: f1b803f9-67bf-5d2b-9665-707bb6fe389e

STIX ID: report--f1b803f9-67bf-5d2b-9665-707bb6fe389e

Feed Name: CertiK Blog

Threat Score
65/100

Date Published: 2023-11-26

Date Updated: 2026-06-11

...
...

Researchers found two serious security weaknesses in a popular Web3-focused smartphone: an unlocked/weak bootloader that could let an attacker install custom firmware and a TEE implementation flaw that allowed extraction of the wallet PIN and private keys; both risks could enable complete compromise of users' plaintext data and crypto assets, were responsibly disclosed to vendors, and the TEE issue has been fixed, with recommendations for stronger hardware and supply-chain protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.