OneKey Anzen said it reproduced a vulnerability in Ledger’s Ethereum app version 1.22.1 that could let a device sign a different transaction from the one shown on the hardware wallet screen. In the reported scenario, a user may see transaction A during review, while the device could actually sign transaction B, which the user never viewed. According to OneKey Anzen, the issue stems from a race condition between the transaction display logic and the underlying buffer, and exploitation requires the host side to already be controlled by a malicious dApp or intermediary software. Ledger’s CTO previously said a fix had gone live about two weeks earlier and that users only needed to update the app. Public information shows the formal 1.22.2 tag appeared on Ledger’s GitHub on Aug. 24. Ledger’s website said the issue was fixed through app-level validation and the SDK layer, and that Ledger Secure SDK v26.6.1 was released on Aug. 21, with affected apps rebuilt and republished. Ledger added that users must update the app through Ledger Live, and that updating device firmware alone will not fix the issue. The company also said it has seen no evidence of real-world exploitation so far.
Odaily reported that OneKey Anzen reproduced a Ledger flaw and found a transaction replacement vulnerability in version 1.22.1 of Ledger’s Ethereum app.
Under the described attack scenario, the hardware wallet screen can still show transaction A while the user is reviewing it, but the device may actually sign transaction B, which the user did not see.
OneKey Anzen said the bug comes from a race condition between the transaction display logic and the underlying buffer. The attack requires the host side to have already been compromised by a malicious dApp or intermediary software.
Ledger’s CTO had previously said the fix went live about two weeks earlier and that users could resolve the issue by updating the app.
Publicly available information shows that the formal tag for version 1.22.2 appeared on Ledger’s GitHub on Aug. 24. Ledger’s website said the issue was fixed through app-level validation and at the SDK layer, and that Ledger Secure SDK v26.6.1 was released on Aug. 21. Related apps have since been rebuilt and republished.
Ledger also said users need to update the app through Ledger Live, and that updating device firmware alone will not complete the fix.
The company added that it currently has no evidence the vulnerability has been exploited in real-world attacks.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.