Android Flaw Leaves 30 Million Crypto Wallets Open To Attack: Microsoft Analysts

bitcoinistPublicado a 2026-04-11Actualizado a 2026-04-11

Resumen

Microsoft analysts revealed a critical security flaw in the EngageLab SDK (v4.5.4), leaving over 30 million Android crypto wallets vulnerable to attack. The "intent redirection" vulnerability allowed a malicious app to bypass Android's sandbox and gain read/write access to a wallet's private data, including seed phrases and keys, without any user interaction. A patch (SDK 5.2.1) was released in mid-2025. Users who haven't updated their apps since then are advised to not only update but also move their funds to new wallets with fresh seed phrases, as any unpatched wallet is considered compromised. The flaw also affected over 50 million apps in total.

A patch has been available for nearly a year, but millions of Android users may still be running vulnerable crypto wallet apps — leaving their funds and private keys exposed to a known security flaw.

Microsoft’s Defender Security Research Team went public last week with details of a vulnerability it first caught in April 2025. The flaw lived inside a widely used software component called the EngageLab SDK, version 4.5.4.

Because that SDK is baked into thousands of Android apps, a single malicious app could trigger a chain reaction that reached far beyond itself.

How The Attack Works

The method is called “intent redirection.” An attacker’s app sends a specially crafted message to any app running the flawed SDK version. Once that message lands, the targeted app is tricked into handing over read and write access to its own data — including stored seed phrases and wallet addresses.

Source: Microsoft

Android’s built-in sandbox system, which normally keeps apps from seeing each other’s data, was bypassed entirely. According to Microsoft, the attack affected more than 50 million apps across the Android ecosystem, with roughly 30 million of those being crypto wallets.

The vulnerability did not require the user to do anything wrong. No suspicious links. No phishing pages. Just having the wrong apps installed at the same time was enough.

Source: Microsoft

Response From Microsoft And Google

Microsoft moved quickly after its discovery. By May 2025, the company had brought Google and the Android Security Team into the response. EngageLab released a fixed version — SDK 5.2.1 — shortly after.

Reports indicate that both Microsoft and Google have since directed users on how to verify whether their wallet apps have been updated through Google Play Protect.

BTCUSD trading at $72,906 on the 24-hour chart: TradingView

Officials also pointed to a broader concern: apps installed as APK files from outside the Play Store are at higher risk, since they bypass the security checks that Google applies to apps listed in its official marketplace.

What Users Should Do Now

For most users who update their apps regularly, the risk has likely passed. But for anyone who has not updated since mid-2025, the recommended action goes beyond a simple app refresh.

Security teams are advising those users to move their funds into entirely new wallets, generated with fresh seed phrases. Any wallet that was active and unpatched during the exposure window should be treated as potentially compromised.

The disclosure comes alongside a separate Android chip vulnerability flagged the previous month and a new US Treasury initiative that pairs government agencies with crypto firms to share cybersecurity threat information — a sign that mobile security in the crypto space is drawing attention at the highest levels.

Featured image from Bleeping Computer, chart from TradingView

Preguntas relacionadas

QWhat is the name of the vulnerable software component and which version was affected?

AThe vulnerable software component is the EngageLab SDK, specifically version 4.5.4.

QWhat is the attack method called and how does it work?

AThe attack method is called 'intent redirection.' A malicious app sends a specially crafted message to an app running the flawed SDK, tricking it into granting read and write access to its own data, including seed phrases and wallet addresses.

QHow many crypto wallet apps were estimated to be affected by this vulnerability?

ARoughly 30 million crypto wallet apps were estimated to be affected.

QWhat is the primary action recommended for users who had an unpatched wallet app?

AUsers are advised to move their funds into entirely new wallets generated with fresh seed phrases, as the old wallet should be treated as potentially compromised.

QWhich two major companies collaborated on the response to this vulnerability after its discovery?

AMicrosoft and Google (specifically the Android Security Team) collaborated on the response.

Lecturas Relacionadas

CRCL 暴涨暴跌,COIN 跟着跳水:CLARITY Act 背后真正的利益战争

A recent draft of the CLARITY Act sparked market volatility, with Circle (CRCL) and Coinbase (COIN) stocks plunging. The core issue is Section 404 of the draft, which proposes prohibiting digital asset service providers from paying interest or rewards *solely* for holding payment stablecoins. The article argues this is not merely a technical debate over rewards, but a fundamental battle over the future role of stablecoins: Will they remain purely payment/transaction tools, or evolve into on-chain savings accounts that compete with bank deposits? US banks, fearing deposit outflow, have lobbied heavily for such restrictions. While Circle and Coinbase were both hit, their exposures differ. Circle's direct revenue primarily comes from reserve earnings, so the draft impacts its future growth narrative. Coinbase, however, relies heavily on USDC rewards and balances as part of its "Everything Exchange" platform strategy, making its growth engine more directly vulnerable. The analysis identifies three deeper layers often missed: 1) The political economy of preventing stablecoins from becoming savings substitutes. 2) The distinct impact on issuers (Circle) versus distributors/platforms (Coinbase). 3) The migration of yield demand to other tokenized securities (like MMFs) regulated under existing frameworks, as hinted in Section 505 of the same draft. In essence, three major battles are underway: banks defending their deposit base, Coinbase fighting for user entry and distribution rights, and Wall Street aiming to control the compliant path for tokenization. While a short-term headwind for crypto-native platforms, the article suggests this regulatory push could force the industry to build more sustainable value in real payment and B2B infrastructure.

marsbitHace 32 min(s)

CRCL 暴涨暴跌,COIN 跟着跳水:CLARITY Act 背后真正的利益战争

marsbitHace 32 min(s)

Tom Lee充值信仰:加密春天已至,ETH会涨到25万美元

Tom Lee, Chairman of BitMine (NYSE: BMNR), asserts that "Crypto Spring" has arrived and predicts ETH could reach $250,000. In his speech at "Proof of Talk 2026," he outlines five macro catalysts: the end of the Iran war reducing oil-price inflation, the likely passing of pro-crypto US legislation (the Clarity Act), a supportive White House, a crypto-friendly new Fed Chair (Kevin Warsh), and strong demographic-driven equity market growth. Lee argues that two key trends will drive ETH's value: Agentic AI/robotics, which will require blockchain for control and payments, and the massive tokenization of real-world assets (potentially a $300 trillion market). He believes Ethereum is poised to become a future monetary unit, with its price closely linked to software stocks that are already benefiting from AI. He notes the evolving role of the Ethereum Foundation, whose ETH holdings have shrunk to 0.1% of supply. He positions public treasury companies like BitMine—which holds 4.47% of ETH's circulating supply—as the new key ecosystem funders and validators. Finally, Lee promotes BitMine as a leveraged play on ETH's rise. He highlights BitMine's investments in AI/identity (via Eightco/ORBS), its massive ETH staking operation generating ~$1M daily, its stake in content creator MrBeast, and its upcoming inclusion in the Russell 1000 index, which could drive significant institutional buying. He concludes that if ETH reaches $25,000, BitMine's stock could rise dramatically from its current ~$18 price.

Odaily星球日报Hace 50 min(s)

Tom Lee充值信仰:加密春天已至,ETH会涨到25万美元

Odaily星球日报Hace 50 min(s)

Trading

Spot
Futuros
活动图片