The Donjon team reported they were able to recover the Nothing CMF Phone 1’s PIN, decrypt its storage, and extract seed phrases from several crypto wallets without booting Android, including Trust Wallet, Base, Kraken Wallet, Rabby, Tangem’s mobile wallet, and Phantom.
Without ever even booting into Android, the exploit automatically recovered the phone’s PIN, decrypted its storage, and extracted the seed phrases from the most popular software wallets.
Released in 2024 by London-based Nothing, the Nothing CMF Phone 1 is a low-cost and modularly customizable mobile phone that runs the Android operating system. The exploit targets the phone’s secure boot chain, Donjon said, which allows an attacker to connect through USB and extract root cryptographic keys before the operating system loads, enabling the device’s storage to be decrypted offline.
Although the demonstration focused on crypto wallets, Donjon said the exposure could extend to other sensitive information stored on the device, including messages, photos, financial information, and account credentials.
However, software wallets are more accessible and typically free to download and use, compared to hardware wallets that can vary in price. However, Guillemet said the software-only approach comes with trade-offs, and highlights a fundamental architectural difference between “general-purpose” phone chips and those specifically designed for private key protection.
“General-purpose chips are built for convenience,” he wrote. “Secure Elements are built for key protection. A dedicated Secure Element isolates secrets from the rest of the system, protecting them even under physical attack.”



















