New Android Attack ‘Pixnapping’ Threatens Crypto Wallet Security

Security researchers have uncovered a serious Android vulnerability that could expose cryptocurrency wallet seed phrases and two-factor authentication codes.

The attack, named Pixnapping, works by reading what’s displayed on your screen—pixel by pixel—without needing any special permissions.

How the Attack Works

Pixnapping exploits weaknesses in how Android displays information on your screen. A research team from UC Berkeley, Carnegie Mellon, and other universities discovered that malicious apps can reconstruct sensitive data by measuring tiny timing differences in how pixels are rendered.

The attack happens in three steps. First, a malicious app triggers another app (like Google Authenticator) to display sensitive information….

Source link