OneKey’s security team, OneKey Anzen, said it has reproduced the Ledger vulnerability previously disclosed by TestMachine and found a transaction replacement issue in Ledger’s Ethereum app version 1.22.1. In the described attack scenario, a user could still see transaction A on the hardware wallet screen while the device may actually sign transaction B, which the user never reviewed. OneKey said the root cause is a race condition between the transaction display logic and the underlying buffer, and that exploitation requires the host side to already be under the control of a malicious dApp or intermediary software. The disclosure timeline has also drawn attention. TestMachine flagged the issue on Aug. 22, and Ledger’s CTO said the next day that a fix had gone live about two weeks earlier and that users only needed to update the app, while urging the community not to "spread panic." Public information, however, shows the formal 1.22.2 tag on Ledger’s GitHub did not appear until Aug. 24. Ledger later said it fixed the issue through app-level validation and at the SDK layer, released Ledger Secure SDK v26.6.1 on Aug. 21, rebuilt and republished affected apps, and added that updating through Ledger Live is required because a firmware update alone is not enough.
BlockBeats reported on Aug. 28 that OneKey’s security team, OneKey Anzen, has reproduced the Ledger vulnerability previously disclosed by TestMachine and identified a transaction replacement flaw in Ledger’s Ethereum app version 1.22.1.
According to OneKey Anzen, in a successful attack scenario the hardware wallet screen may continue to show transaction A, the one the user believes is under review, while the device could actually sign transaction B, which the user never saw.
Attack conditions
OneKey Anzen said the issue is essentially a race condition between the transaction display logic and the underlying buffer. The attack requires the host side to have already been compromised by a malicious dApp or intermediary software.
Disclosure and fix timeline
On Aug. 22, TestMachine said the well-known crypto wallet maker Ledger had a security flaw. The next day, Ledger’s CTO responded that a fix had gone live about two weeks earlier, that users only needed to update the app, and urged the community not to "spread panic."
Publicly available information, however, shows that the formal tag for version 1.22.2 did not appear on Ledger’s GitHub until Aug. 24.
As of publication, Ledger had updated its official website with its latest statement, saying the issue had been fixed through app-level validation and at the SDK layer. The company said it released Ledger Secure SDK v26.6.1 on Aug. 21 and that the related apps had been rebuilt and republished.
Ledger also said users need to update the app through Ledger Live, and that updating device firmware alone is not enough to complete the fix. The company added that it currently has no evidence the vulnerability has been exploited in real-world attacks.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.