New Android Attack ‘Pixnapping’ Threatens Crypto Wallet Security
A novel Android vulnerability dubbed 'Pixnapping' has emerged as a significant threat to cryptocurrency wallet security. The attack exploits pixel-level rendering weaknesses in Android's display system, enabling malicious apps to reconstruct sensitive data without requiring special permissions.
Researchers from UC Berkeley and Carnegie Mellon discovered the technique, which measures microscopic timing differences in pixel rendering. The attack sequence involves triggering target apps to display sensitive information, overlaying semi-transparent windows, and exploiting GPU.zip hardware vulnerabilities to steal data pixel-by-pixel.
Testing across Google Pixel 6-9 and Samsung Galaxy S25 devices running Android 13-16 revealed particular susceptibility in Pixel models. The method effectively bypasses traditional security measures, functioning like a slow-motion screenshot captured through system-level vulnerabilities rather than direct access.