Ledger patched an Ethereum app bug that could show one transaction and sign another

Share

Ledger patched a bug in its Ethereum app (version 1.22.2) that allowed a malicious dApp to substitute a transaction held in memory while it was still under review on the device. The flaw could display an unchanged confirmation screen while the device signed different data once the user pressed approve. Security firm TestMachine discovered and validated the issue on Ledger Flex, with likely impact on Nano X, Nano S Plus, Stax, and Apex models. The fix refuses new signing sessions during an active review and rejects approval callbacks when the app state no longer matches. No confirmed in-the-wild exploitation, lost funds, or private-key extraction has been reported.

Source: Read the original article

Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Lire la Suite

Articles