Ledger’s Donjon researchers found critical flaws in some MediaTek-based Android phones that let attackers via USB — and in some cases even when the device is powered off — rapidly extract encrypted data, including phone PINs and crypto wallet seed phrases, enabling stealthy theft of users’ funds.