Major Android Flaw Exposed Millions of Crypto Wallets to Hackers
A report from the Microsoft Defender Security Research Team released Thursday warns that a critical vulnerability in a widely used third-party Android SDK could have exposed sensitive data in tens of millions of mobile cryptocurrency wallets. The issue affected apps that integrated the SDK and, depending on each implementation, may have allowed attackers to access stored credentials, transaction metadata, or other information that could facilitate theft. Microsoft says it has notified vendors and patches are being distributed.
The incident highlights the wider risk posed by third-party components in mobile crypto apps. Users should update wallet apps immediately, enable additional protections where available (such as hardware-wallet integrations or passphrases), and consider rotating keys or moving funds if an app signals compromise. Developers must audit dependencies, apply fixes, and communicate clearly to users; the disclosure could prompt increased security scrutiny across the ecosystem.